Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.27%—GD Rating SystemAI3/10/20266/10/2026
The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaAlta (8.5)0.36%—Milan Petrovic GD Rating SystemAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Rating System gd-rating-system allows Blind SQL Injection.This issue affects GD Rating System: from n/a through <= 3.7.
AplazadaMedia (6.4)0.37%—GD Rating SystemAI19/11/202417/6/2026
The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AplazadaMedia (5.3)0.54%—Milan Petrovic GD Rating SystemAI12/7/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Milan Petrovic GD Rating System allows PHP Local File Inclusion.This issue affects GD Rating System: from n/a through 3.6.
ModificadaMedia (6.1)0.40%—Dev4press GD Rating System29/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD Rating System allows Stored XSS.This issue affects GD Rating System: from n/a through 3.5.
ModificadaMedia (6.1)0.91%—Dev4press GD Rating System27/8/201917/6/2026
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
ModificadaMedia (6.1)1.3%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
ModificadaMedia (6.1)1.3%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
ModificadaAlta (7.5)3.7%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
ModificadaAlta (7.5)3.7%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
ModificadaAlta (7.5)3.7%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
ModificadaMedia (6.1)1.4%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
ModificadaAlta (7.5)3.7%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
ModificadaMedia (6.1)1.3%—GD Rating System Project GD Rating System8/1/201817/6/2026
The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-about page.