Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2576▼ 298 respecto a la semana anterior
Críticas / altas1356▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
99 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Baja (3.7) | 0.14% | — | Smackcoders WP Ultimate CSV ImporterAI | 3/10/2026 | 3/10/2026 | The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a… | |
| Recibida | Baja (3.5) | 0.15% | — | Smackcoders WP Ultimate CSV ImporterAI | 3/10/2026 | 3/10/2026 | The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite… | |
| Aplazada | Media (5.3) | 0.20% | — | Smackcoders WP Ultimate CSV ImporterAI | 1/10/2026 | 1/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate CSV Importer: from n/a through 9.1. | |
| Aplazada | Media (6.5) | 0.17% | — | Podcast ImporterAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions. | |
| Aplazada | Media (4.1) | 0.31% | — | Smackcoders WP Ultimate CSV ImporterAI | 29/8/2026 | 31/8/2026 | The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. | |
| Pendiente de análisis | Alta (7.7) | 0.57% | — | Kubevirt Containerized Data ImporterAI | 27/7/2026 | 21/9/2026 | In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the… | |
| Aplazada | Media (5.9) | 0.24% | — | Hashthemes Demo ImporterAI | 23/7/2026 | 23/7/2026 | Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Really Simple CSV ImporterAI | 23/7/2026 | 23/7/2026 | Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. | |
| Aplazada | Alta (8.8) | 1.1% | — | Smackcoders WP Ultimate CSV ImporterAI | 11/7/2026 | 13/7/2026 | The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, saveMappedFields, and… | |
| Aplazada | Media (4.4) | 0.24% | — | WP Ultimate CSV Importer Infinite Scroll Ajax Load MoreAI | 10/7/2026 | 14/7/2026 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Media (4.3) | 0.26% | — | Gsheet FOR WOO ImporterAI | 21/5/2026 | 23/7/2026 | The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the process_ajax_restore_action() function in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete… | |
| Aplazada | Alta (8.7) | 0.61% | — | Woocommerce CSV ImporterAI | 17/5/2026 | 17/6/2026 | Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX action. Attackers can craft POST requests with directory traversal sequences in the filename parameter to delete… | |
| Aplazada | Media (5.3) | 0.31% | — | Themegrill Demo ImporterAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ThemeGrill Demo Importer: from n/a through <= 2.0.0.6. | |
| Analizada | Media (6.9) | 0.17% | — | Cewe Photo Importer | 21/3/2026 | 17/6/2026 | CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers can create a malformed JPG file with an oversized buffer and trigger the crash through the import functionality during the image processing… | |
| Aplazada | Media (4.4) | 0.21% | — | Tp2wp ImporterAI | 26/2/2026 | 17/6/2026 | The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea on the attachment importer settings page in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping when domains are saved via AJAX and rendered… | |
| Aplazada | Media (5.4) | 0.20% | — | Mizan Themes Mizan Demo ImporterAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3. | |
| Aplazada | Media (4.3) | 0.18% | — | Wpelemento ImporterAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in wpelemento WPElemento Importer wpelemento-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPElemento Importer: from n/a through <= 0.6.4. | |
| Aplazada | Alta (8.5) | 0.38% | — | Kubevirt Containerized Data ImporterAI | 26/1/2026 | 15/7/2026 | A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC source mechanism. | |
| Aplazada | Media (4.3) | 0.15% | — | Aa-team Wordpress Movies Bulk ImporterAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AA-Team Wordpress Movies Bulk Importer movies importer allows Cross Site Request Forgery.This issue affects Wordpress Movies Bulk Importer: from n/a through <= 1.0. | |
| Aplazada | Alta (7.5) | 0.43% | — | Kraftplugins Demo Importer PlusAI | 17/1/2026 | 17/6/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the SVG file upload functionality. This makes it possible for authenticated attackers, with Author-level access and above, to achieve code execution in vulnerable… | |
| Aplazada | Media (6.4) | 0.23% | — | URL Image ImporterAI | 6/1/2026 | 17/6/2026 | The URL Image Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.7 due to insufficient sanitization of SVG files. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web… | |
| Aplazada | Media (6.4) | 0.27% | — | WP Import Ultimate CSV XML ImporterAI | 1/1/2026 | 17/6/2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due to inadequate validation of the resolved URL after following Bitly shortlink redirects in the `upload_function()` method. While the initial… | |
| Aplazada | Media (4.3) | 0.18% | — | Kraftplugins Demo Importer PlusAI | 30/12/2025 | 1/10/2026 | Missing Authorization vulnerability in Kraft Plugins Demo Importer Plus demo-importer-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Importer Plus: from n/a through <= 2.0.8. | |
| Aplazada | Alta (8.8) | 0.35% | — | Kraftplugins Demo Importer PlusAI | 18/12/2025 | 17/6/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privilege escalation due to a missing capability check on the Ajax::handle_request() function in all versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.1) | 0.27% | — | Blaze Demo ImporterAI | 12/12/2025 | 17/6/2026 | The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a missing capability check on the "blaze_demo_importer_install_demo" function in all versions up to, and including, 1.0.13. This makes it possible for authenticated attackers, with subscriber level… |