Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.40% | — | Geomywp GEO MY WordpressAI | 16/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions. | |
| Analizada | Media (6.6) | 0.75% | — | Geomywp GEO MY WordpressGeomywp GEO MY Wordpress Premium Settings | 22/11/2024 | 17/6/2026 | The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server. | |
| Aplazada | Alta (7.1) | 0.32% | — | Geomywp GEO MY WordpressAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eyal Fitoussi GEO my WordPress geo-my-wp allows Reflected XSS.This issue affects GEO my WordPress: from n/a through <= 4.5.0.3. | |
| Analizada | Crítica (9.8) | 2.1% | — | Geomywp GEO MY Wordpress | 19/8/2024 | 17/6/2026 | The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution. | |
| Aplazada | Media (5.4) | 0.21% | — | Geomywp GEO MY WordpressAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.1. | |
| Modificada | Alta (7.2) | 0.54% | — | Geomywp GEO MY Wordpress | 31/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.0.2. | |
| Modificada | Media (5.4) | 0.41% | — | Geomywp GEO MY Wordpress | 10/10/2023 | 17/6/2026 | The GEO my WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above… |