Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.33% | — | Mappresspro MappressAI | 27/7/2026 | 27/7/2026 | Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mappress MapsAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions. | |
| Aplazada | Media (5.3) | 1.3% | — | Mappress MapsAI | 6/6/2026 | 23/7/2026 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.96.6. This is due to missing ownership verification in the REST API routes registered via `Mappress_Api::rest_api_init()`, where the GET… | |
| Aplazada | Media (5.3) | 0.30% | — | ApppresserAI | 30/10/2025 | 17/6/2026 | The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'myappp_verify' function in all versions up to, and including, 4.5.0. This makes it possible for unauthenticated attackers to extract sensitive data including plugin and… | |
| Analizada | Alta (8.8) | 0.60% | — | Yandaozi Ppress | 19/9/2025 | 17/6/2026 | Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes. | |
| Analizada | Alta (8) | 0.32% | — | Yandaozi Ppress | 19/9/2025 | 17/6/2026 | An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie. | |
| Analizada | Alta (8.8) | 0.41% | — | Yandaozi Ppress | 19/9/2025 | 17/6/2026 | Hardcoded credentials in default configuration of PPress 0.0.9. | |
| Analizada | Media (4.8) | 0.31% | — | Mappresspro Mappress | 15/5/2025 | 17/6/2026 | The MapPress Maps for WordPress plugin before 2.93 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.8) | 0.39% | — | Mappresspro Mappress | 18/4/2025 | 17/6/2026 | The MapPress Maps for WordPress plugin before 2.94.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (6.8) | 0.46% | — | Mappresspro Mappress | 3/4/2025 | 17/6/2026 | The MapPress Maps for WordPress plugin before 2.94.9 does not sanitise and escape some parameters when outputing them in the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks. | |
| Analizada | Media (6.1) | 0.33% | — | Apppresser | 13/3/2025 | 17/6/2026 | The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 4.4.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Analizada | Media (5.4) | 0.27% | — | Tiptoppress Gallery Styles | 8/3/2025 | 17/6/2026 | The Gallery Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery Block in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Analizada | Media (6.5) | 0.54% | — | Yandaozi Ppress | 20/2/2025 | 17/6/2026 | A stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote attacker to execute arbitrary code via a crafted script to the article.title, article.category, and article.tags parameters. | |
| Analizada | Crítica (9.8) | 0.70% | — | Apppresser | 26/11/2024 | 17/6/2026 | The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.6. This is due to the plugin not properly validating a user's password reset code prior to updating their password. This makes it possible for unauthenticated… | |
| Analizada | Media (5.4) | 0.26% | — | Mappresspro Mappress | 6/11/2024 | 17/6/2026 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and including, 2.94.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Crítica (9.8) | 0.68% | — | Apppresser | 16/10/2024 | 17/6/2026 | The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the appp_reset_password() and validate_reset_password() functions not having enough controls to prevent a successful brute force attack of… | |
| Aplazada | Media (5.9) | 0.27% | — | WapppressAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WappPress Team WappPress allows Stored XSS.This issue affects WappPress: from n/a through 6.0.4. | |
| Analizada | Media (4.8) | 0.44% | — | Tiptoppress Term AND Category Based Posts WidgetZephyrwest Category Posts Widget | 12/8/2024 | 17/6/2026 | The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4.9.13 does not validate and escape some of its "Category Posts" widget settings before outputting them back in a page/post where the Widget is embed, which could allow high privilege users such as… | |
| Aplazada | Media (4.9) | 0.22% | — | WapppressAI | 20/7/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WappPress Team WappPress.This issue affects WappPress: from n/a through 6.0.4. | |
| Modificada | Alta (8.1) | 0.50% | — | Apppresser | 29/5/2024 | 17/6/2026 | The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up to, and including, 4.3.2. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an… | |
| Modificada | Media (6.5) | 0.46% | — | Apppresser | 14/5/2024 | 17/6/2026 | Missing Authorization vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0. | |
| Modificada | Alta (8.8) | 0.24% | — | Apppresser | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Bolinger AppPresser apppresser allows Cross Site Request Forgery.This issue affects AppPresser: from n/a through <= 4.3.0. | |
| Modificada | Alta (8.8) | 0.32% | — | Apppresser | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0. | |
| Aplazada | Crítica (10) | 0.63% | — | WapppressAI | 27/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WappPress Team WappPress.This issue affects WappPress: from n/a through 5.0.3. | |
| Modificada | Media (5.3) | 0.61% | — | Mappresspro Mappress Maps FOR Wordpress | 12/2/2024 | 17/6/2026 | The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an AJAX action is a public map, allowing unauthenticated users to read arbitrary private and draft posts. |