Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4) | 0.16% | — | Ylefebvre Link LibraryAI | 25/9/2026 | 25/9/2026 | The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling back to an unprotected fetch when its safe request is rejected, allowing unauthenticated visitors to make the site issue requests to hosts on its internal network and to learn from the response… | |
| Aplazada | Media (4.1) | 0.24% | — | Ylefebvre Link LibraryAI | 25/9/2026 | 25/9/2026 | The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the Contributor role and above to create directories and write or overwrite image files anywhere the web server can write, including outside the site's… | |
| Aplazada | Media (6.1) | 0.15% | — | Ylefebvre Link LibraryAI | 25/9/2026 | 25/9/2026 | The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its front-end directory pages, leading to Reflected Cross-Site Scripting which could be used against any visitor, including logged-in administrators. | |
| Aplazada | Crítica (9.1) | 1.4% | — | Ylefebvre Link LibraryAI | 15/8/2026 | 20/8/2026 | The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead… | |
| Aplazada | Media (6.1) | 0.27% | — | Ylefebvre Link LibraryAI | 8/8/2026 | 26/8/2026 | The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who can be tricked into performing an action. | |
| Aplazada | Crítica (9.1) | 0.46% | — | Ylefebvre Link LibraryAI | 3/8/2026 | 26/8/2026 | The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | |
| Analizada | Media (6.4) | 0.28% | — | Ylefebvre Link Library | 29/7/2026 | 19/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Library: before 7.9.4. | |
| Aplazada | Alta (7.7) | 0.47% | — | Ylefebvre Link LibraryAI | 15/6/2026 | 17/6/2026 | Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions. | |
| Aplazada | Media (4.9) | 0.14% | — | Ylefebvre Link LibraryAI | 24/12/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Yannick Lefebvre Link Library link-library allows Server Side Request Forgery.This issue affects Link Library: from n/a through <= 7.8.7. | |
| Modificada | Media (5.4) | 0.22% | — | Ylefebvre Link Library | 22/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Stored XSS.This issue affects Link Library: from n/a through <= 7.8. | |
| Aplazada | Media (6.4) | 0.25% | — | Ylefebvre Link LibraryAI | 5/4/2025 | 17/6/2026 | The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Media (6.1) | 0.29% | — | Ylefebvre Link Library | 21/1/2025 | 17/6/2026 | The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'searchll' parameter in all versions up to, and including, 7.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (6.1) | 0.35% | — | Ylefebvre Link Library | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.7.1. | |
| Modificada | Media (6.1) | 0.33% | — | Ylefebvre Link Library | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library link-library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6.3. | |
| Modificada | Media (5.4) | 0.26% | — | Ylefebvre Link Library | 8/5/2024 | 17/6/2026 | The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, and including, 7.6.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (6.1) | 0.41% | — | Ylefebvre Link Library | 9/4/2024 | 17/6/2026 | The Link Library plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the searchll parameter in all versions up to, and including, 7.6.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Media (6.1) | 0.42% | — | Ylefebvre Link Library | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.6. | |
| Modificada | Media (6.1) | 0.41% | — | Ylefebvre Link Library | 20/2/2024 | 17/6/2026 | The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Alta (8.8) | 0.21% | — | Ylefebvre Link Library | 12/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Yannick Lefebvre Link Library.This issue affects Link Library: from n/a through 7.5.13. | |
| Modificada | Media (6.1) | 0.38% | — | Ylefebvre Link Library | 8/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.5.13. | |
| Modificada | Media (4.8) | 0.47% | — | Ylefebvre Link Library | 16/1/2023 | 17/6/2026 | The Link Library WordPress plugin before 7.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Alta (7.5) | 1.2% | — | Ylefebvre Link Library | 1/2/2022 | 17/6/2026 | The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request | |
| Modificada | Media (6.5) | 0.48% | — | Ylefebvre Link Library | 1/2/2022 | 17/6/2026 | The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin reset arbitrary settings via a CSRF attack | |
| Modificada | Media (6.1) | 0.80% | — | Ylefebvre Link Library | 1/2/2022 | 17/6/2026 | The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting |