Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.21% | — | RT Mega MenuAI | 18/9/2026 | 18/9/2026 | The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.20% | — | RT Mega MenuAI | 18/9/2026 | 18/9/2026 | The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject… | |
| Aplazada | Alta (7.6) | 0.38% | — | Themeum WP Mega MenuAI | 16/9/2026 | 23/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2. | |
| Aplazada | Media (5.4) | 0.23% | — | RT Mega MenuAI | 2/8/2026 | 26/8/2026 | The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; its only gate is a nonce that any logged-in user can read from a standard admin page. A subscriber-level user can therefore enable the mega menu on a site… | |
| Aplazada | Media (4.3) | 0.25% | — | Cleverplugins Clever Mega Menu FOR Visual ComposerAI | 2/8/2026 | 26/8/2026 | The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates navigation menu item metadata, allowing any authenticated user, including Subscribers, to overwrite menu item content and settings that are rendered in the site's public… | |
| Aplazada | Media (6.5) | 0.30% | — | RT Mega MenuAI | 27/7/2026 | 27/7/2026 | Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | RT Mega MenuAI | 27/7/2026 | 27/7/2026 | Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | |
| Modificada | Media (5.4) | 0.25% | — | Themehunk Mega Menu | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in ThemeHunk ThemeHunk themehunk-megamenu-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ThemeHunk: from n/a through <= 1.2.0. | |
| Aplazada | Media (6.5) | 0.34% | — | Hero Mega MenuAI | 5/3/2025 | 17/6/2026 | The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the hmenu_delete_menu() function in all versions up to, and including, 1.16.5. This makes it possible for unauthenticated attackers to delete arbitrary… | |
| Aplazada | Media (6.1) | 0.26% | — | Hero Mega MenuAI | 5/3/2025 | 17/6/2026 | The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'index' parameter in all versions up to, and including, 1.16.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.5) | 0.35% | — | Hero Mega MenuAI | 5/3/2025 | 17/6/2026 | The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to SQL Injection via several functions in all versions up to, and including, 1.16.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Alta (8.5) | 0.37% | — | Notfound Hero Mega MenuAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows SQL Injection. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5. | |
| Aplazada | Alta (8.5) | 0.37% | — | Notfound Hero Mega Menu - Responsive Wordpress MenuAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows SQL Injection. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5. | |
| Aplazada | Alta (7.1) | 0.28% | — | Notfoundhero Hero Mega MenuAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Hero Mega Menu - Responsive WordPress Menu Plugin allows Reflected XSS. This issue affects Hero Mega Menu - Responsive WordPress Menu Plugin: from n/a through 1.16.5. | |
| Aplazada | Alta (7.2) | 0.83% | — | Themeum WP Mega MenuAI | 13/12/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Themeum WP Mega Menu wp-megamenu allows Object Injection.This issue affects WP Mega Menu: from n/a through <= 1.4.2. | |
| Aplazada | Crítica (9.8) | 0.67% | — | Wordpress Mega MenuAI | 16/10/2024 | 17/6/2026 | The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, 2.0.6 via the compiler_save AJAX action. This makes it possible for unauthenticated attackers to create arbitrary PHP files that can be used to execute malicious code. | |
| Aplazada | Media (6.4) | 0.34% | — | Themehunk Easy Mega MenuAI | 8/10/2024 | 17/6/2026 | The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘themehunk_megamenu_bg_image' parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Media (4.3) | 0.35% | — | Themehunk Mega Menu | 25/9/2024 | 17/6/2026 | The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions hooked via AJAX in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Modificada | Crítica (9.8) | 0.54% | — | Stylemixthemes Mega Menu | 10/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu allows PHP Local File Inclusion.This issue affects MegaMenu: from n/a through 2.3.12. | |
| Aplazada | Media (5.4) | 0.32% | — | Megamenu MAX Mega MenuAI | 28/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Megamenu Max Mega Menu.This issue affects Max Mega Menu: from n/a through 3.3. | |
| Modificada | Crítica (9.8) | 1.0% | — | Joommasters JMS Drop Mega Menu | 5/6/2023 | 17/6/2026 | PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php. | |
| Modificada | Media (6.1) | 0.87% | — | Accesspressthemes AP Mega Menu | 21/3/2022 | 17/6/2026 | The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Media (6.1) | 0.91% | — | Megamenu MAX Mega Menu | 21/8/2019 | 17/6/2026 | The megamenu plugin before 2.4 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 1.4% | — | Responsive Mega Menu PRO Project Responsive Mega Menu PROPrestashop | 10/5/2018 | 17/6/2026 | modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute a SQL Injection through function calls in the code parameter. |