Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 334 respecto a la semana anterior
Críticas / altas1340▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.26% | — | Sitelock Security WP Hardening Login Security Malware ScansAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in SiteLock SiteLock Security – WP Hardening, Login Security & Malware Scans sitelock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SiteLock Security – WP Hardening, Login Security & Malware Scans: from n/a through <= 5.0.2. | |
| Aplazada | Alta (7.2) | 0.31% | — | Cleantalk Login Security Firewall Malware RemovalAI | 9/12/2025 | 17/6/2026 | The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the page URL in all versions up to, and including, 2.168 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Melapress Login SecurityAI | 26/7/2025 | 17/6/2026 | The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication… | |
| Modificada | Alta (7.2) | 0.90% | — | Melapress Login Security | 16/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security melapress-login-security allows Object Injection.This issue affects MelaPress Login Security: from n/a through <= 2.1.0. | |
| Analizada | Alta (8.2) | 0.37% | — | Melapress Login Security | 8/4/2025 | 17/6/2026 | The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'monitor_admin_actions' function in version 2.1.0. This makes it possible for unauthenticated attackers to delete any user. | |
| Aplazada | Media (5.3) | 0.39% | — | Wpdo Dologin SecurityAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in WPDO DoLogin Security dologin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DoLogin Security: from n/a through <= 3.7.1. | |
| Modificada | Alta (7.2) | 0.56% | — | Melapress Login Security | 10/6/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Melapress MelaPress Login Security melapress-login-security.This issue affects MelaPress Login Security: from n/a through <= 1.3.0. | |
| Modificada | Media (6.5) | 1.0% | — | Wpdo Dologin Security | 16/10/2023 | 17/6/2026 | The DoLogin Security WordPress plugin before 3.7.1 does not restrict the access of a widget that shows the IPs of failed logins to low privileged users. | |
| Analizada | Media (5.3) | 0.71% | — | Wpdo Dologin Security | 25/9/2023 | 17/6/2026 | The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing. | |
| Analizada | Media (6.1) | 0.70% | — | Wpdo Dologin Security | 25/9/2023 | 17/6/2026 | The DoLogin Security WordPress plugin before 3.7 does not properly sanitize IP addresses coming from the X-Forwarded-For header, which can be used by attackers to conduct Stored XSS attacks via WordPress' login form. | |
| Modificada | Media (6.2) | 0.61% | — | Clogica WP Login Security AND History | 1/6/2021 | 17/6/2026 | The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS payloads on them as well | |
| Modificada | Crítica (9.8) | 1.7% | — | Login Security Project Login Security | 30/1/2020 | 16/6/2026 | The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted username. | |
| Modificada | Media (4.3) | 1.3% | — | Login Security Project Login Security | 28/8/2013 | 16/6/2026 | The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal, when using the login delay option, allows remote attackers to cause a denial of service (CPU consumption) via a large number of failed login attempts. |