Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 272 respecto a la semana anterior
Críticas / altas1349▲ 92 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.29% | — | Social Media Share Buttons Social Sharing IconsAI | 1/10/2026 | 3/10/2026 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (7.1) | 0.18% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button.… | |
| Aplazada | Media (6.8) | 0.29% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts… | |
| Aplazada | Alta (7.1) | 0.25% | — | Social Media AND Share IconsAI | 24/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Creativews CWS SvgiconsAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVGicons cws-svgicons allows Blind SQL Injection.This issue affects CWS SVGicons: from n/a through <= 1.5.5. | |
| Aplazada | Baja (1.9) | 0.17% | — | Better-auth Better-iconsAI | 13/7/2026 | 13/7/2026 | A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects unknown code of the component scan_project_icons/sync_icon. Such manipulation of the argument icons_file leads to path traversal. An attack has to be approached locally. The exploit has been disclosed to the public and… | |
| Aplazada | Media (4.3) | 0.21% | — | Inisev Social Media AND Share IconsAI | 17/6/2026 | 1/10/2026 | : Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & Share Icons: from n/a through 2.8.6. | |
| Aplazada | Media (6.4) | 0.33% | — | Advanced Social Media IconsAI | 12/5/2026 | 17/6/2026 | The Advanced Social Media Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `social` shortcode in all versions up to, and including, 1.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.1) | 0.24% | — | Accesspress Social IconsAI | 10/5/2026 | 25/7/2026 | AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering JavaScript payloads into the 'icon title' field. Attackers can store XSS payloads like image tags with onerror event handlers that execute when the plugin page… | |
| Analizada | Media (4.8) | 0.24% | — | Pixelite Responsive Favicons | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Responsive Favicons allows Cross-Site Scripting (XSS).This issue affects Responsive Favicons: from 0.0.0 before 2.0.2. | |
| Analizada | Media (5.3) | 0.29% | — | Imagexmedia Material Icons | 25/3/2026 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This issue affects Material Icons: from 0.0.0 before 2.0.4. | |
| Analizada | Media (6.1) | 0.15% | — | Beyris UI Icons | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Icons allows Cross-Site Scripting (XSS).This issue affects UI Icons: from 0.0.0 before 1.0.1, from 1.1.0 before 1.1.1. | |
| Aplazada | Alta (8.3) | 0.32% | — | Mimetypes Link IconsAI | 21/3/2026 | 17/6/2026 | The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due to the plugin making outbound HTTP requests to user-controlled URLs without proper validation when the "Show file size" option is enabled. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.34% | — | Wpzoom Social Icons Widget AND BlockAI | 13/3/2026 | 17/6/2026 | The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the add_menu_item() method hooked to admin_menu in all versions up to, and including, 4.5.8. This is due to the method performing wp_insert_post() and update_post_meta()… | |
| Aplazada | Media (6.4) | 0.21% | — | Themeisle Menu IconsAI | 3/2/2026 | 17/6/2026 | The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_wp_attachment_image_alt’ post meta in all versions up to, and including, 0.13.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level… | |
| Aplazada | Media (6.5) | 0.20% | — | Themifyme Themify-iconsAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Icons themify-icons allows Stored XSS.This issue affects Themify Icons: from n/a through <= 2.0.3. | |
| Aplazada | Crítica (9.8) | 0.70% | — | Icons FactoryAI | 15/8/2025 | 17/6/2026 | The Icons Factory plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient authorization and improper path validation within the delete_files() function in all versions up to, and including, 1.6.12. This makes it possible for unauthenticated attackers to to delete arbitrary files on the… | |
| Analizada | Media (4.8) | 0.34% | — | Inisev Social Media Share Buttons & Social Sharing Icons | 15/5/2025 | 17/6/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite… | |
| Aplazada | Alta (7.1) | 0.29% | — | Bjornw File IconsAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BjornW File Icons file-icons allows Reflected XSS.This issue affects File Icons: from n/a through <= 2.1. | |
| Aplazada | Media (6.4) | 0.33% | — | Smart Icons FOR WordpressAI | 2/4/2025 | 17/6/2026 | The Smart Icons For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Editor-level access and above, to inject… | |
| Aplazada | Media (5.3) | 0.47% | — | Simple IconsAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Travis Simple Icons simple-icons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Icons: from n/a through <= 2.8.4. | |
| Aplazada | Media (5.9) | 0.26% | — | Vasilis Triantafyllou Flag IconsAIVasilis Triantafyllou Language-icons-flags-switcherAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Vasilis Triantafyllou Flag Icons language-icons-flags-switcher allows Stored XSS.This issue affects Flag Icons: from n/a through <= 2.2. | |
| Aplazada | Alta (7.1) | 0.20% | — | Origothemes Extra Options FaviconsAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in OrigoThemes Extra Options – Favicons extra-options-favicons allows Stored XSS.This issue affects Extra Options – Favicons: from n/a through <= 1.1.0. | |
| Aplazada | Media (6.5) | 0.27% | — | Copist Icons EnricherAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in copist Icons Enricher icons-enricher allows Stored XSS.This issue affects Icons Enricher: from n/a through <= 1.0.8. | |
| Aplazada | Media (4.3) | 0.35% | — | Social Share PRO Social Share Icons AND Social Share ButtonsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in social share pro Social Share Icons & Social Share Buttons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.5.7. |