Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.23% | — | GivewpAI | 30/9/2026 | 30/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | GivewpAI | 30/9/2026 | 30/9/2026 | Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions. | |
| Aplazada | Alta (7.1) | 0.20% | — | GivewpAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions. | |
| Aplazada | Crítica (9.1) | 0.30% | — | Stellarwp GivewpAI | 30/9/2026 | 30/9/2026 | Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9. | |
| Aplazada | Media (6.5) | 0.31% | — | GivewpAI | 21/9/2026 | 21/9/2026 | The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | |
| Aplazada | Alta (8.1) | 0.38% | — | GivewpAI | 16/9/2026 | 17/9/2026 | The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value it stores and the value it later uses to look that donor up, allowing unauthenticated users to be resolved as an arbitrary donor and to set the WordPress password of any user account linked to one,… | |
| Aplazada | Crítica (10) | 2.3% | — | Stellarwp GivewpAILiquidweb GivewpAI | 28/8/2026 | 28/8/2026 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1. | |
| Aplazada | Media (6.4) | 0.36% | — | GivewpAI | 28/8/2026 | 28/8/2026 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'give_form' shortcode in all versions up to, and including, 4.14.4. This is due to insufficient input sanitization and output escaping on the continue_button_title and display_style shortcode… | |
| Aplazada | Media (6.5) | 0.27% | — | GivewpAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | GivewpAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | GivewpAI | 13/8/2026 | 14/8/2026 | Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | GivewpAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | GivewpAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | GivewpAI | 31/7/2026 | 26/8/2026 | The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details. | |
| Aplazada | Media (5.3) | 0.30% | — | GivewpAI | 31/7/2026 | 26/8/2026 | The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part from request input, which allows unauthenticated users to complete donations through a payment gateway the administrator has disabled. | |
| Aplazada | Media (6.8) | 0.43% | — | GivewpAI | 30/7/2026 | 30/7/2026 | The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting before outputting it in an HTML attribute, allowing users with the GiveWP Worker role and above to inject arbitrary web scripts that execute on the public donation form viewed by any visitor. | |
| Aplazada | Alta (7.1) | 0.25% | — | GivewpAI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions. | |
| Aplazada | Media (5.4) | 0.14% | — | GivewpAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions. | |
| Aplazada | Media (6.4) | 0.36% | — | GivewpAI | 16/7/2026 | 16/7/2026 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.41% | — | GivewpAI | 2/7/2026 | 2/7/2026 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction][image]' parameter in all versions up to, and including, 4.16.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.42% | — | GivewpAI | 1/7/2026 | 1/7/2026 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_id' (and other) shortcode attributes of the 'givewp_campaign_comments' shortcode in versions up to, and including, 4.16.0. This is due to insufficient input sanitization and output… | |
| Aplazada | Media (4.3) | 0.23% | — | GivewpAI | 1/7/2026 | 1/7/2026 | The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 This is due to missing nonce validation on the give_set_notification_status_handler() function. This makes it possible for unauthenticated attackers to disable donation email notifications via a forged… | |
| Aplazada | Alta (7.1) | 0.25% | — | GivewpAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Stellarwp GivewpAI | 1/6/2026 | 22/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based XSS. This issue affects GiveWP: from n/a through 4.14.5. | |
| Aplazada | Media (5.3) | 0.31% | — | Stellarwp GivewpAI | 29/4/2026 | 17/6/2026 | Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GiveWP: from n/a through <= 4.14.5. |