Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 88 respecto a la semana anterior
Críticas / altas1419▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.35% | — | Wpmet FundengineAI | 25/8/2026 | 26/8/2026 | The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.37% | — | Wpmet FundengineAI | 25/8/2026 | 26/8/2026 | The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wpmet FundengineAI | 20/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wpmet FundengineAI | 18/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | Wpmet FundengineAI | 27/7/2026 | 27/7/2026 | Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Roxnor Wp-fundraising-donationAIWpmet FundengineAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6. | |
| Analizada | Alta (8.8) | 0.43% | — | Wpmet Fundengine | 1/8/2024 | 17/6/2026 | The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying user meta updated through the update_user_meta function. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Crítica (9.8) | 7.9% | — | Wpmet Fundengine | 8/6/2022 | 17/6/2026 | The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a parameter before using it in a SQL statement via one of it's REST route, leading to an SQL injection exploitable by unauthenticated users |