Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2554▼ 405 respecto a la semana anterior
Críticas / altas1317▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

74 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.30%—WP Store LocatorAI30/9/202630/9/2026
Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions.
AplazadaAlta (7.5)0.37%—WP Multi Store Locator PROAI18/9/202619/9/2026
The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaCrítica (9.3)0.40%—Locatoraid Store LocatorAI20/8/202620/8/2026
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
AplazadaBaja (3.4)0.37%—Store LocatorAI13/6/202621/7/2026
The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration files that contain database credentials and authentication keys.
AplazadaBaja (3.5)0.24%—Store LocatorAI13/6/202621/7/2026
The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin before 1.6.9 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the…
AplazadaBaja (3.5)0.24%—Store LocatorAI10/6/202623/7/2026
The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin before 1.6.6 admin page, allowing high-privileged users such as administrators to perform Stored Cross-Site Scripting attacks even when the…
AplazadaMedia (6.4)0.26%—WP Store LocatorAI23/4/202617/6/2026
The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl_address' post meta value in versions up to, and including, 2.2.261 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaMedia (5.9)0.21%—Plainware Locatoraid Store LocatorAI31/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plainware Locatoraid Store Locator locatoraid allows Stored XSS.This issue affects Locatoraid Store Locator: from n/a through <= 3.9.68.
AplazadaAlta (8.5)0.30%—Agilelogix Store LocatorAI9/12/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Blind SQL Injection.This issue affects Store Locator WordPress: from n/a through <= 1.6.2.
AplazadaAlta (8.8)0.46%—WP Store LocatorAI22/10/202517/6/2026
Deserialization of Untrusted Data vulnerability in Tijmen Smit WP Store Locator wp-store-locator allows Object Injection.This issue affects WP Store Locator: from n/a through <= 2.2.260.
AplazadaAlta (7.2)0.69%—Docodoco Store LocatorAI15/10/202517/6/2026
The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on…
AplazadaMedia (6.6)0.27%—Agilelogix Agile Store LocatorAI6/6/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Upload a Web Shell to a Web Server.This issue affects Store Locator WordPress: from n/a through <= 1.5.2.
AplazadaAlta (7.6)0.35%—Agilelogix Store LocatorAI6/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows SQL Injection.This issue affects Store Locator WordPress: from n/a through <= 1.5.1.
AnalizadaMedia (6.5)0.22%—Joomlaserviceprovider JSP Store Locator15/5/202517/6/2026
The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.
AnalizadaAlta (8.8)0.56%—Joomlaserviceprovider JSP Store Locator15/5/202517/6/2026
The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.
AplazadaCrítica (9.3)0.37%—Webbytemplate Office LocatorAI17/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebbyTemplate Office Locator office-locator allows SQL Injection.This issue affects Office Locator: from n/a through <= 1.3.0.
AnalizadaMedia (5.9)0.32%—Google Maps\ Store Locator Project16/4/202517/6/2026
Vulnerability in Drupal Google Maps: Store Locator.This issue affects Google Maps: Store Locator: *.*.
AplazadaMedia (4.3)0.15%—Wpexperts WP Multistore LocatorAI1/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPExperts.io WP Multistore Locator wp-multi-store-locator allows Cross Site Request Forgery.This issue affects WP Multistore Locator: from n/a through <= 2.5.2.
AplazadaAlta (7.1)0.17%—Store Locator WidgetAI27/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Store Locator Widgets Store Locator Widget store-locator-widget allows Stored XSS.This issue affects Store Locator Widget: from n/a through <= 2025r2.
AplazadaMedia (6.5)0.36%—Pierre Lannoy IP LocatorAI27/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lannoy IP Locator ip-locator allows DOM-Based XSS.This issue affects IP Locator: from n/a through <= 4.1.0.
AplazadaCrítica (9.3)0.59%—Wpexperts WP Multistore LocatorAI26/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Multistore Locator wp-multi-store-locator allows SQL Injection.This issue affects WP Multistore Locator: from n/a through <= 2.5.2.
AplazadaAlta (7.1)0.37%—JAS Saran G Gwebpro-store-locatorAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jas Saran G Web Pro Store Locator gwebpro-store-locator allows Reflected XSS.This issue affects G Web Pro Store Locator: from n/a through <= 2.0.1.
AplazadaCrítica (9.3)0.53%—Wpexperts WP Multistore LocatorAI25/2/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Multistore Locator wp-multi-store-locator allows Blind SQL Injection.This issue affects WP Multistore Locator: from n/a through <= 2.5.1.
AplazadaMedia (6.4)0.33%—Store Locator WidgetAI19/2/202517/6/2026
The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocatorwidget' shortcode in all versions up to, and including, 2025r1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (7.1)0.32%—Umangmetatagg Custom WP Store LocatorAI3/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in umangmetatagg Custom WP Store Locator custom-store-locator allows Reflected XSS.This issue affects Custom WP Store Locator: from n/a through <= 1.4.7.