Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.42% | — | Easy Google FontsAI | 10/9/2026 | 10/9/2026 | The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control_selectors meta field in all versions up to, and including, 2.0.4. This is due to the plugin registering the control_selectors meta field with show_in_rest enabled but without a sanitize_callback, and subsequently… | |
| Aplazada | Media (4.3) | 0.40% | — | Typesquare Webfonts FOR ConahaAI | 20/5/2026 | 23/7/2026 | The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Crítica (9.8) | 1.3% | — | Dsgvo Google WEB Fonts GdprAI | 8/4/2026 | 24/7/2026 | The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1. The function is exposed via a `wp_ajax_nopriv_` hook, requiring no authentication. It fetches a… | |
| Aplazada | Alta (7.5) | 0.38% | — | Fonts Manager Custom FontsAI | 21/3/2026 | 17/6/2026 | The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedFnt’ parameter in all versions up to, and including, 1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Alta (8.4) | 0.46% | — | Gnome Fonts ViewerAI | 29/1/2026 | 17/6/2026 | Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds write by crafting a malicious TTF font file. Attackers can generate a specially crafted TTF file with an oversized pattern to exhaust memory through repeated malloc() calls and potentially crash the… | |
| Aplazada | Media (5.3) | 0.26% | — | Custom Fonts Host Your Fonts LocallyAI | 20/1/2026 | 17/6/2026 | The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'BCF_Google_Fonts_Compatibility' class constructor function in all versions up to, and including, 2.1.16. This makes it possible for unauthenticated attackers to delete… | |
| Aplazada | Media (5.4) | 0.22% | — | MDZ Persian Admin FontsAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in MDZ Persian Admnin Fonts persian-admin-fonts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Persian Admnin Fonts: from n/a through <= 4.1.03. | |
| Aplazada | Alta (7.1) | 0.29% | — | Kontur FontsamplerAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kontur Fontsampler fontsampler allows Reflected XSS.This issue affects Fontsampler: from n/a through <= 0.4.14. | |
| Aplazada | Media (4.3) | 0.23% | — | Uzair EasyfontsAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Uzair Easyfonts easyfonts allows Cross Site Request Forgery.This issue affects Easyfonts: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.1) | 0.31% | — | Wisdomlogix Solutions PVT LTD Fonts Manager Custom FontsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wisdomlogix Solutions Pvt. Ltd. Fonts Manager | Custom Fonts fonts-manager-custom-fonts allows Reflected XSS.This issue affects Fonts Manager | Custom Fonts: from n/a through <= 1.2. | |
| Aplazada | Media (4.3) | 0.62% | — | Mohamed ABD Elhalim Arabic WebfontsAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Mohamed Abd Elhalim Arabic Webfonts arabic-webfonts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Arabic Webfonts: from n/a through <= 1.4.6. | |
| Analizada | Alta (8.8) | 0.42% | — | Fontsplugin Fonts | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Fonts Plugin Fonts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fonts: from n/a through 3.7.7. | |
| Aplazada | Media (5.3) | 0.39% | — | Xserver Typesquare WebfontsAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in XSERVER Inc. TypeSquare Webfonts allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects TypeSquare Webfonts: from n/a through 2.0.7. | |
| Analizada | Media (5.4) | 0.16% | — | Fontsplugin Fonts | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7. | |
| Modificada | Media (5.4) | 0.26% | — | Brainstormforce Custom Fonts | 24/5/2024 | 17/6/2026 | The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg file upload in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author level or higher, to… | |
| Aplazada | Media (4.3) | 0.34% | — | Adrian Morchen Embed Google FontsAI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Adrian Mörchen Embed Google Fonts.This issue affects Embed Google Fonts: from n/a through 3.1.0. | |
| Analizada | Media (6.1) | 0.40% | — | Danialhatami Persian Fonts | 27/2/2024 | 17/6/2026 | The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Alta (8.8) | 0.30% | — | Breakdance Elegant Custom Fonts | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Louis Reingold Elegant Custom Fonts plugin <= 1.0 versions. | |
| Modificada | Alta (8.8) | 0.30% | — | TS Webfonts FOR Sakura | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SAKURA Internet Inc. TS Webfonts for さくらのレンタルサーバ plugin <= 3.1.2 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Themekraft TK Google Fonts Gdpr Compliant | 6/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeKraft TK Google Fonts GDPR Compliant plugin <= 2.2.11 versions. | |
| Modificada | Alta (8.8) | 0.22% | — | Kvvaradha KV Tinymce Editor ADD Fonts | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kvvaradha Kv TinyMCE Editor Add Fonts plugin <= 1.1 versions. | |
| Modificada | Media (6.1) | 0.37% | — | Kaplugins Free-google-fonts | 30/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in KAPlugins Google Fonts For WordPress plugin <= 3.0.0 versions. | |
| Analizada | Media (4.3) | 0.31% | — | TS Webfonts FOR Sakura | 21/7/2023 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in TS Webfonts for SAKURA 3.1.2 and earlier allows a remote unauthenticated attacker to hijack the authentication of a user and to change settings by having a user view a malicious page. | |
| Analizada | Media (6.1) | 0.60% | — | TS Webfonts FOR Sakura | 21/7/2023 | 17/6/2026 | Cross-site scripting vulnerability in TS Webfonts for SAKURA 3.1.0 and earlier allows a remote unauthenticated attacker to inject an arbitrary script. | |
| Modificada | Media (4.8) | 0.37% | — | Seedwebs Seed Fonts | 19/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Seed Webs Seed Fonts plugin <= 2.3.1 versions. |