Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 13 respecto a la semana anterior
Críticas / altas1452▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

250 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.33%—Kylephillips Nested PagesAI30/9/202630/9/2026
Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
AplazadaAlta (7.1)0.18%—Core WEB Vitals AND Pagespeed BoosterAI23/9/202623/9/2026
Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.
AplazadaAlta (8)0.34%—Unbounce Landing PagesAI19/9/202621/9/2026
The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin.
AplazadaAlta (7.1)0.32%—Unbounce Landing PagesAI8/9/20268/9/2026
Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a through 1.1.4.
AplazadaMedia (6.8)0.23%—Sogo ADD Script TO Individual Pages Header FooterAI30/8/202631/8/2026
The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contributor-level access and above to store…
AplazadaAlta (7.3)0.38%—Wplegalpages WP Legal PagesAI24/8/202626/8/2026
Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Pendiente de análisisAlta (8.8)0.68%—Cloudflare Pages-actionAICloudflare Wrangler-actionAI12/8/202628/8/2026
Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN…
AplazadaMedia (5.8)0.35%—Term PagesAI10/8/202626/8/2026
The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
AplazadaMedia (5.4)0.23%—Child Pages CardAI6/8/202626/8/2026
The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page, allowing users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaMedia (4.8)0.24%—Kylephillips Nested PagesAI4/8/202626/8/2026
The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress plugin before 3.2.15 is enabled for the post type) to inject…
AplazadaMedia (6.4)0.36%—Insert PagesAI2/7/20262/7/2026
The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key names) in all versions up to, and including, 3.11.4. This is due to insufficient output escaping in the the_meta() function: while the custom field VALUE is sanitized with wp_kses_post(), the custom…
AplazadaBaja (2.1)0.43%—Pretix-pagesAI25/6/202625/6/2026
Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.
AplazadaMedia (5.3)0.25%—Avirtum Ipages FlipbookAI17/6/20261/10/2026
Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/a through 1.5.1.
AnalizadaCrítica (9.8)0.58%—Microsoft Power Pages22/5/202623/7/2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.
AplazadaMedia (6.4)0.26%—Caterhamcomputing CC Child PagesAI14/5/202617/6/2026
The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
AplazadaMedia (4.3)0.23%—Inquiry Form TO Posts OR PagesAI15/4/202617/6/2026
The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in version 1.0. This is due to missing nonce validation on the plugin settings update handler, combined with insufficient input sanitization on all user-supplied fields and missing…
AplazadaMedia (4.4)0.33%—Inquiry Form TO Posts OR PagesAI8/4/202624/7/2026
The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Form Header' field in versions up to and including 1.0. This is due to insufficient input sanitization when saving via update_option() and lack of output escaping when displaying the stored value. The…
AplazadaMedia (4.3)0.13%—Font Pairing Preview FOR Landing PagesAI7/3/202617/6/2026
The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's font pairing…
AplazadaMedia (6.5)0.24%—LeadpagesAI20/2/202617/6/2026
Missing Authorization vulnerability in Leadpages Leadpages leadpages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leadpages: from n/a through <= 1.1.3.
AplazadaAlta (7.5)0.29%—WplegalpagesAI20/2/202617/6/2026
Missing Authorization vulnerability in WP Legal Pages WPLegalPages wplegalpages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLegalPages: from n/a through <= 3.5.4.
AnalizadaMedia (6.1)0.18%—SAP Business Server Pages10/2/202617/6/2026
SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and…
ModificadaMedia (4.3)0.32%—Apple PagesApple IpadosApple Iphone OSApple Macos28/1/202617/6/2026
An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. Processing a maliciously crafted Pages document may result in unexpected termination or disclosure of process memory.
ModificadaAlta (8.6)1.3%—4homepages 4images13/1/202617/6/2026
4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted…
AplazadaMedia (4.3)0.22%—SAP Product Designer WEB UIAISAP Business Server PagesAI13/1/202617/6/2026
SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application.
AplazadaMedia (6.4)0.27%—WP JS List Pages ShortcodesAI7/1/202617/6/2026
The WP Js List Pages Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to, and including, 1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access…