Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

72 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.34%—Data443 Gdpr FrameworkAI6/10/20266/10/2026
Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions.
AplazadaAlta (7.2)0.51%—Complianz Gdpr Ccpa Cookie Consent BannerAI18/9/202618/9/2026
The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaMedia (5.3)0.34%—Prestashop PsgdprAI16/9/202622/9/2026
PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs.
AnalizadaAlta (7.5)0.56%—Mageplaza Gdpr9/9/202610/9/2026
Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to…
AplazadaCrítica (10)0.52%—WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI31/8/20261/9/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1.
AplazadaMedia (4.3)0.17%—Mooveagency Gdpr Cookie ComplianceAI5/8/202626/8/2026
The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link.
AplazadaMedia (6.5)0.34%—Gdpr Framework BY Data443AI4/8/202626/8/2026
The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's…
AplazadaMedia (4.3)0.34%—Gdpr Cookie ConsentAI10/7/202610/7/2026
The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan AJAX action) in versions up to, and including, 4.3.6. This…
AplazadaMedia (6.4)0.33%—WP Gdpr Cookie ConsentAI9/6/202623/7/2026
The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in versions up to, and including, 1.0.0. This is due to missing capability and nonce checks on the handleAjaxCalls() function, combined with insufficient input sanitization on the…
AplazadaBaja (1.8)0.26%—Backdrop Gdpr CookiesAI26/5/202624/7/2026
The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission…
AplazadaCrítica (9.8)1.3%—Dsgvo Google WEB Fonts GdprAI8/4/202624/7/2026
The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1. The function is exposed via a `wp_ajax_nopriv_` hook, requiring no authentication. It fetches a…
AplazadaMedia (4.9)0.22%—Complianz Gdpr Ccpa Cookie ConsentAI26/3/202617/6/2026
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.4.2. This is due to the `revert_divs_to_summary` function replacing `&#8221;` HTML entities with literal double-quote characters (`"`) in post content without subsequent…
AplazadaAlta (7.5)0.38%—Gdpr Cookie ConsentAI19/2/202617/6/2026
The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings' REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to retrieve sensitive plugin settings including API…
AplazadaMedia (5.3)0.31%—Themebeez Simple Gdpr Cookie ComplianceAI23/1/202617/6/2026
Missing Authorization vulnerability in themebeez Simple GDPR Cookie Compliance simple-gdpr-cookie-compliance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple GDPR Cookie Compliance: from n/a through <= 2.0.0.
AplazadaMedia (6.5)0.30%—Ninjateam Gdpr Ccpa Compliance SupportAI22/1/202617/6/2026
Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GDPR CCPA Compliance Support: from n/a through <= 2.7.4.
AplazadaMedia (5.3)0.28%—Silkentrepreneur WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI30/12/202517/6/2026
Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3.
AplazadaMedia (5.3)0.25%—Webtoffee WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI16/12/202517/6/2026
Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.7.
AplazadaMedia (6.4)0.22%—HU Webuni Cookie Notice Compliance FOR Gdpr CcpaAI22/11/202517/6/2026
The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookies_accepted shortcode in all versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (4.3)0.29%—Webtoffee WP Cookie Notice FOR Gdpr Ccpa Eprivacy ConsentAI21/11/202517/6/2026
Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3.
AplazadaAlta (7.1)0.12%—Shahjahan Jewel WP Gdpr Cookie ConsentAI6/11/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel WP GDPR Cookie Consent wp-gdpr-cookie-consent allows Stored XSS.This issue affects WP GDPR Cookie Consent: from n/a through <= 1.0.0.
AplazadaMedia (6.5)0.21%—Gdprinfo Cookie Notice AND Consent BannerAI3/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GDPR Info Cookie Notice & Consent Banner for GDPR & CCPA Compliance cookie-notice-and-consent-banner allows Stored XSS.This issue affects Cookie Notice & Consent Banner for GDPR & CCPA Compliance: from n/a through <=…
AplazadaMedia (4.3)0.16%—Webtoffee WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Cross Site Request Forgery.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 3.8.0.
AplazadaMedia (4.3)0.16%—Matthias Nordwig Gdpr-compliant-recaptcha-for-all-formsAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Matthias Nordwig Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant gdpr-compliant-recaptcha-for-all-forms allows Cross Site Request Forgery.This issue affects Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant: from n/a through…
AplazadaMedia (4.3)0.25%—Ninjateam Gdpr Ccpa Compliance SupportAI19/5/202517/6/2026
Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GDPR CCPA Compliance Support: from n/a through <= 2.7.3.
AnalizadaMedia (5.4)0.31%—Webtoffee Gdpr Cookie Consent15/5/202517/6/2026
The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the…