Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.18% | — | Page Title Description Open Graph UpdaterAI | 19/2/2026 | 17/6/2026 | The Page Title, Description & Open Graph Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.02. This is due to missing nonce validation on multiple AJAX actions including dieno_update_page_title. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (5.3) | 0.45% | — | Willnorris Open Graph | 6/6/2024 | 17/6/2026 | The Open Graph plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.2 via the 'opengraph_default_description' function. This makes it possible for unauthenticated attackers to extract sensitive data including partial content of password-protected blog posts. | |
| Modificada | Alta (8.8) | 0.28% | — | Underdock Open Graph Metabox | 25/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Niels van Renselaar Open Graph Metabox plugin <= 1.4.4 versions. | |
| Modificada | Media (4.8) | 0.32% | — | Alexmacarthur Complete Open Graph | 17/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex MacArthur Complete Open Graph plugin <= 3.4.5 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Rocketapps Open Graphite | 8/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rocket Apps Open Graphite plugin <= 1.6.0 versions. | |
| Modificada | Crítica (9.8) | 1.1% | — | Open-graph Project Open-graph | 8/8/2021 | 17/6/2026 | This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor payload. | |
| Modificada | Alta (8.8) | 0.56% | — | Custom4web WP Open Graph | 5/7/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WP Open Graph 1.6.1 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (6.1) | 1.0% | — | Webdados Open Graph FOR Facebook, Google+ AND Twitter Card Tags | 14/5/2018 | 17/6/2026 | Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | Open Graph Importer Project Open Graph Importer | 15/6/2015 | 17/6/2026 | The Open Graph Importer (og_tag_importer) 7.x-1.x for Drupal does not properly check the create permission for content types created during import, which allows remote authenticated users to bypass intended restrictions by leveraging the "import og_tag_importer" permission. | |
| Modificada | Media (4.3) | 1.2% | — | Open Graph Protocol Project Open Graph Protocol | 11/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Open Graph protocol (jh_opengraphprotocol) extension before 1.0.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |