Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

33 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.24%—Wp-pollsAI23/7/20265/10/2026
Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
AplazadaMedia (5.3)0.11%—CP PollsAI15/6/202617/6/2026
WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML pages that execute unwanted poll operations when administrators visit the page while logged in.
AplazadaMedia (5.1)0.19%—CP PollsAI15/6/202617/6/2026
WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unsanitized file upload functionality. Attackers can upload files containing script payloads with event handlers like onerror attributes to execute arbitrary JavaScript in the…
AplazadaMedia (5.9)0.26%—Codepeople CP PollsAI20/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Polls cp-polls allows Stored XSS.This issue affects CP Polls: from n/a through <= 1.0.81.
AnalizadaMedia (5.4)0.30%—Codepeople Polls CP15/5/202517/6/2026
The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).
AnalizadaMedia (5.4)0.30%—Codepeople Polls CP15/5/202517/6/2026
The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).
AplazadaAlta (7.1)0.15%—Felixtz Modern-pollsAI24/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in felixtz Modern Polls modern-polls allows Stored XSS.This issue affects Modern Polls: from n/a through <= 1.0.10.
AnalizadaMedia (5.3)0.48%—Wp-polls Project Wp-polls22/1/202517/6/2026
The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional…
AplazadaMedia (5.4)0.41%—Mare.io Popup Surveys AND PollsAI16/12/202417/6/2026
Missing Authorization vulnerability in Eric Sloan Popup Surveys & Polls for WordPress (Mare.io) popup-surveys allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Surveys & Polls for WordPress (Mare.io): from n/a through <= 1.36.
AplazadaMedia (4.3)1.1%💥 PoCLiquidpoll Advanced Polls FOR Creators AND BrandsAI13/12/202417/6/2026
Missing Authorization vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a through 3.3.68.
AplazadaAlta (7.1)0.32%—Codepeople CP PollsAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Polls cp-polls allows Reflected XSS.This issue affects CP Polls: from n/a through <= 1.0.74.
AplazadaMedia (5.3)0.41%—Codepeople CP PollsAI17/5/202417/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allows Code Injection.This issue affects CP Polls: from n/a through 1.0.71.
AplazadaMedia (5.3)0.42%—Codepeople CP PollsAI17/5/202417/6/2026
: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.
ModificadaCrítica (9.8)0.79%—Codepeople Polls CP4/3/202317/6/2026
A vulnerability has been found in codepeople cp-polls Plugin 1.0.1 on WordPress and classified as critical. This vulnerability affects unknown code of the file cp-admin-int-message-list.inc.php. The manipulation of the argument lu leads to sql injection. The attack can be initiated remotely. Upgrading to version 1.0.2…
ModificadaMedia (5.3)0.67%—Wp-polls Project Wp-polls21/11/202217/6/2026
The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.
ModificadaBaja (3.1)0.41%—Wp-polls Project Wp-polls18/11/202217/6/2026
Auth. (subscriber+) Race Condition vulnerability in WP-Polls plugin <= 2.76.0 on WordPress.
ModificadaMedia (6.1)0.92%—Wp-polls Project Wp-polls27/8/201917/6/2026
The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option.
ModificadaCrítica (9.8)1.8%—Wp-polls Project Wp-polls27/8/201917/6/2026
The wp-polls plugin before 2.72 for WordPress has SQL injection.
ModificadaMedia (6.1)0.91%—Codepeople Polls CP27/8/201917/6/2026
The cp-polls plugin before 1.0.5 for WordPress has XSS.
ModificadaMedia (6.1)0.91%—Codepeople Polls CP27/8/201917/6/2026
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
ModificadaAlta (7.3)1.6%—Gamerpolls5/6/201817/6/2026
An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of the account they wish to take over, and re-sign it using the hard coded secret.
ModificadaMedia (4.3)2.0%—Sodahead Polls1/1/201516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Sodahead Polls plugin before 2.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via (1) the poll_id parameter to customizer.php or (2) the customize parameter to poll.php.
ModificadaMedia (4.3)1.6%—Polldaddy Polls & Ratings Plugin Project Polldaddy Polls & Ratings10/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Polldaddy Polls & Ratings plugin before 2.0.25 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a ratings shortcode and a unique ID. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.91%💥 Exploit2daybiz Polls Script2/11/201116/6/2026
SQL injection vulnerability in searchvote.php in 2daybiz Polls (aka Advanced Poll) Script allows remote attackers to execute arbitrary SQL commands via the category parameter.
ModificadaMedia (5.8)3.2%💥 ExploitFocalmedia.net Quick Polls9/3/201116/6/2026
Multiple directory traversal vulnerabilities in FocalMedia.Net Quick Polls before 1.0.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the p parameter in a preview action to index.php, or (2) delete arbitrary files via a .. (dot dot) in the p parameter in a delete action to index.php.
Orbitaley — Vulnerabilidades