Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—PerfmattersAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.4 versions.
AplazadaAlta (7.5)0.94%—PerfmattersAI2/7/20262/7/2026
The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 via the 's' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the…
AplazadaAlta (7.1)0.25%—PerfmattersAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.3 versions.
AplazadaAlta (8.1)0.53%—PerfmattersAI10/4/202617/6/2026
The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to, and including, 2.5.9. This is due to the `PMCS::action_handler()` method processing the bulk action `activate`/`deactivate` handlers without any authorization check or nonce verification. The…
AplazadaAlta (8.1)0.53%—PerfmattersAI3/4/202621/7/2026
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['delete']` parameter without any sanitization, authorization check, or nonce verification. The…
ModificadaAlta (8.8)0.41%—Perfmatters29/2/202417/6/2026
Missing Authorization vulnerability in Perfmatters.This issue affects Perfmatters: from n/a through 2.1.6.
ModificadaMedia (5.4)0.37%—Perfmatters30/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Perfmatters allows Stored XSS.This issue affects Perfmatters: from n/a before 2.2.0.
ModificadaMedia (6.1)0.41%—Perfmatters30/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Perfmatters allows Reflected XSS.This issue affects Perfmatters: from n/a through 2.1.6.
ModificadaAlta (8.8)0.24%—Perfmatters30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Perfmatters allows Cross Site Request Forgery.This issue affects Perfmatters: from n/a through 2.1.6.