Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.24% | — | Keeswolters Mopinion Feedback FormAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in keeswolters Mopinion Feedback Form mopinion-feedback-form allows DOM-Based XSS.This issue affects Mopinion Feedback Form: from n/a through <= 1.1.1. | |
| Aplazada | Media (5.1) | 0.47% | — | Opinionstage Poll Survey AND Quiz MakerAI | 16/1/2026 | 17/6/2026 | Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes… | |
| Aplazada | Media (5.3) | 0.33% | — | Opinionstage Poll Survey AND Quiz MakerAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Opinion Stage Poll, Survey & Quiz Maker Plugin by Opinion Stage social-polls-by-opinionstage allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll, Survey & Quiz Maker Plugin by Opinion Stage: from n/a through <= 19.12.0. | |
| Analizada | Media (4.8) | 0.20% | — | Objectplanet Opinio | 2/12/2025 | 3/9/2026 | Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey. | |
| Analizada | Baja (2.1) | 0.31% | — | Objectplanet Opinio | 2/12/2025 | 25/9/2026 | Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests to an arbitrary destination. | |
| Analizada | Baja (2.3) | 0.18% | — | Objectplanet Opinio | 2/12/2025 | 25/9/2026 | Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the connected users and then access such files without authentication. | |
| Aplazada | Media (4.3) | 0.15% | — | Opinionstage Poll Survey Quiz MakerAI | 27/11/2025 | 17/6/2026 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.12.0. This is due to missing or insufficient nonce validation on the disconnect_account_action function. This makes it possible for unauthenticated attackers… | |
| Aplazada | Alta (7.5) | 0.50% | — | Opinionstage Poll Survey Quiz MakerAI | 28/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Opinion Stage Poll, Survey & Quiz Maker Plugin by Opinion Stage social-polls-by-opinionstage allows PHP Local File Inclusion.This issue affects Poll, Survey & Quiz Maker Plugin by Opinion Stage:… | |
| Analizada | Media (4.3) | 0.29% | — | Opinionstage Poll, Survey & Quiz Maker | 17/6/2025 | 17/6/2026 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on several functions in all versions up to, and including, 19.9.0. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Modificada | Crítica (9.8) | 0.74% | — | Objectplanet Opinio | 1/2/2024 | 17/6/2026 | Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application. | |
| Modificada | Alta (8.8) | 6.0% | — | Objectplanet Opinio | 31/7/2021 | 17/6/2026 | admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code. | |
| Modificada | Alta (7.5) | 1.7% | — | Objectplanet Opinio | 31/7/2021 | 17/6/2026 | ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data. | |
| Modificada | Media (6.5) | 1.1% | — | Objectplanet Opinio | 31/7/2021 | 17/6/2026 | ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI. The XXE can… | |
| Modificada | Media (6.1) | 0.98% | — | Objectplanet Opinio | 30/7/2021 | 17/6/2026 | ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.) | |
| Modificada | Media (6.1) | 0.64% | — | Objectplanet Opinio | 3/7/2017 | 17/6/2026 | In ObjectPlanet Opinio before 7.6.4, there is XSS. |