Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.30%—Codepeople Polls CP15/5/202517/6/2026
The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).
AnalizadaMedia (5.4)0.30%—Codepeople Polls CP15/5/202517/6/2026
The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).
ModificadaCrítica (9.8)0.79%—Codepeople Polls CP4/3/202317/6/2026
A vulnerability has been found in codepeople cp-polls Plugin 1.0.1 on WordPress and classified as critical. This vulnerability affects unknown code of the file cp-admin-int-message-list.inc.php. The manipulation of the argument lu leads to sql injection. The attack can be initiated remotely. Upgrading to version 1.0.2…
ModificadaMedia (6.1)0.91%—Codepeople Polls CP27/8/201917/6/2026
The cp-polls plugin before 1.0.5 for WordPress has XSS.
ModificadaMedia (6.1)0.91%—Codepeople Polls CP27/8/201917/6/2026
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.