Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.21% | — | Prevent Files Folders AccessAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions. | |
| Aplazada | Media (6.5) | 0.47% | — | Nextcloud Team FoldersAINextcloud WorkspaceAI | 18/9/2026 | 18/9/2026 | A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables organizations to delegate limited administrative privileges for team folder management… | |
| Aplazada | Media (6.8) | 0.43% | — | Catfolders Document Gallery PDF LibraryAI | 5/9/2026 | 8/9/2026 | The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected… | |
| Aplazada | Media (5.3) | 0.19% | — | Catfolders Document Gallery PROAI | 29/8/2026 | 31/8/2026 | The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site. | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Drupal Media FoldersAI | 25/8/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8. | |
| Aplazada | Alta (7.5) | 0.43% | — | CatfoldersAI | 16/8/2026 | 26/8/2026 | The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, allowing unauthenticated users to retrieve the title, type, size and URL of the media attachments assigned to any of its folders, including folders which are not published… | |
| Aplazada | Media (4.3) | 0.23% | — | Wickedplugins Wicked FoldersAI | 16/3/2026 | 17/6/2026 | The Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the delete_folders() function due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.22% | — | Maxgalleria Media Library FoldersAI | 14/2/2026 | 17/6/2026 | The Media Library Folders plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 8.3.6 via the delete_maxgalleria_media() and maxgalleria_rename_image() functions due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.19% | — | FoldersAI | 8/1/2026 | 17/6/2026 | The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Replacement in all versions up to, and including, 3.1.5. This is due to missing object-level authorization checks in the handle_folders_file_upload() function.… | |
| Aplazada | Alta (8.5) | 0.24% | — | Codedraft Mediabay - Wordpress Media Library FoldersAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Folders allows Blind SQL Injection.This issue affects Mediabay - WordPress Media Library Folders: from n/a through 1.4. | |
| Aplazada | Media (5.3) | 0.26% | — | CatfoldersAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in CatFolders CatFolders catfolders allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CatFolders: from n/a through <= 2.5.3. | |
| Analizada | Media (4.3) | 0.28% | — | Nextcloud Group Folders | 5/12/2025 | 17/6/2026 | Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user with read-only permission can restore a file from the trash bin. This vulnerability is fixed in 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8,… | |
| Aplazada | Media (4.3) | 0.23% | — | Webxiaowei FoldersAI | 27/11/2025 | 17/6/2026 | The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on the 'wcp_change_post_folder' function in all versions up to, and including, 3.1.5. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.44% | — | CatfoldersAI | 11/9/2025 | 30/9/2026 | The CatFolders – Tame Your WordPress Media Library by Category plugin for WordPress is vulnerable to time-based SQL Injection via the CSV Import contents in all versions up to, and including, 2.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Media (6.5) | 0.43% | — | Miniorange Prevent Files Folders AccessAI | 20/8/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in miniOrange Prevent files / folders access prevent-file-access allows Path Traversal.This issue affects Prevent files / folders access: from n/a through <= 2.6.0. | |
| Aplazada | Alta (7.1) | 0.14% | — | Codedraft Mediabay - Wordpress Media Library FoldersAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in codedraft Mediabay - WordPress Media Library Folders allows Reflected XSS. This issue affects Mediabay - WordPress Media Library Folders: from n/a through 1.4. | |
| Analizada | Media (6.5) | 0.79% | — | Nextcloud Group FoldersNextcloud Server | 16/5/2025 | 17/6/2026 | Nextcloud Server is a self hosted personal cloud system, and the Nextcloud Groupfolders app provides admin-configured folders shared by everyone in a group or team. In Nextcloud Server prior to 30.0.2, 29.0.9, and 28.0.1, Nextcloud Enterprise Server prior to 30.0.2 and 29.0.9, and Nextcloud Groupfolders app prior to… | |
| Analizada | Media (4.3) | 0.34% | — | Maxfoundry Media Library Folders | 15/2/2025 | 17/6/2026 | The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in all versions up to, and including, 8.3.0. This makes it possible for authenticated attackers, with Author-level access and above, to change plugin settings… | |
| Analizada | Media (6.3) | 0.33% | — | Maxfoundry Media Library Folders | 30/8/2024 | 17/6/2026 | The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several AJAX functions in the media-library-plus.php file in all versions up to, and including, 8.2.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (6.5) | 0.45% | — | Maxfoundry Media Library Folders | 29/8/2024 | 17/6/2026 | The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter of the 'mlf_change_sort_type' AJAX action in all versions up to, and including, 8.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Analizada | Media (5.4) | 0.39% | — | Premio Folders | 6/8/2024 | 17/6/2026 | The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.8) | 3.3% | — | Folders PROAI | 14/6/2024 | 17/6/2026 | The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_folders_file_upload' function in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers, with author access and above, to upload arbitrary files on the… | |
| Aplazada | Media (4.3) | 0.67% | — | Folderify FoldersAIFolderify Folders PROAI | 14/6/2024 | 17/6/2026 | The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0 in Folders and 3.0.2 in Folders Pro via the 'handle_folders_file_upload' function. This makes it possible for authenticated attackers, with author access and above, to upload files to… | |
| Aplazada | Media (5.4) | 0.37% | — | Folders PROAI | 4/5/2024 | 17/6/2026 | The Folders Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's First Name and Last Name in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (6.1) | 0.39% | — | Maxfoundry Media Library Folders | 19/4/2024 | 17/6/2026 | The Media Library Folders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 8.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… |