Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.34% | — | Data443 Gdpr FrameworkAI | 6/10/2026 | 6/10/2026 | Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions. | |
| Aplazada | Alta (7.2) | 0.51% | — | Complianz Gdpr Ccpa Cookie Consent BannerAI | 18/9/2026 | 18/9/2026 | The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Elementor Cookie Blocker Regex in all versions up to, and including, 7.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.34% | — | Prestashop PsgdprAI | 16/9/2026 | 22/9/2026 | PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs. | |
| Analizada | Alta (7.5) | 0.56% | — | Mageplaza Gdpr | 9/9/2026 | 10/9/2026 | Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to… | |
| Aplazada | Crítica (10) | 0.52% | — | WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI | 31/8/2026 | 1/9/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through 4.4.1. | |
| Aplazada | Media (4.3) | 0.17% | — | Mooveagency Gdpr Cookie ComplianceAI | 5/8/2026 | 26/8/2026 | The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, allowing an attacker to log any user out and delete the site's cookies by luring them to a crafted link. | |
| Aplazada | Media (6.5) | 0.34% | — | Gdpr Framework BY Data443AI | 4/8/2026 | 26/8/2026 | The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's… | |
| Aplazada | Media (4.3) | 0.34% | — | Gdpr Cookie ConsentAI | 10/7/2026 | 10/7/2026 | The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan AJAX action) in versions up to, and including, 4.3.6. This… | |
| Aplazada | Media (6.4) | 0.33% | — | WP Gdpr Cookie ConsentAI | 9/6/2026 | 23/7/2026 | The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in versions up to, and including, 1.0.0. This is due to missing capability and nonce checks on the handleAjaxCalls() function, combined with insufficient input sanitization on the… | |
| Aplazada | Baja (1.8) | 0.26% | — | Backdrop Gdpr CookiesAI | 26/5/2026 | 24/7/2026 | The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission… | |
| Aplazada | Crítica (9.8) | 1.3% | — | Dsgvo Google WEB Fonts GdprAI | 8/4/2026 | 24/7/2026 | The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1. The function is exposed via a `wp_ajax_nopriv_` hook, requiring no authentication. It fetches a… | |
| Aplazada | Media (4.9) | 0.22% | — | Complianz Gdpr Ccpa Cookie ConsentAI | 26/3/2026 | 17/6/2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4.4.2. This is due to the `revert_divs_to_summary` function replacing `”` HTML entities with literal double-quote characters (`"`) in post content without subsequent… | |
| Aplazada | Alta (7.5) | 0.38% | — | Gdpr Cookie ConsentAI | 19/2/2026 | 17/6/2026 | The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings' REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to retrieve sensitive plugin settings including API… | |
| Aplazada | Media (5.3) | 0.31% | — | Themebeez Simple Gdpr Cookie ComplianceAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in themebeez Simple GDPR Cookie Compliance simple-gdpr-cookie-compliance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple GDPR Cookie Compliance: from n/a through <= 2.0.0. | |
| Aplazada | Media (6.5) | 0.30% | — | Ninjateam Gdpr Ccpa Compliance SupportAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GDPR CCPA Compliance Support: from n/a through <= 2.7.4. | |
| Aplazada | Media (5.3) | 0.28% | — | Silkentrepreneur WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3. | |
| Aplazada | Media (5.3) | 0.25% | — | Webtoffee WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.7. | |
| Aplazada | Media (6.4) | 0.22% | — | HU Webuni Cookie Notice Compliance FOR Gdpr CcpaAI | 22/11/2025 | 17/6/2026 | The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookies_accepted shortcode in all versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.29% | — | Webtoffee WP Cookie Notice FOR Gdpr Ccpa Eprivacy ConsentAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3. | |
| Aplazada | Alta (7.1) | 0.12% | — | Shahjahan Jewel WP Gdpr Cookie ConsentAI | 6/11/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel WP GDPR Cookie Consent wp-gdpr-cookie-consent allows Stored XSS.This issue affects WP GDPR Cookie Consent: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.21% | — | Gdprinfo Cookie Notice AND Consent BannerAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GDPR Info Cookie Notice & Consent Banner for GDPR & CCPA Compliance cookie-notice-and-consent-banner allows Stored XSS.This issue affects Cookie Notice & Consent Banner for GDPR & CCPA Compliance: from n/a through <=… | |
| Aplazada | Media (4.3) | 0.16% | — | Webtoffee WP Cookie Notice FOR Gdpr Ccpa AND Eprivacy ConsentAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Cross Site Request Forgery.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 3.8.0. | |
| Aplazada | Media (4.3) | 0.16% | — | Matthias Nordwig Gdpr-compliant-recaptcha-for-all-formsAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Matthias Nordwig Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant gdpr-compliant-recaptcha-for-all-forms allows Cross Site Request Forgery.This issue affects Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant: from n/a through… | |
| Aplazada | Media (4.3) | 0.25% | — | Ninjateam Gdpr Ccpa Compliance SupportAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Ninja Team GDPR CCPA Compliance Support ninja-gdpr-compliance allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GDPR CCPA Compliance Support: from n/a through <= 2.7.3. | |
| Analizada | Media (5.4) | 0.31% | — | Webtoffee Gdpr Cookie Consent | 15/5/2025 | 17/6/2026 | The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the… |