Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 303 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.35% | — | Benjaminjonard KoillectionAI | 15/6/2026 | 17/6/2026 | An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted URL. | |
| Aplazada | Media (5.9) | 0.29% | — | Benjamin Intal Stackable Ultimate Gutenberg BlocksAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Stored XSS.This issue affects Stackable: from n/a through <= 3.19.5. | |
| Aplazada | Media (4.3) | 0.30% | — | Nawawi Jamili Docket CacheAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Nawawi Jamili Docket Cache docket-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Docket Cache: from n/a through <= 24.07.04. | |
| Aplazada | Alta (8.1) | 0.48% | — | Nawawi Jamili Docket CacheAIPHPAI | 24/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nawawi Jamili Docket Cache docket-cache allows PHP Local File Inclusion.This issue affects Docket Cache: from n/a through <= 24.07.03. | |
| Aplazada | Media (6.5) | 0.20% | — | Russelljamieson Genesis Club LiteAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Genesis Club Lite genesis-club-lite allows Stored XSS.This issue affects Genesis Club Lite: from n/a through <= 1.17. | |
| Aplazada | Media (6.5) | 0.20% | — | Benjamin Pick Geolocation IP DetectionAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Pick Geolocation IP Detection geoip-detect allows Stored XSS.This issue affects Geolocation IP Detection: from n/a through <= 5.5.0. | |
| Aplazada | Media (5.9) | 0.22% | — | Russelljamieson AuthorsureAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson AuthorSure authorsure allows Stored XSS.This issue affects AuthorSure: from n/a through <= 2.3. | |
| Analizada | Baja (2.1) | 0.41% | — | Benjaminjonard Koillection | 31/8/2025 | 17/6/2026 | A vulnerability has been found in Koillection up to 1.6.18. Affected is an unknown function of the file assets/controllers/csrf_protection_controller.js. Such manipulation leads to cross-site request forgery. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading… | |
| Aplazada | Alta (7.5) | 0.53% | — | Benjamin Denis Seopress FOR MainwpAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Benjamin Denis SEOPress for MainWP seopress-for-mainwp allows PHP Local File Inclusion.This issue affects SEOPress for MainWP: from n/a through <= 1.4. | |
| Aplazada | Alta (7.1) | 0.23% | — | Russelljamieson CaptionpixAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson CaptionPix captionpix allows Reflected XSS.This issue affects CaptionPix: from n/a through <= 1.8. | |
| Analizada | Media (6.1) | 0.16% | — | Ulfbenjaminsson Smooth Gallery Replacement | 15/5/2025 | 17/6/2026 | The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Analizada | Media (6.1) | 0.29% | — | Benjaminjonard Koillection | 7/5/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Koillection v.1.6.10 allows a remote attacker to escalate privileges via the collection, Wishlist and album components | |
| Aplazada | Media (5.9) | 0.27% | — | Benjamin Buddle Send FromAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Buddle Send From send-from allows Stored XSS.This issue affects Send From: from n/a through <= 2.2. | |
| Aplazada | Alta (7.5) | 0.70% | — | Nawawi Jamili Docket CacheAIPHPAI | 17/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nawawi Jamili Docket Cache docket-cache allows PHP Local File Inclusion.This issue affects Docket Cache: from n/a through <= 24.07.02. | |
| Analizada | Media (4.9) | 0.53% | — | Benjaminrojas WP Editor | 17/4/2025 | 17/6/2026 | The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files on the affected site's server which may reveal sensitive information. | |
| Analizada | Alta (7.2) | 1.0% | — | Benjaminrojas WP Editor | 17/4/2025 | 17/6/2026 | The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to overwrite arbitrary files on the affected site's server which… | |
| Aplazada | Media (5.9) | 0.40% | — | Benjamin Chris WP EditormdAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Chris WP Editor.md – The Perfect WordPress Markdown Editor wp-editormd allows Stored XSS.This issue affects WP Editor.md – The Perfect WordPress Markdown Editor: from n/a through <= 10.2.1. | |
| Aplazada | Media (4.3) | 0.17% | — | Benjamin Pick Contact Form 7 Select BOX Editor ButtonAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Benjamin Pick Contact Form 7 Select Box Editor Button contact-form-7-select-box-editor-button allows Cross Site Request Forgery.This issue affects Contact Form 7 Select Box Editor Button: from n/a through <= 0.6. | |
| Aplazada | Alta (7.1) | 0.17% | — | Jamie O Idealien Category EnhancementsAI | 28/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jamie O Idealien Category Enhancements idealien-category-enhancements allows Stored XSS.This issue affects Idealien Category Enhancements: from n/a through <= 1.2. | |
| Analizada | Media (5.4) | 0.30% | — | Benjaminzekavica Easy SVG Support | 8/11/2024 | 17/6/2026 | The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Analizada | Alta (7.2) | 0.58% | — | Benjaminrojas WP Editor | 13/9/2024 | 17/6/2026 | The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call… | |
| Aplazada | Media (5.4) | 0.31% | — | Jamie Bergen Plugin Notes PlusAI | 19/8/2024 | 17/6/2026 | Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Plugin Notes Plus: from n/a through 1.2.7. | |
| Aplazada | Media (5.9) | 0.27% | — | Jamie Bergen Plugin Notes PlusAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jamie Bergen Plugin Notes Plus allows Stored XSS.This issue affects Plugin Notes Plus: from n/a through 1.2.6. | |
| Aplazada | Alta (7.1) | 0.35% | — | Benjaminrojas WP EditorAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Rojas WP Editor allows Reflected XSS.This issue affects WP Editor: from n/a through 1.2.8. | |
| Modificada | Alta (7.5) | 0.45% | — | Benjaminrojas WP Editor | 17/3/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Benjamin Rojas WP Editor.This issue affects WP Editor: from n/a through 1.2.7. |