Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.42% | — | Regularlabs Snippets FreeAIRegularlabs Snippets PROAI | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0 - Snippets substitutes variable values supplied by an article tag into saved Snippet content. The affected versions do not consider the article author's… | |
| Aplazada | Alta (8.5) | 0.58% | — | Postsnippets Post SnippetsAI | 25/6/2026 | 25/6/2026 | Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions. | |
| Aplazada | Media (4.4) | 0.36% | — | Postsnippets Post SnippetsAI | 29/5/2026 | 21/7/2026 | The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.19. This is due to insufficient output escaping of imported snippet content when rendering JavaScript variables in the post editor. Specifically, the `jqueryUiDialog()` method in `WPEditor.php`… | |
| Analizada | Crítica (9.3) | 0.38% | — | Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+4 | 27/5/2026 | 17/6/2026 | The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites. | |
| Aplazada | Media (6.4) | 0.32% | — | Text SnippetsAI | 22/4/2026 | 17/6/2026 | The Text Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ts` shortcode in all versions up to, and including, 0.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.9) | 0.31% | — | Themeisle Woody AD SnippetsAI | 25/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1. | |
| Aplazada | Alta (8.5) | 0.23% | — | Postsnippets Post SnippetsAI | 25/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affects Post Snippets: from n/a through <= 4.0.12. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Themerex Pets ClubAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects Pets Club: from n/a through <= 2.3. | |
| Aplazada | Media (4.3) | 0.22% | — | Codesnippets Code SnippetsAI | 6/2/2026 | 17/6/2026 | The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.4. This is due to missing nonce validation on the cloud snippet download and update actions in the Cloud_Search_List_Table class. This makes it possible for unauthenticated attackers to force… | |
| Aplazada | Alta (8.1) | 0.47% | — | Ancorathemes Pets LandAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Pets Land petsland allows PHP Local File Inclusion.This issue affects Pets Land: from n/a through <= 1.2.8. | |
| Aplazada | Media (4.3) | 0.12% | — | Postsnippets Post SnippetsAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Post Snippets post-snippets allows Cross Site Request Forgery.This issue affects Post Snippets: from n/a through <= 4.0.11. | |
| Aplazada | Alta (8) | 0.36% | — | Codesnippets Code SnippetsAI | 19/11/2025 | 17/6/2026 | The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` variable… | |
| Aplazada | Alta (7.1) | 0.25% | — | Igor Benic PetsAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Igor Benic Pets pets allows Reflected XSS.This issue affects Pets: from n/a through <= 1.4.1. | |
| Analizada | Media (6.5) | 0.53% | — | Smartbear Swagger Petstore | 25/9/2025 | 17/6/2026 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version | |
| Analizada | Media (6.1) | 0.38% | — | Smartbear Swagger Petstore | 25/9/2025 | 17/6/2026 | Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet | |
| Analizada | Media (6.5) | 0.43% | — | Smartbear Swagger Petstore | 25/9/2025 | 17/6/2026 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint | |
| Analizada | Baja (2) | 0.28% | — | Facebook-riares Online Petshop Management System | 18/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unknown function of the file availableframe.php of the component Admin Dashboard. The manipulation of the argument name/address results in cross site scripting. It is possible to launch the attack… | |
| Analizada | Baja (2) | 0.28% | — | Facebook-riares Online Petshop Management System | 18/9/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of the file addcnp.php of the component Available Products Page. The manipulation of the argument name/description leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Aplazada | Media (4.3) | 0.13% | — | Pluginsandsnippets Simple Page Access RestrictionAI | 27/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Plugins and Snippets Simple Page Access Restriction simple-page-access-restriction allows Cross Site Request Forgery.This issue affects Simple Page Access Restriction: from n/a through <= 1.0.32. | |
| Aplazada | Crítica (9.6) | 0.19% | — | Shahjahan Jewel Fluent SnippetsAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets easy-code-manager allows Cross Site Request Forgery.This issue affects FluentSnippets: from n/a through <= 10.50. | |
| Analizada | Media (6.5) | 0.22% | — | Pluginsandsnippets Simple Page Access Restriction | 30/5/2025 | 17/6/2026 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and capability checks in the settings save handler in the settings.php script. This makes it possible for unauthenticated attackers… | |
| Analizada | Media (6.3) | 0.29% | — | Jtsternberg Code Snippets CPT | 8/3/2025 | 17/6/2026 | The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated… | |
| Aplazada | Alta (7.6) | 0.62% | — | Alphabpo Easy Code SnippetsAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpha BPO Easy Code Snippets easy-code-snippets allows SQL Injection.This issue affects Easy Code Snippets: from n/a through <= 1.0.2. | |
| Aplazada | Media (5.3) | 0.47% | — | Pluginsandsnippets Simple Page Access RestrictionAI | 18/12/2024 | 17/6/2026 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level… | |
| Aplazada | Media (6.1) | 0.29% | — | Easy Code SnippetsAI | 7/12/2024 | 17/6/2026 | The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… |