Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.20% | — | Notify OdooAI | 15/5/2026 | 17/6/2026 | The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the _updateSettings function. This makes it possible for unauthenticated attackers to change the Notify Odoo URL to an… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Form NotifyAI | 15/5/2026 | 17/6/2026 | The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This is due to the plugin trusting user-controlled cookie data to determine which WordPress account to authenticate after a LINE OAuth login. When LINE doesn't provide an email address (which is common),… | |
| Aplazada | Media (4.3) | 0.24% | — | Wisernotify Wiser ReviewAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Wisernotify team WiserReview Product Reviews for WooCommerce wiser-review allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WiserReview Product Reviews for WooCommerce: from n/a through <= 2.9. | |
| Aplazada | Media (5.9) | 0.21% | — | Touchoftech Draft NotifyAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TouchOfTech Draft Notify draft-notify allows Stored XSS.This issue affects Draft Notify: from n/a through <= 1.5. | |
| Aplazada | Media (5.4) | 0.25% | — | Popup Builder Easy Notify LiteAI | 13/12/2025 | 17/6/2026 | The Popup Builder (Easy Notify Lite) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the easynotify_cp_reset() function in all versions up to, and including, 1.1.37. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Usestrict Bbpress NotifyAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in useStrict bbPress Notify bbpress-notify-nospam allows Reflected XSS.This issue affects bbPress Notify: from n/a through <= 2.19.5. | |
| Aplazada | Media (6.5) | 0.17% | — | Ablancodev Woocommerce Notify Updated ProductAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ablancodev Woocommerce Notify Updated Product woocommerce-notify-updated-product allows Stored XSS.This issue affects Woocommerce Notify Updated Product: from n/a through <= 1.6. | |
| Aplazada | Alta (7.1) | 0.25% | — | Iamapinan WOO Line NotifyAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iamapinan Woocommerce Line Notify woo-line-notify allows Stored XSS.This issue affects Woocommerce Line Notify: from n/a through <= 1.1.7. | |
| Analizada | Media (4.3) | 0.20% | — | Ani2life Wp-reply Notify | 15/5/2025 | 17/6/2026 | The WP-Reply Notify WordPress plugin through 1.1 does not have a CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack. | |
| Aplazada | Media (6.5) | 0.31% | — | Wpvsingh Site NotifyAI | 10/4/2025 | 17/6/2026 | Missing Authorization vulnerability in wpvsingh Site Notify site-notify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Notify: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.28% | — | Michael Stursberg Browser-update-notifyAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Stursberg Browser-Update-Notify browser-update-notify allows Reflected XSS.This issue affects Browser-Update-Notify: from n/a through <= 0.2.1. | |
| Aplazada | Media (6.5) | 0.29% | — | Ghozylab Popup BuilderAIGhozylab Easy-notify-liteAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Popup Builder easy-notify-lite allows Stored XSS.This issue affects Popup Builder: from n/a through <= 1.1.33. | |
| Aplazada | Alta (7.1) | 0.32% | — | Pektsekye Notify OdooAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pektsekye Notify Odoo notify-odoo allows Stored XSS.This issue affects Notify Odoo: from n/a through <= 1.0.0. | |
| Aplazada | Media (5.3) | 0.55% | — | Wisernotify Wiser Notify Social ProofAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Wiser Notify WiserNotify Social Proof allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WiserNotify Social Proof: from n/a through 2.5. | |
| Modificada | Media (6.1) | 0.29% | — | Usestrict Bbpress Notify | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vinny Alves (UseStrict Consulting) bbPress Notify allows Reflected XSS.This issue affects bbPress Notify: from n/a through 2.18.3. | |
| Modificada | Media (5.4) | 0.11% | — | Savignano S-notify | 1/7/2024 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email. | |
| Aplazada | Alta (8.8) | 0.15% | — | Savignano S NotifyAI | 1/7/2024 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME certificate of PGP key via malicious link or email. | |
| Aplazada | Media (4.3) | 0.30% | — | Verygoodplugins Fatal Error NotifyAI | 16/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Very Good Plugins Fatal Error Notify.This issue affects Fatal Error Notify: from n/a through 1.5.2. | |
| Analizada | Media (6.1) | 0.21% | — | Savignano S-notify | 10/4/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload functionality of the User Profile pages in savignano S/Notify before 4.0.0 for Confluence allows attackers to manipulate user data via specially crafted certificate. | |
| Analizada | Media (5.2) | 0.14% | — | Savignano S-notify | 10/4/2024 | 17/6/2026 | Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link. | |
| Analizada | Media (6.1) | 0.23% | — | Verygoodplugins Fatal Error Notify | 27/2/2024 | 17/6/2026 | The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such as subscriber to call it and spam the admin email address with error messages. The issue is also exploitable via CSRF | |
| Analizada | Media (5.4) | 0.17% | — | Savignano S-notify | 9/1/2024 | 17/6/2026 | An issue was discovered in savignano S/Notify before 4.0.2 for Confluence. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website.… | |
| Analizada | Media (5.4) | 0.17% | — | Savignano S-notify | 9/1/2024 | 17/6/2026 | An issue was discovered in savignano S/Notify before 2.0.1 for Bitbucket. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website.… | |
| Modificada | Alta (7.1) | 0.19% | — | Savignano S-notify | 9/1/2024 | 17/6/2026 | An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email or by visiting a malicious website. If… | |
| Modificada | Media (6.1) | 0.39% | — | Simonchuang WP Line Notify | 6/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Simon Chuang WP LINE Notify plugin <= 1.4.4 versions. |