Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.14% | — | Paytr Virtual POS Iframe APIAIWhmcsAI | 9/9/2026 | 1/10/2026 | Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API WHMCS Module: from v9.0.0 before v9.0.3. | |
| Aplazada | Alta (7.5) | 0.30% | — | Paytr Virtual POS Iframe APIAIPaytr Whmcs ModuleAI | 8/9/2026 | 1/10/2026 | Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API WHMCS Module allows Black Box Reverse Engineering. This issue affects PayTR Virtual Pos iFrame API WHMCS Module: from v9.0.0 before v9.0.3. | |
| Aplazada | Alta (7.5) | 0.32% | — | Paytr Virtual POS Iframe APIAIWhmcsAI | 8/9/2026 | 1/10/2026 | Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API WHMCS Module allows Input Data Manipulation. This issue affects PayTR Virtual Pos iFrame API WHMCS Module: from v9.0.0 before v9.0.3. | |
| Aplazada | Media (6.4) | 0.26% | — | Tinywebgallery Advanced IframeAI | 8/7/2026 | 8/7/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (6.4) | 0.32% | — | WP Iframe GEO Style FOR Amazon AffiliatesAI | 27/5/2026 | 17/6/2026 | The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Alta (7.4) | 0.50% | — | Yiiframework YIIAI | 20/5/2026 | 23/7/2026 | Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local File Inclusion. The function calls extract($_params_, EXTR_OVERWRITE) before the require statement that loads the view file. As a result, a caller-controlled… | |
| Aplazada | Media (6.5) | 0.23% | — | Tinywebgallery Advanced IframeAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdempfle Advanced iFrame advanced-iframe allows DOM-Based XSS.This issue affects Advanced iFrame: from n/a through <= 2025.10. | |
| Aplazada | Media (6.4) | 0.18% | — | Inline Frame IframeAI | 25/11/2025 | 17/6/2026 | The Inline frame – Iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedsite' shortcode in all versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.23% | — | Responsive Iframe GooglemapAI | 22/10/2025 | 17/6/2026 | The Responsive iframe GoogleMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'responsive_map' shortcode in all versions up to, and including, 1.0.2. This is due to insufficient input sanitization and output escaping on the 'width' and 'height' attributes. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.20% | — | Coderz Studio Custom Iframe FOR ElementorAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coderz Studio Custom iFrame for Elementor custom-iframe allows DOM-Based XSS.This issue affects Custom iFrame for Elementor: from n/a through <= 1.0.13. | |
| Aplazada | Alta (7.1) | 0.24% | — | Vikas Sharma Iframe BlockAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vikas Sharma iFrame Block allows Stored XSS. This issue affects iFrame Block: from n/a through 0.1.1. | |
| Aplazada | Media (5.4) | 0.24% | — | Tinywebgallery Advanced IframeAI | 16/8/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in version less than, or equal to, 2025.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (6.4) | 0.30% | — | Tinywebgallery Advanced IframeAI | 26/7/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (8.5) | 0.27% | — | Gopiplus Iframe Images GalleryAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus iFrame Images Gallery wp-iframe-images-gallery allows SQL Injection.This issue affects iFrame Images Gallery: from n/a through <= 9.0. | |
| Aplazada | Media (5.9) | 0.25% | — | Debashish Iframe WidgetAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debashish IFrame Widget iframe-widget allows Stored XSS.This issue affects IFrame Widget: from n/a through <= 4.1. | |
| Analizada | Media (5.1) | 0.32% | — | Yiiframework Yii2-redis | 5/6/2025 | 17/6/2026 | The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the extension writes commands sequence to logs. Prior to version 2.0.20, AUTH parameters are written in plain text exposing username and password. That might be an issue if attacker has access to… | |
| Modificada | Media (6.1) | 0.27% | — | Iframe Remove Filter Project Iframe Remove Filter | 14/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal IFrame Remove Filter allows Cross-Site Scripting (XSS).This issue affects IFrame Remove Filter: from 2.0.0 before 2.0.5, from 7.X-1.0 through 7.X-1.5, from 1.0 through 1.2. | |
| Analizada | Media (6.1) | 0.24% | — | Yiiframework YII | 10/4/2025 | 17/6/2026 | Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. Upgrade yiisoft/yii to version 1.1.31 or higher. | |
| Analizada | Crítica (9.8) | 88% | ⚠ Explotación activa | Yiiframework YII | 10/4/2025 | 17/6/2026 | Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025. | |
| Analizada | Media (5.3) | 0.29% | — | Tinywebgallery Advanced Iframe | 26/3/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData… | |
| Analizada | Media (5.4) | 0.21% | — | Tinywebgallery Advanced Iframe | 26/3/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 due to insufficient input sanitization and output escaping on user supplied attributes through the 'src' attribute when the src supplied… | |
| Modificada | Media (5.4) | 0.26% | — | Tinywebgallery Advanced Iframe | 26/3/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Media (5.3) | 0.66% | — | Yiiframework YII | 24/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src\Framework\MockObject\MockClass.php. The manipulation leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.62% | — | Yiiframework YII | 24/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to… | |
| Analizada | Crítica (9.1) | 80% | — | Yiiframework YII | 20/3/2025 | 17/6/2026 | In yiisoft/yii2 version 2.0.48, the base Component class contains a vulnerability where the `__set()` magic method does not validate that the value passed is a valid Behavior class name or configuration. This allows an attacker to instantiate arbitrary classes, passing parameters to their constructors and invoking… |