Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2494▼ 451 respecto a la semana anterior
Críticas / altas1280▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.36% | — | Pinterest Site VerificationAIMeta TAG ManagerAI | 8/4/2026 | 25/7/2026 | The Pinterest Site Verification plugin using Meta Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_var' parameter in versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.21% | — | Codefish Pinterest Pinboard WidgetAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codefish Pinterest Pinboard Widget pinterest-pinboard-widget allows Stored XSS.This issue affects Pinterest Pinboard Widget: from n/a through <= 1.0.7. | |
| Aplazada | Alta (8.5) | 0.28% | — | Valvepress Pinterest Automatic PINAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows SQL Injection.This issue affects Pinterest Automatic Pin: from n/a through < 4.19.0. | |
| Aplazada | Media (5.9) | 0.26% | — | Marvie Pons Pinterest Verify Meta TAGAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marvie Pons Pinterest Verify Meta Tag pinterest-verify-meta-tag allows Stored XSS.This issue affects Pinterest Verify Meta Tag: from n/a through <= 1.3. | |
| Aplazada | Media (4.3) | 0.28% | — | Valvepress Pinterest Automatic PINAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ValvePress Pinterest Automatic Pin wp-pinterest-automatic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinterest Automatic Pin: from n/a through <= 4.19.0. | |
| Aplazada | Alta (7.1) | 0.26% | — | Lemonadestudio Lemonade Social Networks Autoposter PinterestAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lemonadestudio Lemonade Social Networks Autoposter Pinterest lemonade-sna-pinterest-edition allows Reflected XSS.This issue affects Lemonade Social Networks Autoposter Pinterest: from n/a through <= 2.0. | |
| Aplazada | Media (5.4) | 0.45% | — | Gsplugins GS Pins FOR PinterestAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in GS Plugins GS Pins for Pinterest allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GS Pins for Pinterest: from n/a through 1.6.7. | |
| Analizada | Media (5.4) | 0.29% | — | Gsplugins GS Pinterest Portfolio | 3/12/2024 | 17/6/2026 | The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gs_pin_widget' shortcode in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping on user supplied… | |
| Modificada | Media (6.5) | 0.27% | — | Gsplugins GS Pinterest Portfolio | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Pins for Pinterest allows Stored XSS.This issue affects GS Pins for Pinterest: from n/a through 1.8.2. | |
| Analizada | Alta (7.3) | 0.24% | — | Pinterest Querybook | 14/3/2024 | 17/6/2026 | Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's datadocs functionality works by using a Websocket Server. The client talks to this WSS whenever updating/deleting/reading any cells as well as for watching the live status of query executions.… | |
| Analizada | Media (6.1) | 0.36% | — | Pinterest Querybook | 28/2/2024 | 17/6/2026 | Querybook is a Big Data Querying UI. When a user searches for their queries, datadocs, tables and lists, the search result is marked and highlighted, and this feature uses dangerouslySetInnerHTML which means that if the highlighted result has an XSS payload it will trigger. While the input to dangerouslySetInnerHTML… | |
| Analizada | Media (6.1) | 0.53% | — | Pinterest Querybook | 21/2/2024 | 17/6/2026 | Querybook is a user interface for querying big data. Prior to version 3.31.1, there is a vulnerability in Querybook's rich text editor that enables users to input arbitrary URLs without undergoing necessary validation. This particular security flaw allows the use of `javascript:` protocol which can potentially trigger… | |
| Modificada | Media (5.4) | 0.36% | — | Bkmacdaddy Pinterest RSS Widget | 8/8/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in bkmacdaddy designs Pinterest RSS Widget plugin <= 2.3.1 versions. | |
| Modificada | Crítica (9.8) | 4.5% | — | Valvepress Pinterest Automatic PIN | 7/6/2023 | 17/6/2026 | The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for unauthenticated attackers to update arbitrary… | |
| Modificada | Media (6.1) | 0.43% | — | Pinterest Querybook | 6/12/2022 | 17/6/2026 | Querybook is an open source data querying UI. In affected versions user provided data is not escaped in the error field of the auth callback url in `querybook/server/app/auth/oauth_auth.py` and `querybook/server/app/auth/okta_auth.py`. This may allow attackers to perform reflected cross site scripting (XSS) if Content… | |
| Modificada | Media (5.4) | 0.63% | — | Thealpinepress Alpine Phototile FOR Pinterest | 23/8/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest plugin <= 1.3.1 at WordPress. | |
| Modificada | Media (5.4) | 0.51% | — | AS - Create Pinterest Pinboard Pages Project AS - Create Pinterest Pinboard Pages | 23/8/2022 | 17/6/2026 | Authenticated (subscriber+) plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability in Akash soni's AS – Create Pinterest Pinboard Pages plugin <= 1.0 at WordPress. | |
| Modificada | Media (6.1) | 1.6% | — | Bestwebsoft Pinterest | 20/8/2019 | 17/6/2026 | The bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues. | |
| Modificada | Alta (8.8) | 0.60% | — | Weblizar Pinterest-feeds | 13/1/2018 | 17/6/2026 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php. | |
| Modificada | Media (6.1) | 0.78% | — | Weblizar Pinterest-feeds | 13/1/2018 | 17/6/2026 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php security parameter. | |
| Modificada | Media (6.1) | 0.95% | — | Weblizar Pinterest-feeds | 13/1/2018 | 17/6/2026 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php PFFREE_Access_Token parameter. | |
| Modificada | Media (6.1) | 0.95% | — | Weblizar Pinterest-feeds | 13/1/2018 | 17/6/2026 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php weblizar_pffree_settings_save_get-users parameter. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… |