Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.34% | — | Gdpr Cookie ConsentAI | 10/7/2026 | 10/7/2026 | The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function (the wp_ajax_gcc_save_schedule_scan AJAX action) in versions up to, and including, 4.3.6. This… | |
| Aplazada | Media (6.4) | 0.33% | — | WP Gdpr Cookie ConsentAI | 9/6/2026 | 23/7/2026 | The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in versions up to, and including, 1.0.0. This is due to missing capability and nonce checks on the handleAjaxCalls() function, combined with insufficient input sanitization on the… | |
| Aplazada | Alta (7.5) | 0.38% | — | Gdpr Cookie ConsentAI | 19/2/2026 | 17/6/2026 | The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'gdpr/v1/settings' REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to retrieve sensitive plugin settings including API… | |
| Aplazada | Alta (7.1) | 0.12% | — | Shahjahan Jewel WP Gdpr Cookie ConsentAI | 6/11/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel WP GDPR Cookie Consent wp-gdpr-cookie-consent allows Stored XSS.This issue affects WP GDPR Cookie Consent: from n/a through <= 1.0.0. | |
| Analizada | Media (5.4) | 0.31% | — | Webtoffee Gdpr Cookie Consent | 15/5/2025 | 17/6/2026 | The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not properly sanitize and escape the IP headers when logging them, allowing visitors to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Consent report' page and the malicious script is executed in the… | |
| Analizada | Media (6.5) | 0.20% | — | Webtoffee Gdpr Cookie Consent | 15/5/2025 | 17/6/2026 | The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks | |
| Modificada | Alta (7.3) | 0.28% | — | Termly Gdpr Cookie Consent Banner | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Termly Cookie Consent.This issue affects Cookie Consent: from n/a through 3.2. | |
| Modificada | Media (4.8) | 0.39% | — | Supsystic Gdpr Cookie Consent | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic GDPR Cookie Consent by Supsystic allows Stored XSS.This issue affects GDPR Cookie Consent by Supsystic: from n/a through 2.1.2. | |
| Modificada | Media (4.8) | 0.44% | — | Radicalwebdesign Gdpr Cookie Consent Notice BOX | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Radical Web Design GDPR Cookie Consent Notice Box plugin <= 1.1.6 versions. | |
| Modificada | Media (5.4) | 0.86% | — | Cookielawinfo Gdpr Cookie Consent | 21/8/2020 | 17/6/2026 | ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation. |