Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 13 respecto a la semana anterior
Críticas / altas1452▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

644 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.18%—Wordpress Persistent Login Persistent LoginAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.
AplazadaCrítica (9.8)0.67%—Miniorange OTP Login Verification SMS NotificationsAI26/9/202628/9/2026
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass via the mo_wp_login_intent parameter in all versions up to, and including, 5.5.5. This is due to a missing password-intent guard in the skip_pass_fallback-enabled configuration branch of the…
AplazadaMedia (6.9)0.31%—Grav-plugin-loginAI26/9/202628/9/2026
grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challenge to be bypassed for content gated by the authenticated() Twig function or the [authenticated] shortcode. On sites with 2FA enabled, Login::isAuthenticated() checked only the session flag indicating…
AplazadaMedia (5.3)0.25%—Trustedlogin ConnectorAI23/9/202623/9/2026
Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.
AplazadaAlta (7.1)0.18%—WPS Limit LoginAI23/9/202623/9/2026
Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.
AplazadaAlta (7.5)0.30%—Rename WP Login PHP TO Anything YOU WantAI23/9/202623/9/2026
The Rename wp-login.php to anything you want plugin for WordPress is vulnerable to time-based SQL Injection via 'log' (Username) Parameter in all versions up to, and including, 2.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaMedia (5.3)0.25%—Ciphercoin Easy Hide LoginAI23/9/202623/9/2026
The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page through certain password-reset request parameters and to recover the site's configured secret login slug from the returned page, defeating the Easy…
AplazadaMedia (4.4)0.19%—OTP Login Register WoocommerceAI19/9/202621/9/2026
The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fb-config' Setting in all versions up to, and including, 2.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and…
AplazadaMedia (5.3)0.37%—Codection Clean LoginAI18/9/202618/9/2026
The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass the anti-automation control on the registration form and create accounts without solving it.
AplazadaMedia (5.3)0.30%—Codection Clean LoginAI18/9/202618/9/2026
The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account in its registration handler, allowing unauthenticated users to create accounts even when the site has registration disabled.
AplazadaCrítica (9.8)0.50%—Login With QRAI17/9/202618/9/2026
The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
AplazadaMedia (5.3)0.27%—LoginwordpressAIWwbn AvideoAI16/9/202622/9/2026
In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out…
AplazadaMedia (5.5)0.32%—Storeapps Temporary Login Without PasswordAI12/9/202614/9/2026
The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC…
AplazadaAlta (7.2)0.46%—Storeapps Temporary Login Without PasswordAI12/9/202614/9/2026
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing…
AplazadaCrítica (9.3)0.37%—Avideo LogincontrolAIWwbn AvideoAI11/9/202611/9/2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated attacker can inject malicious JavaScript by submitting a crafted public key, which…
AplazadaMedia (5.3)0.32%—OTP Login Register WoocommerceAI11/9/202611/9/2026
The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `process_otp_form` is keyed exclusively on the attacker-controlled…
AplazadaMedia (4.3)0.39%—Thememylogin Theme MY LoginAI5/9/20268/9/2026
The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_ms_signup_handler()` function's `gimmeanotherblog` branch failing to enforce the network's `active_signup` registration policy, checking only…
AnalizadaMedia (4.1)0.27%—Zyxware Disable Login Page2/9/20268/9/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
AplazadaAlta (7.1)0.25%—Netweblogic Login With AjaxAI2/9/20263/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS. This issue affects Login With Ajax: from n/a through 4.5.1.
AplazadaMedia (5.4)0.30%—MY LoginAI2/9/20263/9/2026
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them.
AplazadaMedia (6.5)0.25%—Persistent LoginAI1/9/20261/9/2026
The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
AplazadaAlta (7.1)0.25%—Wordpress Social Login AND RegisterAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
Pendiente de análisisMedia (5.7)0.22%—Drupal Disable Login PageAI25/8/20262/9/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
Pendiente de análisisMedia (5.7)0.19%—Drupal Email Login OTPAI25/8/202628/8/2026
Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
AplazadaCrítica (10)0.60%—Miniorange Saml SSOAIMiniorange Saml SP Single Sign ON Login With AdfsAIMiniorange Saml SP Single Sign ON Saml SSO Login With Google AppsAIJoomlaAI25/8/20268/9/2026
Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Login with ADFS < 6.4, SAML SP Single Sign On – SAML SSO login with Google Apps < 6.4 - This is due to the mo_saml_validate_signature() function performing a…