Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2576▼ 298 respecto a la semana anterior
Críticas / altas1356▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

99 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaBaja (3.7)0.14%—Smackcoders WP Ultimate CSV ImporterAI3/10/20263/10/2026
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not use a site-specific secret when deriving the storage location of the import logs it writes under the uploads directory, nor does it block direct access to them, allowing unauthenticated attackers to retrieve the personal data of users imported from a…
RecibidaBaja (3.5)0.15%—Smackcoders WP Ultimate CSV ImporterAI3/10/20263/10/2026
The WP Ultimate CSV Importer WordPress plugin before 9.2 does not properly validate the file types contained in an uploaded archive nor sanitise their content before storing them in a publicly served location, allowing high privilege users such as administrators to achieve Stored Cross-Site Scripting. On Multisite…
AplazadaMedia (5.3)0.20%—Smackcoders WP Ultimate CSV ImporterAI1/10/20261/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate CSV Importer: from n/a through 9.1.
AplazadaMedia (6.5)0.17%—Podcast ImporterAI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions.
AplazadaMedia (4.1)0.31%—Smackcoders WP Ultimate CSV ImporterAI29/8/202631/8/2026
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.
Pendiente de análisisAlta (7.7)0.57%—Kubevirt Containerized Data ImporterAI27/7/202621/9/2026
In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the…
AplazadaMedia (5.9)0.24%—Hashthemes Demo ImporterAI23/7/202623/7/2026
Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.
AplazadaCrítica (9.1)0.50%—Really Simple CSV ImporterAI23/7/202623/7/2026
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
AplazadaAlta (8.8)1.1%—Smackcoders WP Ultimate CSV ImporterAI11/7/202613/7/2026
The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, saveMappedFields, and…
AplazadaMedia (4.4)0.24%—WP Ultimate CSV Importer Infinite Scroll Ajax Load MoreAI10/7/202614/7/2026
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
AplazadaMedia (4.3)0.26%—Gsheet FOR WOO ImporterAI21/5/202623/7/2026
The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the process_ajax_restore_action() function in all versions up to, and including, 2.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete…
AplazadaAlta (8.7)0.61%—Woocommerce CSV ImporterAI17/5/202617/6/2026
Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX action. Attackers can craft POST requests with directory traversal sequences in the filename parameter to delete…
AplazadaMedia (5.3)0.31%—Themegrill Demo ImporterAI15/4/202617/6/2026
Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ThemeGrill Demo Importer: from n/a through <= 2.0.0.6.
AnalizadaMedia (6.9)0.17%—Cewe Photo Importer21/3/202617/6/2026
CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers can create a malformed JPG file with an oversized buffer and trigger the crash through the import functionality during the image processing…
AplazadaMedia (4.4)0.21%—Tp2wp ImporterAI26/2/202617/6/2026
The TP2WP Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Watched domains' textarea on the attachment importer settings page in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping when domains are saved via AJAX and rendered…
AplazadaMedia (5.4)0.20%—Mizan Themes Mizan Demo ImporterAI3/2/202617/6/2026
Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3.
AplazadaMedia (4.3)0.18%—Wpelemento ImporterAI3/2/202617/6/2026
Missing Authorization vulnerability in wpelemento WPElemento Importer wpelemento-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPElemento Importer: from n/a through <= 0.6.4.
AplazadaAlta (8.5)0.38%—Kubevirt Containerized Data ImporterAI26/1/202615/7/2026
A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolumeClaims (PVCs) from unauthorized namespaces, resulting in unauthorized access to data via the DataImportCron PVC source mechanism.
AplazadaMedia (4.3)0.15%—Aa-team Wordpress Movies Bulk ImporterAI22/1/202617/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in AA-Team Wordpress Movies Bulk Importer movies importer allows Cross Site Request Forgery.This issue affects Wordpress Movies Bulk Importer: from n/a through <= 1.0.
AplazadaAlta (7.5)0.43%—Kraftplugins Demo Importer PlusAI17/1/202617/6/2026
The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the SVG file upload functionality. This makes it possible for authenticated attackers, with Author-level access and above, to achieve code execution in vulnerable…
AplazadaMedia (6.4)0.23%—URL Image ImporterAI6/1/202617/6/2026
The URL Image Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.7 due to insufficient sanitization of SVG files. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web…
AplazadaMedia (6.4)0.27%—WP Import Ultimate CSV XML ImporterAI1/1/202617/6/2026
The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.35. This is due to inadequate validation of the resolved URL after following Bitly shortlink redirects in the `upload_function()` method. While the initial…
AplazadaMedia (4.3)0.18%—Kraftplugins Demo Importer PlusAI30/12/20251/10/2026
Missing Authorization vulnerability in Kraft Plugins Demo Importer Plus demo-importer-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Importer Plus: from n/a through <= 2.0.8.
AplazadaAlta (8.8)0.35%—Kraftplugins Demo Importer PlusAI18/12/202517/6/2026
The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privilege escalation due to a missing capability check on the Ajax::handle_request() function in all versions up to, and including, 2.0.8. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.1)0.27%—Blaze Demo ImporterAI12/12/202517/6/2026
The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a missing capability check on the "blaze_demo_importer_install_demo" function in all versions up to, and including, 1.0.13. This makes it possible for authenticated attackers, with subscriber level…