Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.50%—Comment Guestbook Project Comment Guestbook30/9/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress.
ModificadaMedia (6.1)0.73%—Gwolle Guestbook Project Gwolle Guestbook23/6/202217/6/2026
A vulnerability was found in Gwolle Guestbook Plugin 1.7.4. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting. The attack may be initiated remotely.
ModificadaMedia (6.1)0.80%—Gwolle Guestbook Project Gwolle Guestbook27/12/202117/6/2026
The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin page
ModificadaMedia (6.1)1.2%—Gwolle Guestbook Project Gwolle Guestbook2/10/201817/6/2026
XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via the PATH_INFO to wp-admin/index.php
ModificadaCrítica (9)37%💥 ExploitGwolle Guestbook Project Gwolle Guestbook11/9/201717/6/2026
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and…
ModificadaAlta (7.5)1.7%—Mavili Guestbook Project Mavili Guestbook4/10/201216/6/2026
Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) edit.asp, (2) delete.asp, or (3) approve.asp.
ModificadaMedia (5)1.5%—Mavili Guestbook Project Mavili Guestbook4/10/201216/6/2026
Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attackers to read the database via a direct request.
ModificadaAlta (7.5)1.3%—Mavili Guestbook Project Mavili Guestbook4/10/201216/6/2026
SQL injection vulnerability in edit.asp in Mavili Guestbook, as released in November 2007, allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.2%—Mavili Guestbook Project Mavili Guestbook4/10/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Mavili Guestbook, as released in November 2007, allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) approve.asp, (2) delete.asp, (3) edit.asp, or (4) edit2.asp.
ModificadaAlta (7.5)1.00%💥 ExploitEsoftpro Online Guestbook PRO1/11/201116/6/2026
SQL injection vulnerability in ogp_show.php in esoftpro Online Guestbook Pro 5.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.
ModificadaAlta (7.5)0.92%💥 ExploitEsoftpro Online Guestbook PRO12/7/201016/6/2026
SQL injection vulnerability in ogp_show.php in Online Guestbook Pro allows remote attackers to execute arbitrary SQL commands via the display parameter.
ModificadaMedia (4.3)0.85%—Esoftpro Online Guestbook PRO13/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the search_choice parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)0.93%—Esoftpro Online Guestbook PRO13/7/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ogp_show.php in Online Guestbook Pro 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2) display parameter.
ModificadaMedia (4.3)1.5%💥 ExploitEsoftpro Online Guestbook PRO13/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter.
ModificadaMedia (6.5)4.3%💥 ExploitDmsguestbook Project Dmsguestbook6/2/200816/6/2026
SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.
ModificadaMedia (4.3)2.3%—Dmsguestbook Project Dmsguestbook6/2/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter to wp-admin/admin.php, or the (2) messagefield parameter in the guestbook page, and the (3) title parameter in the messagearea.
ModificadaMedia (4.3)1.5%—Dmsguestbook Project Dmsguestbook6/2/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) gbname, (2) gbemail, (3) gburl, and (4) gbmsg parameters to unspecified programs. NOTE: the provenance of this information is unknown;…
ModificadaMedia (4)3.1%—Dmsguestbook Project Dmsguestbook6/2/200816/6/2026
Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) folder and (2) file parameters.
ModificadaMedia (4.3)2.3%💥 ExploitFantastic Guestbook Project Fantastic Guestbook13/7/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php in Fantastic Guestbook 2.0.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) nickname parameters.
ModificadaMedia (4.3)1.6%—Cjguestbook Project Cjguestbook24/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in sign.php in cjGuestbook 1.3 and earlier allows remote attackers to inject Javascript code via a javascript URI in an img bbcode tag in the comments parameter.
ModificadaMedia (4.3)1.4%—Pixysoft Guestbook PRO11/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.
Orbitaley — Vulnerabilidades