Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2554▼ 405 respecto a la semana anterior
Críticas / altas1317▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
74 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.30% | — | WP Store LocatorAI | 30/9/2026 | 30/9/2026 | Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions. | |
| Aplazada | Alta (7.5) | 0.37% | — | WP Multi Store Locator PROAI | 18/9/2026 | 19/9/2026 | The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Locatoraid Store LocatorAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. | |
| Aplazada | Baja (3.4) | 0.37% | — | Store LocatorAI | 13/6/2026 | 21/7/2026 | The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys. | |
| Aplazada | Baja (3.5) | 0.24% | — | Store LocatorAI | 13/6/2026 | 21/7/2026 | The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin before 1.6.9 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the… | |
| Aplazada | Baja (3.5) | 0.24% | — | Store LocatorAI | 10/6/2026 | 23/7/2026 | The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin before 1.6.6 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the… | |
| Aplazada | Media (6.4) | 0.26% | — | WP Store LocatorAI | 23/4/2026 | 17/6/2026 | The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl_address' post meta value in versions up to, and including, 2.2.261 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (5.9) | 0.21% | — | Plainware Locatoraid Store LocatorAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plainware Locatoraid Store Locator locatoraid allows Stored XSS.This issue affects Locatoraid Store Locator: from n/a through <= 3.9.68. | |
| Aplazada | Alta (8.5) | 0.30% | — | Agilelogix Store LocatorAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Blind SQL Injection.This issue affects Store Locator WordPress: from n/a through <= 1.6.2. | |
| Aplazada | Alta (8.8) | 0.46% | — | WP Store LocatorAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Tijmen Smit WP Store Locator wp-store-locator allows Object Injection.This issue affects WP Store Locator: from n/a through <= 2.2.260. | |
| Aplazada | Alta (7.2) | 0.69% | — | Docodoco Store LocatorAI | 15/10/2025 | 17/6/2026 | The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on… | |
| Aplazada | Media (6.6) | 0.27% | — | Agilelogix Agile Store LocatorAI | 6/6/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Upload a Web Shell to a Web Server.This issue affects Store Locator WordPress: from n/a through <= 1.5.2. | |
| Aplazada | Alta (7.6) | 0.35% | — | Agilelogix Store LocatorAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows SQL Injection.This issue affects Store Locator WordPress: from n/a through <= 1.5.1. | |
| Analizada | Media (6.5) | 0.22% | — | Joomlaserviceprovider JSP Store Locator | 15/5/2025 | 17/6/2026 | The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. | |
| Analizada | Alta (8.8) | 0.56% | — | Joomlaserviceprovider JSP Store Locator | 15/5/2025 | 17/6/2026 | The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks. | |
| Aplazada | Crítica (9.3) | 0.37% | — | Webbytemplate Office LocatorAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebbyTemplate Office Locator office-locator allows SQL Injection.This issue affects Office Locator: from n/a through <= 1.3.0. | |
| Analizada | Media (5.9) | 0.32% | — | Google Maps\ Store Locator Project | 16/4/2025 | 17/6/2026 | Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*. | |
| Aplazada | Media (4.3) | 0.15% | — | Wpexperts WP Multistore LocatorAI | 1/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPExperts.io WP Multistore Locator wp-multi-store-locator allows Cross Site Request Forgery.This issue affects WP Multistore Locator: from n/a through <= 2.5.2. | |
| Aplazada | Alta (7.1) | 0.17% | — | Store Locator WidgetAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Store Locator Widgets Store Locator Widget store-locator-widget allows Stored XSS.This issue affects Store Locator Widget: from n/a through <= 2025r2. | |
| Aplazada | Media (6.5) | 0.36% | — | Pierre Lannoy IP LocatorAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy IP Locator ip-locator allows DOM-Based XSS.This issue affects IP Locator: from n/a through <= 4.1.0. | |
| Aplazada | Crítica (9.3) | 0.59% | — | Wpexperts WP Multistore LocatorAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Multistore Locator wp-multi-store-locator allows SQL Injection.This issue affects WP Multistore Locator: from n/a through <= 2.5.2. | |
| Aplazada | Alta (7.1) | 0.37% | — | JAS Saran G Gwebpro-store-locatorAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jas Saran G Web Pro Store Locator gwebpro-store-locator allows Reflected XSS.This issue affects G Web Pro Store Locator: from n/a through <= 2.0.1. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Wpexperts WP Multistore LocatorAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Multistore Locator wp-multi-store-locator allows Blind SQL Injection.This issue affects WP Multistore Locator: from n/a through <= 2.5.1. | |
| Aplazada | Media (6.4) | 0.33% | — | Store Locator WidgetAI | 19/2/2025 | 17/6/2026 | The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocatorwidget' shortcode in all versions up to, and including, 2025r1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.32% | — | Umangmetatagg Custom WP Store LocatorAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in umangmetatagg Custom WP Store Locator custom-store-locator allows Reflected XSS.This issue affects Custom WP Store Locator: from n/a through <= 1.4.7. |