Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.15% | — | GtranslateAI | 23/9/2026 | 23/9/2026 | The GTranslate WordPress plugin before 5.0.1 does not remove shortcodes from the content of outgoing emails before expanding them which, in a non-default configuration, allows unauthenticated users to have arbitrary shortcodes registered on the site executed server side. | |
| Aplazada | Baja (3.5) | 0.14% | — | Translate Wordpress With GtranslateAI | 11/9/2026 | 11/9/2026 | The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site. | |
| Analizada | Baja (2.7) | 0.30% | — | Gtranslate | 19/5/2026 | 23/7/2026 | Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing. This issue affects Translate Drupal with GTranslate: from 0.0.0 before 3.0.5. | |
| Aplazada | Media (6.5) | 0.17% | — | Reubenthiessen Translate This Gtranslate ShortcodeAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reubenthiessen Translate This gTranslate Shortcode translate-this-google-translate-web-element-shortcode allows Stored XSS.This issue affects Translate This gTranslate Shortcode: from n/a through <= 1.0. | |
| Aplazada | Media (6.4) | 0.24% | — | Translate This Gtranslate ShortcodeAI | 16/8/2025 | 17/6/2026 | The Translate This gTranslate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘base_lang’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (5.3) | 0.54% | — | Gtranslate Google Language TranslatorAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in edo888 Google Language Translator google-language-translator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google Language Translator: from n/a through <= 6.0.19. | |
| Analizada | Media (5.4) | 0.51% | — | Gtranslate Google Language Translator | 16/10/2024 | 17/6/2026 | The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in versions up to, and including, 6.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Media (4.8) | 0.47% | — | Translate Wordpress With Gtranslate | 25/9/2023 | 17/6/2026 | The Translate WordPress with GTranslate WordPress plugin before 3.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). This… | |
| Modificada | Alta (8.8) | 0.61% | — | Translate Wordpress With Gtranslate | 28/3/2022 | 17/6/2026 | The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker could gain access to a logged in admin… | |
| Modificada | Media (4.7) | 0.75% | — | Translate Wordpress With Gtranslate | 7/2/2022 | 17/6/2026 | The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT… | |
| Modificada | Media (4.8) | 0.68% | — | Gtranslate Google Language Translator | 8/11/2021 | 17/6/2026 | The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (6.1) | 1.6% | — | Gtranslate | 30/7/2021 | 17/6/2026 | In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vulnerable to Reflected… | |
| Modificada | Media (6.1) | 4.5% | — | Translate Wordpress With Gtranslate | 20/4/2020 | 17/6/2026 | The GTranslate plugin before 2.8.52 for WordPress has Reflected XSS via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option. | |
| Modificada | Media (6.1) | 0.95% | — | Gtranslate Google Language Translator | 13/8/2019 | 17/6/2026 | The google-language-translator plugin before 5.0.06 for WordPress has XSS. |