Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.24% | — | Wp-pollsAI | 23/7/2026 | 5/10/2026 | Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions. | |
| Aplazada | Media (5.3) | 0.11% | — | CP PollsAI | 15/6/2026 | 17/6/2026 | WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML pages that execute unwanted poll operations when administrators visit the page while logged in. | |
| Aplazada | Media (5.1) | 0.19% | — | CP PollsAI | 15/6/2026 | 17/6/2026 | WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unsanitized file upload functionality. Attackers can upload files containing script payloads with event handlers like onerror attributes to execute arbitrary JavaScript in the… | |
| Aplazada | Media (5.9) | 0.26% | — | Codepeople CP PollsAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Polls cp-polls allows Stored XSS.This issue affects CP Polls: from n/a through <= 1.0.81. | |
| Analizada | Media (5.4) | 0.30% | — | Codepeople Polls CP | 15/5/2025 | 17/6/2026 | The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup). | |
| Analizada | Media (5.4) | 0.30% | — | Codepeople Polls CP | 15/5/2025 | 17/6/2026 | The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup). | |
| Aplazada | Alta (7.1) | 0.15% | — | Felixtz Modern-pollsAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in felixtz Modern Polls modern-polls allows Stored XSS.This issue affects Modern Polls: from n/a through <= 1.0.10. | |
| Analizada | Media (5.3) | 0.48% | — | Wp-polls Project Wp-polls | 22/1/2025 | 17/6/2026 | The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional… | |
| Aplazada | Media (5.4) | 0.41% | — | Mare.io Popup Surveys AND PollsAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Eric Sloan Popup Surveys & Polls for WordPress (Mare.io) popup-surveys allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Surveys & Polls for WordPress (Mare.io): from n/a through <= 1.36. | |
| Aplazada | Media (4.3) | 1.1% | 💥 PoC | Liquidpoll Advanced Polls FOR Creators AND BrandsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in LiquidPoll LiquidPoll – Advanced Polls for Creators and Brands allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LiquidPoll – Advanced Polls for Creators and Brands: from n/a through 3.3.68. | |
| Aplazada | Alta (7.1) | 0.32% | — | Codepeople CP PollsAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Polls cp-polls allows Reflected XSS.This issue affects CP Polls: from n/a through <= 1.0.74. | |
| Aplazada | Media (5.3) | 0.41% | — | Codepeople CP PollsAI | 17/5/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allows Code Injection.This issue affects CP Polls: from n/a through 1.0.71. | |
| Aplazada | Media (5.3) | 0.42% | — | Codepeople CP PollsAI | 17/5/2024 | 17/6/2026 | : Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71. | |
| Modificada | Crítica (9.8) | 0.79% | — | Codepeople Polls CP | 4/3/2023 | 17/6/2026 | A vulnerability has been found in codepeople cp-polls Plugin 1.0.1 on WordPress and classified as critical. This vulnerability affects unknown code of the file cp-admin-int-message-list.inc.php. The manipulation of the argument lu leads to sql injection. The attack can be initiated remotely. Upgrading to version 1.0.2… | |
| Modificada | Media (5.3) | 0.67% | — | Wp-polls Project Wp-polls | 21/11/2022 | 17/6/2026 | The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations. | |
| Modificada | Baja (3.1) | 0.41% | — | Wp-polls Project Wp-polls | 18/11/2022 | 17/6/2026 | Auth. (subscriber+) Race Condition vulnerability in WP-Polls plugin <= 2.76.0 on WordPress. | |
| Modificada | Media (6.1) | 0.92% | — | Wp-polls Project Wp-polls | 27/8/2019 | 17/6/2026 | The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option. | |
| Modificada | Crítica (9.8) | 1.8% | — | Wp-polls Project Wp-polls | 27/8/2019 | 17/6/2026 | The wp-polls plugin before 2.72 for WordPress has SQL injection. | |
| Modificada | Media (6.1) | 0.91% | — | Codepeople Polls CP | 27/8/2019 | 17/6/2026 | The cp-polls plugin before 1.0.5 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.91% | — | Codepeople Polls CP | 27/8/2019 | 17/6/2026 | The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list. | |
| Modificada | Alta (7.3) | 1.6% | — | Gamerpolls | 5/6/2018 | 17/6/2026 | An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of the account they wish to take over, and re-sign it using the hard coded secret. | |
| Modificada | Media (4.3) | 2.0% | — | Sodahead Polls | 1/1/2015 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Sodahead Polls plugin before 2.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via (1) the poll_id parameter to customizer.php or (2) the customize parameter to poll.php. | |
| Modificada | Media (4.3) | 1.6% | — | Polldaddy Polls & Ratings Plugin Project Polldaddy Polls & Ratings | 10/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Polldaddy Polls & Ratings plugin before 2.0.25 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a ratings shortcode and a unique ID. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | 2daybiz Polls Script | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in searchvote.php in 2daybiz Polls (aka Advanced Poll) Script allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Media (5.8) | 3.2% | 💥 Exploit | Focalmedia.net Quick Polls | 9/3/2011 | 16/6/2026 | Multiple directory traversal vulnerabilities in FocalMedia.Net Quick Polls before 1.0.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the p parameter in a preview action to index.php, or (2) delete arbitrary files via a .. (dot dot) in the p parameter in a delete action to index.php. |