Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.29% | — | Themegoods PhotographyAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Photography <= 7.7.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Grand PhotographyAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Themegoods Grand PhotographyAI | 13/7/2026 | 13/7/2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8. | |
| Aplazada | Alta (7.1) | 0.25% | — | Artale Wedding PhotographyAI | 2/7/2026 | 5/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions. | |
| Aplazada | Media (5.4) | 0.14% | — | Themegoods Grand PhotographyAI | 8/4/2026 | 20/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Photography grandphotography allows Cross Site Request Forgery.This issue affects Grand Photography: from n/a through <= 5.7.8. | |
| Aplazada | Alta (7.2) | 0.50% | — | Themegoods PhotographyAI | 19/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue affects Photography: from n/a before 7.7.6. | |
| Aplazada | Media (5.3) | 0.32% | — | Vowelweb VW PhotographyAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in vowelweb VW Photography vw-photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Photography: from n/a through <= 1.3.8. | |
| Aplazada | Alta (7.1) | 0.26% | — | Themegoods PhotographyAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Photography photography allows DOM-Based XSS.This issue affects Photography: from n/a through < 7.7.6. | |
| Aplazada | Alta (7.1) | 0.24% | — | Gt3themes Soho - Photography Wordpress ThemeAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes SOHO - Photography WordPress Theme soho allows DOM-Based XSS.This issue affects SOHO - Photography WordPress Theme: from n/a through <= 3.0.3. | |
| Aplazada | Alta (7.1) | 0.27% | — | Gt3themes Oyster - Photography Wordpress ThemeAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GT3themes Oyster - Photography WordPress Theme oyster allows DOM-Based XSS.This issue affects Oyster - Photography WordPress Theme: from n/a through <= 4.4.3. | |
| Aplazada | Alta (8.1) | 0.47% | — | Themegoods PhotographyAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeGoods Photography photography allows PHP Local File Inclusion.This issue affects Photography: from n/a through < 7.7.5. | |
| Analizada | Alta (7.1) | 0.21% | — | Themegoods Photography | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Photography photography allows Reflected XSS.This issue affects Photography: from n/a through <= 7.7.2. | |
| Modificada | Alta (8.1) | 0.33% | — | Themegoods Photography | 9/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Photography photography allows Object Injection.This issue affects Photography: from n/a through <= 7.7.2. | |
| Analizada | Alta (7.5) | 0.37% | — | Themegoods Photography | 6/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a through 7.5.2. | |
| Aplazada | Media (5.4) | 0.21% | — | Themegoods PhotographyAI | 15/4/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Photography photography allows Server Side Request Forgery.This issue affects Photography: from n/a through < 7.7.6. | |
| Aplazada | Media (6.3) | 0.29% | — | Themegoods PhotographyAI | 14/2/2025 | 17/6/2026 | Missing Authorization vulnerability in ThemeGoods Photography photography allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photography: from n/a through <= 7.7.2. | |
| Modificada | Crítica (9.8) | 8.9% | — | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Alta (8.8) | 1.4% | — | Photography CMS Project Photography CMS | 24/1/2018 | 17/6/2026 | Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demonstrated by adding an admin account. | |
| Modificada | Alta (10) | 3.9% | — | Photography-on-the-net Exhibit Engine 2 | 30/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in styles.php in Exhibit Engine (EE) 1.22 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the toroot parameter. | |
| Modificada | Media (6.8) | 1.9% | — | Photography-on-the-net Exhibit Engine 2 | 30/3/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Exhibit Engine (EE) 1.22, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) fetchsettings.php or (2) fstyles.php. NOTE: the provenance of this information is unknown; the details are obtained solely… |