Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.8) | 0.21% | — | Pluginrx Broken Link NotifierAI | 30/9/2026 | 30/9/2026 | The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services. | |
| Aplazada | Media (4.8) | 0.24% | — | Ifeelweb Post Status Notifier LiteAI | 23/7/2026 | 23/7/2026 | The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are… | |
| Aplazada | Media (5.3) | 0.22% | — | Pluginrx Broken Link NotifierAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in PluginRx Broken Link Notifier broken-link-notifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Broken Link Notifier: from n/a through <= 1.3.5. | |
| Aplazada | Media (4.4) | 0.23% | — | Javascript NotifierAI | 24/1/2026 | 17/6/2026 | The JavaScript Notifier plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 1.2.8. This is due to insufficient input sanitization and output escaping on user-supplied attributes in the `wp_footer` action. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.35% | — | Wanotifier NotifierAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in WANotifier Notifier notifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notifier: from n/a through <= 2.7.13. | |
| Aplazada | Media (4.3) | 0.15% | — | WP Status NotifierAI | 7/1/2026 | 17/6/2026 | The WP Status Notifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin settings via a forged… | |
| Analizada | Media (6.5) | 0.69% | — | Pluginrx Broken Link Notifier | 11/7/2025 | 17/6/2026 | The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.3.0 via the ajax_blinks() function which ultimately calls the check_url_status_code() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary… | |
| Aplazada | Media (4.1) | 0.24% | — | Pluginrx Broken Link NotifierAI | 11/7/2025 | 17/6/2026 | The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0 via broken links that are later exported. This makes it possible for authenticated attackers, with Contributor-level access and above, to embed untrusted input into exported CSV files, which can… | |
| Modificada | Media (6.5) | 0.32% | — | Jenkins Ifttt Build Notifier | 9/7/2025 | 17/6/2026 | Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Aplazada | Media (4.3) | 0.27% | — | Wanotifier NotifierAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in WANotifier Notifier notifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notifier: from n/a through <= 2.7.12. | |
| Aplazada | Media (4.3) | 0.42% | — | Aleswebs Admail Multilingual Back IN Stock Notifier FOR WoocommerceAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in aleswebs AdMail – Multilingual Back in-Stock Notifier for WooCommerce admail allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AdMail – Multilingual Back in-Stock Notifier for WooCommerce: from n/a through <= 1.7.0. | |
| Aplazada | Media (5.9) | 0.35% | — | Ufukart Comment Approved Notifier ExtendedAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ufukart Comment Approved Notifier Extended comment-approved-notifier-extended allows Stored XSS.This issue affects Comment Approved Notifier Extended: from n/a through <= 5.2. | |
| Aplazada | Media (6.1) | 0.30% | — | Post Status NotifierAI | 29/10/2024 | 17/6/2026 | The Post Status Notifier Lite and Premium plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.11.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (6.1) | 0.40% | — | Cvstech Exit Notifier | 13/9/2024 | 17/6/2026 | The Exit Notifier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.10.4. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they… | |
| Analizada | Media (4.8) | 0.37% | — | Wanotifier | 31/7/2024 | 17/6/2026 | The WANotifier WordPress plugin before 2.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (6.5) | 0.49% | — | Back IN Stock NotifierAI | 14/5/2024 | 17/6/2026 | The The Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.3.1. This is due to the plugin for WordPress allowing users to execute an action that does not properly validate a value… | |
| Modificada | Media (6.5) | 0.68% | — | Jenkins MQ Notifier | 6/3/2024 | 17/6/2026 | Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default. | |
| Modificada | Alta (7.5) | 0.67% | — | Multivendorx Product Stock Manager & Notifier FOR Woocommerce | 30/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in MultiVendorX Product Stock Manager & Notifier for WooCommerce.This issue affects Product Stock Manager & Notifier for WooCommerce: from n/a through 2.0.1. | |
| Modificada | Media (6.1) | 0.41% | — | Ifeelweb Post Status Notifier Lite | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Reith Post Status Notifier Lite plugin <= 1.11.0 versions. | |
| Modificada | Media (6.5) | 0.34% | — | Woocommerce Order Status Change Notifier | 15/5/2023 | 17/6/2026 | The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without… | |
| Modificada | Media (6.1) | 0.90% | — | Ifeelweb Post Status Notifier Lite | 9/1/2023 | 17/6/2026 | The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high privilege users such as admin. | |
| Modificada | Media (5.3) | 0.39% | — | Jenkins Bigpanda Notifier | 21/9/2022 | 17/6/2026 | Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it. | |
| Modificada | Media (4.3) | 0.50% | — | Jenkins Bigpanda Notifier | 21/9/2022 | 17/6/2026 | Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (6.5) | 0.73% | — | Jenkins Skype Notifier | 30/6/2022 | 17/6/2026 | Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (4.3) | 0.74% | — | Jenkins Rocketchat Notifier | 30/6/2022 | 17/6/2026 | Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. |