Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8) | 0.34% | — | Unbounce Landing PagesAI | 19/9/2026 | 21/9/2026 | The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin. | |
| Aplazada | Alta (7.1) | 0.32% | — | Unbounce Landing PagesAI | 8/9/2026 | 8/9/2026 | Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a through 1.1.4. | |
| Aplazada | Media (4.3) | 0.19% | — | Pluginops Landing Page BuilderAI | 16/7/2026 | 17/7/2026 | The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.3.6. This is due to missing or incorrect nonce validation on the ulpb_admin_ajax function. This makes it possible… | |
| Aplazada | Alta (7.1) | 0.25% | — | Pluginops Landing Page BuilderAI | 29/6/2026 | 29/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Rarathemes Lawyer Landing PageAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lawyer Landing Page: from n/a through <= 1.2.7. | |
| Aplazada | Media (5.3) | 0.29% | — | Raratheme APP Landing PageAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme App Landing Page app-landing-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects App Landing Page: from n/a through <= 1.2.2. | |
| Aplazada | Media (5.3) | 0.29% | — | Rarathemes Book Landing PageAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme Book Landing Page book-landing-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Book Landing Page: from n/a through <= 1.2.7. | |
| Aplazada | Media (5.3) | 0.29% | — | Rarathemes Construction Landing PageAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme Construction Landing Page construction-landing-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Construction Landing Page: from n/a through <= 1.4.1. | |
| Aplazada | Media (4.3) | 0.13% | — | Font Pairing Preview FOR Landing PagesAI | 7/3/2026 | 17/6/2026 | The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's font pairing… | |
| Aplazada | Media (5.9) | 0.20% | — | Pluginops Landing Page BuilderAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder page-builder-add allows Stored XSS.This issue affects Landing Page Builder: from n/a through <= 1.5.3.4. | |
| Aplazada | Media (5.4) | 0.20% | — | Niklaslindemann Bulk Landing Page Creator FOR Wordpress LpageryAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in niklaslindemann Bulk Landing Page Creator for WordPress LPagery lpagery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk Landing Page Creator for WordPress LPagery: from n/a through <= 2.4.9. | |
| Aplazada | Media (5.3) | 0.33% | — | Moosend Landing PagesAI | 7/1/2026 | 17/6/2026 | The Moosend Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the moosend_landings_auth_get function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Alta (8.8) | 0.30% | — | Aa-team Premium AGE Verification / Restriction FOR WordpressAIAa-team Responsive Coming Soon Landing Page / Holding Page FOR WordpressAI | 6/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive… | |
| Aplazada | Media (4.3) | 0.15% | — | WP Landing PageAI | 6/12/2025 | 17/6/2026 | The WP Landing Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to missing nonce validation on the 'wplp_api_update_text' function. This makes it possible for unauthenticated attackers to update arbitrary post meta via a forged request… | |
| Aplazada | Media (5.9) | 0.22% | — | Wpdrift Landing-pages-and-domain-aliasesAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdrift.no Landing pages and Domain aliases for WordPress landing-pages-and-domain-aliases allows Stored XSS.This issue affects Landing pages and Domain aliases for WordPress: from n/a through <= 0.8. | |
| Aplazada | Alta (7.1) | 0.15% | — | Eslam Mahmoud Redirect Wordpress TO Welcome OR Landing PageAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Eslam Mahmoud Redirect wordpress to welcome or landing page redirect-to-welcome-or-landing-page allows Stored XSS.This issue affects Redirect wordpress to welcome or landing page: from n/a through <= 2.0. | |
| Aplazada | Alta (7.1) | 0.23% | — | Fatcatapps Landing Page CATAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing Page Cat landing-page-cat allows Reflected XSS.This issue affects Landing Page Cat: from n/a through <= 1.7.8. | |
| Aplazada | Alta (7.1) | 0.32% | — | Fatcatapps Landing Page CATAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps Landing Page Cat landing-page-cat allows Reflected XSS.This issue affects Landing Page Cat: from n/a through <= 1.7.7. | |
| Modificada | Alta (8.8) | 0.19% | — | Rarathemes Construction Landing Page | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in raratheme Construction Landing Page construction-landing-page allows Cross Site Request Forgery.This issue affects Construction Landing Page: from n/a through <= 1.3.5. | |
| Modificada | Alta (8.8) | 0.22% | — | Rarathemes Lawyer Landing Page | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Cross Site Request Forgery.This issue affects Lawyer Landing Page: from n/a through <= 1.2.4. | |
| Aplazada | Media (5.4) | 0.39% | — | Fatcatapps Landing Page CATAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in fatcatapps Landing Page Cat landing-page-cat.This issue affects Landing Page Cat: from n/a through <= 1.7.4. | |
| Aplazada | Media (5.3) | 0.52% | — | 8degreethemes Coming Soon Landing Page AND Maintenance ModeAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in 8Degree Themes Coming Soon Landing Page and Maintenance Mode WordPress Plugin allows Retrieve Embedded Sensitive Data.This issue affects Coming Soon Landing Page and Maintenance Mode WordPress Plugin: from n/a through 2.2.0. | |
| Aplazada | Media (6.1) | 0.45% | — | SEO Landing Page GeneratorAI | 28/11/2024 | 17/6/2026 | The SEO Landing Page Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.66.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.1) | 0.37% | — | Fatcatapps Landing Page CATAI | 9/11/2024 | 17/6/2026 | The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.7.6. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.5) | 0.54% | — | Pluginops Landing Page BuilderAI | 19/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginOps Landing Page Builder allows PHP Local File Inclusion.This issue affects Landing Page Builder: from n/a through 1.5.2.0. |