Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
–

2389 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.27%—Appointment Booking Plugin LatepointAI2/10/20262/10/2026
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through…
AplazadaCrítica (10)0.31%—Backupsheep Wordpress Backup PluginAI1/10/20261/10/2026
The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files…
AplazadaMedia (6.5)0.13%—Plugin-planet User Submitted PostsAI30/9/202630/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS. This issue affects User Submitted Posts: from n/a through 20260810.
AplazadaAlta (7.5)0.27%—Booking-wp-plugin BooklyAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
AplazadaMedia (6.5)0.28%—Booking-wp-plugin BooklyAI30/9/202630/9/2026
Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.
AplazadaMedia (5.8)0.21%—Pluginrx Broken Link NotifierAI30/9/202630/9/2026
The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address filter and make the server send requests to internal services.
AplazadaAlta (7.2)0.19%—Htplugins HT Contact FormAI29/9/202630/9/2026
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
AplazadaAlta (8.8)0.40%—Convertplug ConvertplusAI28/9/202629/9/2026
The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action's nonce guard is gated behind an isset() check and fails open when the…
AplazadaMedia (5.3)0.22%—Booking-wp-plugin BooklyAI28/9/202628/9/2026
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.
AplazadaAlta (8.4)0.29%—Getgrav Grav Plugin DatamanagerAI26/9/202630/9/2026
The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by…
AplazadaAlta (8.7)0.45%—Getgrav Grav Plugin CommentsAI26/9/202628/9/2026
The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the admin service is registered on the current route rather than that the…
AplazadaMedia (6.9)0.31%—Grav-plugin-loginAI26/9/202628/9/2026
grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challenge to be bypassed for content gated by the authenticated() Twig function or the [authenticated] shortcode. On sites with 2FA enabled, Login::isAuthenticated() checked only the session flag indicating…
AplazadaMedia (5.3)0.18%—Booking-wp-plugin BooklyAI25/9/202625/9/2026
The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifier to overwrite that customer's stored personal information such as name, email and address.
AplazadaAlta (7.5)0.75%—Weplugins WP MapsAI25/9/202625/9/2026
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above,…
AplazadaMedia (6.4)0.33%—Weplugins WP MapsAI25/9/202625/9/2026
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapes_values Parameter in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaCrítica (9.1)0.37%—Booking-wp-plugin BooklyAI25/9/202626/9/2026
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the…
AplazadaMedia (5.3)0.32%—Booking-wp-plugin BooklyAI25/9/202625/9/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2. This is due to the `postValidateCustomer()` function using a loose PHP inequality operator (`!=`) to compare the session-stored…
AplazadaBaja (3.5)0.14%—Pickplugins Post GridAI24/9/202624/9/2026
The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input elements that are normally stripped from their content, leading to HTML injection…
AplazadaMedia (6.5)0.17%—Pickplugins Post GridAI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.
Pendiente de análisisAlta (8.8)1.1%—Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Application Manager PluginAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.
AplazadaMedia (5.9)0.16%—Tauri Updater PluginAI23/9/202623/9/2026
The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains the version number, download URL, and signature -- is fetched over TLS but is never itself signed or authenticated. Because the only anti-rollback check…
AplazadaMedia (4.3)0.15%—Oplugins Booking ManagerAI23/9/202623/9/2026
The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking…
AplazadaMedia (6.8)0.23%—Oplugins Booking ManagerAI23/9/202623/9/2026
The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to perform SQL injection attacks by importing a feed they control.
AplazadaMedia (6.5)0.20%—Payment Plugins FOR Paypal WoocommerceAI23/9/202623/9/2026
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, allowing unauthenticated attackers to have another buyer's approved but uncaptured…
AplazadaMedia (5.6)0.24%—Tauri Http PluginAIReqwestAI22/9/202622/9/2026
The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally without re-checking the new target URL against the scope. This allows an attacker who…