Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
242 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | Radiustheme Classified ListingAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions. | |
| Aplazada | Alta (7.1) | 0.19% | — | Radiustheme Classified ListingAI | 4/9/2026 | 8/9/2026 | The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing… | |
| Aplazada | Media (5.4) | 0.29% | — | Radiustheme Classified ListingAI | 2/9/2026 | 23/9/2026 | Missing Authorization vulnerability in Mamunur Rashid Classified Listing classified-listing allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Classified Listing: from n/a through 6.1.3. | |
| Aplazada | Alta (8.1) | 0.33% | — | Classified Listing Mobile Number VerificationAI | 26/8/2026 | 26/8/2026 | The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.6.0. This is due to missing server-side Firebase OTP validation in the process_otp_login() function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.3) | 0.16% | — | Mlsimport IDX Plugin MLS Plugin FOR Real Estate ListingsAI | 5/8/2026 | 26/8/2026 | The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress… | |
| Aplazada | Baja (2.7) | 0.30% | — | Radiustheme Classified ListingAI | 3/8/2026 | 26/8/2026 | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators and report managers. | |
| Aplazada | Baja (2.7) | 0.30% | — | Radiustheme Classified ListingAI | 3/8/2026 | 26/8/2026 | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private… | |
| Aplazada | Media (6.4) | 0.33% | — | Realestateconnected Easy Property ListingsAI | 1/8/2026 | 12/8/2026 | The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Method in all versions up to, and including, 3.5.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Media (5.4) | 0.23% | — | Cridio ListingproAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in ListingPro <= 2.9.10 versions. | |
| Aplazada | Alta (8.8) | 0.20% | — | ApuslistingAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Stylemixthemes UlistingAI | 23/7/2026 | 23/7/2026 | Contributor Broken Access Control in uListing <= 2.2.0 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | Stylemixthemes UlistingAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in uListing <= 2.2.0 versions. | |
| Aplazada | Media (4.3) | 0.27% | — | Radiustheme Classified ListingAI | 21/7/2026 | 21/7/2026 | The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order. | |
| Aplazada | Media (6.5) | 0.30% | — | Radiustheme Classified ListingAI | 2/7/2026 | 2/7/2026 | Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Radiustheme Classified ListingAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Automotive ListingsAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Cridio ListingproAI | 26/6/2026 | 26/6/2026 | Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions. | |
| Analizada | Alta (8.8) | 0.43% | — | Faboba Ultimate Property Listing | 19/6/2026 | 19/8/2026 | Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the sf_selectuser_id parameter. Attackers can send GET requests to index.php with the option=com_upl and view=propertylisting… | |
| Aplazada | Media (4.3) | 0.37% | — | Radiustheme Classified ListingAI | 19/6/2026 | 22/6/2026 | The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capability/ownership check on the gallery_image_update_as_feature AJAX handler (action:… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Cridio ListingproAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Radiustheme Classified ListingAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions. | |
| Aplazada | Media (6.3) | 0.26% | — | Subscriber Broken Access Control IN Classified ListingAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | Radiustheme Classified ListingAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions. | |
| Aplazada | Media (5.1) | 0.33% | — | Evoluted PHP Directory Listing ScriptAI | 9/6/2026 | 23/7/2026 | Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter value is reflected without HTML encoding inside the HTML title element and inside anchor href attributes in the breadcrumb navigation. Attackers can inject arbitrary… | |
| Aplazada | Alta (8.8) | 0.27% | — | Listing HUB CMSAI | 4/6/2026 | 22/7/2026 | Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to pages.php with crafted id values using error-based SQL injection techniques to extract database… |