Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.42%—Regularlabs Snippets FreeAIRegularlabs Snippets PROAI14/9/202616/9/2026
Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0 - Snippets substitutes variable values supplied by an article tag into saved Snippet content. The affected versions do not consider the article author's…
AplazadaAlta (8.5)0.58%—Postsnippets Post SnippetsAI25/6/202625/6/2026
Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.
AplazadaMedia (4.4)0.36%—Postsnippets Post SnippetsAI29/5/202621/7/2026
The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.19. This is due to insufficient output escaping of imported snippet content when rendering JavaScript variables in the post editor. Specifically, the `jqueryUiDialog()` method in `WPEditor.php`…
AnalizadaCrítica (9.3)0.38%—Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+427/5/202617/6/2026
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
AplazadaMedia (6.4)0.32%—Text SnippetsAI22/4/202617/6/2026
The Text Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ts` shortcode in all versions up to, and including, 0.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaCrítica (9.9)0.31%—Themeisle Woody AD SnippetsAI25/3/202617/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue affects Woody ad snippets: from n/a through <= 2.7.1.
AplazadaAlta (8.5)0.23%—Postsnippets Post SnippetsAI25/3/202617/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion.This issue affects Post Snippets: from n/a through <= 4.0.12.
AplazadaCrítica (9.8)0.53%—Themerex Pets ClubAI5/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects Pets Club: from n/a through <= 2.3.
AplazadaMedia (4.3)0.22%—Codesnippets Code SnippetsAI6/2/202617/6/2026
The Code Snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.9.4. This is due to missing nonce validation on the cloud snippet download and update actions in the Cloud_Search_List_Table class. This makes it possible for unauthenticated attackers to force…
AplazadaAlta (8.1)0.47%—Ancorathemes Pets LandAI22/1/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Pets Land petsland allows PHP Local File Inclusion.This issue affects Pets Land: from n/a through <= 1.2.8.
AplazadaMedia (4.3)0.12%—Postsnippets Post SnippetsAI31/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Post Snippets post-snippets allows Cross Site Request Forgery.This issue affects Post Snippets: from n/a through <= 4.0.11.
AplazadaAlta (8)0.36%—Codesnippets Code SnippetsAI19/11/202517/6/2026
The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. This is due to the plugin's use of extract() on attacker-controlled shortcode attributes within the `evaluate_shortcode_from_flat_file` method, which can be used to overwrite the `$filepath` variable…
AplazadaAlta (7.1)0.25%—Igor Benic PetsAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Igor Benic Pets pets allows Reflected XSS.This issue affects Pets: from n/a through <= 1.4.1.
AnalizadaMedia (6.5)0.53%—Smartbear Swagger Petstore25/9/202517/6/2026
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version
AnalizadaMedia (6.1)0.38%—Smartbear Swagger Petstore25/9/202517/6/2026
Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet
AnalizadaMedia (6.5)0.43%—Smartbear Swagger Petstore25/9/202517/6/2026
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint
AnalizadaBaja (2)0.28%—Facebook-riares Online Petshop Management System18/9/202517/6/2026
A security flaw has been discovered in itsourcecode Online Petshop Management System 1.0. The affected element is an unknown function of the file availableframe.php of the component Admin Dashboard. The manipulation of the argument name/address results in cross site scripting. It is possible to launch the attack…
AnalizadaBaja (2)0.28%—Facebook-riares Online Petshop Management System18/9/202517/6/2026
A vulnerability was identified in itsourcecode Online Petshop Management System 1.0. Impacted is an unknown function of the file addcnp.php of the component Available Products Page. The manipulation of the argument name/description leads to cross site scripting. It is possible to initiate the attack remotely. The…
AplazadaMedia (4.3)0.13%—Pluginsandsnippets Simple Page Access RestrictionAI27/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Plugins and Snippets Simple Page Access Restriction simple-page-access-restriction allows Cross Site Request Forgery.This issue affects Simple Page Access Restriction: from n/a through <= 1.0.32.
AplazadaCrítica (9.6)0.19%—Shahjahan Jewel Fluent SnippetsAI16/7/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets easy-code-manager allows Cross Site Request Forgery.This issue affects FluentSnippets: from n/a through <= 10.50.
AnalizadaMedia (6.5)0.22%—Pluginsandsnippets Simple Page Access Restriction30/5/202517/6/2026
The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and capability checks in the settings save handler in the settings.php script. This makes it possible for unauthenticated attackers…
AnalizadaMedia (6.3)0.29%—Jtsternberg Code Snippets CPT8/3/202517/6/2026
The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated…
AplazadaAlta (7.6)0.62%—Alphabpo Easy Code SnippetsAI16/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpha BPO Easy Code Snippets easy-code-snippets allows SQL Injection.This issue affects Easy Code Snippets: from n/a through <= 1.0.2.
AplazadaMedia (5.3)0.47%—Pluginsandsnippets Simple Page Access RestrictionAI18/12/202417/6/2026
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level…
AplazadaMedia (6.1)0.29%—Easy Code SnippetsAI7/12/202417/6/2026
The Easy Code Snippets plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…