Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.50% | — | Comment Guestbook Project Comment Guestbook | 30/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress. | |
| Modificada | Media (6.1) | 0.73% | — | Gwolle Guestbook Project Gwolle Guestbook | 23/6/2022 | 17/6/2026 | A vulnerability was found in Gwolle Guestbook Plugin 1.7.4. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting. The attack may be initiated remotely. | |
| Modificada | Media (6.1) | 0.80% | — | Gwolle Guestbook Project Gwolle Guestbook | 27/12/2021 | 17/6/2026 | The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin page | |
| Modificada | Media (6.1) | 1.2% | — | Gwolle Guestbook Project Gwolle Guestbook | 2/10/2018 | 17/6/2026 | XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via the PATH_INFO to wp-admin/index.php | |
| Modificada | Crítica (9) | 37% | 💥 Exploit | Gwolle Guestbook Project Gwolle Guestbook | 11/9/2017 | 17/6/2026 | PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and… | |
| Modificada | Alta (7.5) | 1.7% | — | Mavili Guestbook Project Mavili Guestbook | 4/10/2012 | 16/6/2026 | Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) edit.asp, (2) delete.asp, or (3) approve.asp. | |
| Modificada | Media (5) | 1.5% | — | Mavili Guestbook Project Mavili Guestbook | 4/10/2012 | 16/6/2026 | Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attackers to read the database via a direct request. | |
| Modificada | Alta (7.5) | 1.3% | — | Mavili Guestbook Project Mavili Guestbook | 4/10/2012 | 16/6/2026 | SQL injection vulnerability in edit.asp in Mavili Guestbook, as released in November 2007, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Mavili Guestbook Project Mavili Guestbook | 4/10/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Mavili Guestbook, as released in November 2007, allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) approve.asp, (2) delete.asp, (3) edit.asp, or (4) edit2.asp. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Esoftpro Online Guestbook PRO | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in ogp_show.php in esoftpro Online Guestbook Pro 5.1 allows remote attackers to execute arbitrary SQL commands via the search parameter. | |
| Modificada | Alta (7.5) | 0.92% | 💥 Exploit | Esoftpro Online Guestbook PRO | 12/7/2010 | 16/6/2026 | SQL injection vulnerability in ogp_show.php in Online Guestbook Pro allows remote attackers to execute arbitrary SQL commands via the display parameter. | |
| Modificada | Media (4.3) | 0.85% | — | Esoftpro Online Guestbook PRO | 13/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the search_choice parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 0.93% | — | Esoftpro Online Guestbook PRO | 13/7/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ogp_show.php in Online Guestbook Pro 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2) display parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Esoftpro Online Guestbook PRO | 13/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter. | |
| Modificada | Media (6.5) | 4.3% | 💥 Exploit | Dmsguestbook Project Dmsguestbook | 6/2/2008 | 16/6/2026 | SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors. NOTE: it is not clear whether this issue crosses privilege boundaries. | |
| Modificada | Media (4.3) | 2.3% | — | Dmsguestbook Project Dmsguestbook | 6/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter to wp-admin/admin.php, or the (2) messagefield parameter in the guestbook page, and the (3) title parameter in the messagearea. | |
| Modificada | Media (4.3) | 1.5% | — | Dmsguestbook Project Dmsguestbook | 6/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) gbname, (2) gbemail, (3) gburl, and (4) gbmsg parameters to unspecified programs. NOTE: the provenance of this information is unknown;… | |
| Modificada | Media (4) | 3.1% | — | Dmsguestbook Project Dmsguestbook | 6/2/2008 | 16/6/2026 | Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) folder and (2) file parameters. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Fantastic Guestbook Project Fantastic Guestbook | 13/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php in Fantastic Guestbook 2.0.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) nickname parameters. | |
| Modificada | Media (4.3) | 1.6% | — | Cjguestbook Project Cjguestbook | 24/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject Javascript code via a javascript URI in an img bbcode tag in the comments parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Pixysoft Guestbook PRO | 11/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message. |