Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

242 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.18%—Radiustheme Classified ListingAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions.
AplazadaAlta (7.1)0.19%—Radiustheme Classified ListingAI4/9/20268/9/2026
The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing…
AplazadaMedia (5.4)0.29%—Radiustheme Classified ListingAI2/9/202623/9/2026
Missing Authorization vulnerability in Mamunur Rashid Classified Listing classified-listing allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Classified Listing: from n/a through 6.1.3.
AplazadaAlta (8.1)0.33%—Classified Listing Mobile Number VerificationAI26/8/202626/8/2026
The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.6.0. This is due to missing server-side Firebase OTP validation in the process_otp_login() function. This makes it possible for unauthenticated attackers to…
AplazadaMedia (4.3)0.16%—Mlsimport IDX Plugin MLS Plugin FOR Real Estate ListingsAI5/8/202626/8/2026
The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress…
AplazadaBaja (2.7)0.30%—Radiustheme Classified ListingAI3/8/202626/8/2026
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators and report managers.
AplazadaBaja (2.7)0.30%—Radiustheme Classified ListingAI3/8/202626/8/2026
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private…
AplazadaMedia (6.4)0.33%—Realestateconnected Easy Property ListingsAI1/8/202612/8/2026
The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Method in all versions up to, and including, 3.5.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaMedia (5.4)0.23%—Cridio ListingproAI23/7/202623/7/2026
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.
AplazadaAlta (8.8)0.20%—ApuslistingAI23/7/202623/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
AplazadaMedia (4.3)0.25%—Stylemixthemes UlistingAI23/7/202623/7/2026
Contributor Broken Access Control in uListing <= 2.2.0 versions.
AplazadaMedia (5.4)0.29%—Stylemixthemes UlistingAI23/7/202623/7/2026
Subscriber Broken Access Control in uListing <= 2.2.0 versions.
AplazadaMedia (4.3)0.27%—Radiustheme Classified ListingAI21/7/202621/7/2026
The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.
AplazadaMedia (6.5)0.30%—Radiustheme Classified ListingAI2/7/20262/7/2026
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
AplazadaAlta (7.1)0.25%—Radiustheme Classified ListingAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.
AplazadaAlta (7.1)0.25%—Automotive ListingsAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions.
AplazadaMedia (6.5)0.22%—Cridio ListingproAI26/6/202626/6/2026
Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.
AnalizadaAlta (8.8)0.43%—Faboba Ultimate Property Listing19/6/202619/8/2026
Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the sf_selectuser_id parameter. Attackers can send GET requests to index.php with the option=com_upl and view=propertylisting…
AplazadaMedia (4.3)0.37%—Radiustheme Classified ListingAI19/6/202622/6/2026
The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capability/ownership check on the gallery_image_update_as_feature AJAX handler (action:…
AplazadaCrítica (9.3)0.40%—Cridio ListingproAI17/6/202617/6/2026
Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.
AplazadaAlta (7.1)0.25%—Radiustheme Classified ListingAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions.
AplazadaMedia (6.3)0.26%—Subscriber Broken Access Control IN Classified ListingAI15/6/202617/6/2026
Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions.
AplazadaMedia (6.5)0.27%—Radiustheme Classified ListingAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.
AplazadaMedia (5.1)0.33%—Evoluted PHP Directory Listing ScriptAI9/6/202623/7/2026
Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter value is reflected without HTML encoding inside the HTML title element and inside anchor href attributes in the breadcrumb navigation. Attackers can inject arbitrary…
AplazadaAlta (8.8)0.27%—Listing HUB CMSAI4/6/202622/7/2026
Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to pages.php with crafted id values using error-based SQL injection techniques to extract database…