Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.34% | — | Muslim Prayer Time Salah IqamahAI | 9/1/2025 | 17/6/2026 | The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID parameter in all versions up to, and including, 1.8.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Alta (7.1) | 0.17% | — | Mmrs151 Prayer-times-anywhereAI | 7/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mmrs151 Prayer Times Anywhere prayer-times-anywhere allows Stored XSS.This issue affects Prayer Times Anywhere: from n/a through <= 2.0.1. | |
| Aplazada | Alta (7.1) | 0.20% | — | Techdabang World Prayer TimeAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in techdabang World Prayer Time world-prayer-time allows Stored XSS.This issue affects World Prayer Time: from n/a through <= 2.0. | |
| Analizada | Media (6.5) | 0.53% | — | Mmrs151 Daily Prayer Time | 25/9/2024 | 17/6/2026 | The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, and including, 2024.08.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Analizada | Alta (7.6) | 0.26% | — | Realwebcare Muslim Prayer Time BD | 26/6/2024 | 17/6/2026 | The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack | |
| Analizada | Media (4.3) | 0.21% | — | Goprayer Prayer | 14/6/2024 | 17/6/2026 | The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Media (6.1) | 0.20% | — | Goprayer Prayer | 14/6/2024 | 17/6/2026 | The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Aplazada | Media (4.4) | 0.27% | — | Nafeza Prayer TimeAI | 4/6/2024 | 17/6/2026 | The Nafeza Prayer Time plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Analizada | Media (5.3) | 0.19% | — | Goprayer WP Prayer | 15/5/2024 | 17/6/2026 | The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | |
| Modificada | Alta (8.8) | 0.35% | — | Goprayer WP Prayer | 15/5/2024 | 17/6/2026 | The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Alta (7.6) | 0.26% | — | Goprayer WP Prayer | 15/5/2024 | 17/6/2026 | The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (5.4) | 0.39% | — | Mmrs151 Daily Prayer Time | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.10.13 versions. | |
| Modificada | Alta (8.8) | 0.32% | — | Mmrs151 Daily Prayer Time | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.03.08 versions. | |
| Modificada | Media (4.3) | 0.38% | — | Goprayer WP Prayer | 12/7/2023 | 17/6/2026 | The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5. This is due to missing or incorrect nonce validation on the save() and export() functions. This makes it possible for unauthenticated attackers to save plugin settings and trigger a data export via a… | |
| Modificada | Media (5.4) | 0.40% | — | Mmrs151 Daily Prayer Time | 22/6/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.05.04 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Goprayer WP Prayer | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Go Prayer WP Prayer plugin <= 1.9.6 versions. | |
| Modificada | Crítica (9.8) | 9.0% | — | Daily Prayer Time Project Daily Prayer Time | 18/4/2022 | 17/6/2026 | The Daily Prayer Time WordPress plugin before 2022.03.01 does not sanitise and escape the month parameter before using it in a SQL statement via the get_monthly_timetable AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection | |
| Modificada | Media (5.4) | 0.62% | — | Mmrs151 Daily Prayer Time | 13/9/2021 | 17/6/2026 | The Daily Prayer Time WordPress plugin before 2021.08.10 does not sanitise or escape some of its settings before outputting them in the page, leading to Authenticated Stored Cross-Site Scripting issues. | |
| Modificada | Media (5.4) | 0.70% | — | Goprayer WP Prayer | 1/6/2021 | 17/6/2026 | The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer engine. An authenticated WordPress user with any role can fill in the form to request a prayer. The… | |
| Modificada | Media (4.3) | 0.84% | — | Prayer Project Prayer | 26/10/2018 | 17/6/2026 | Prayer through 1.3.5 sends a Referer header, containing a user's username, when a user clicks on a link in their email because header.t lacks a no-referrer setting. | |
| Modificada | Crítica (9.8) | 58% | — | Mlwebtechnologies Prayercenter | 22/2/2018 | 17/6/2026 | SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerability than CVE-2008-6429. | |
| Modificada | Media (5.4) | 0.27% | — | Buddhist Prayer Project Buddhist Prayer | 20/10/2014 | 17/6/2026 | The Buddhist Prayer (aka com.buddhist.prayer.mantra.sutra) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 0.85% | — | Fr.simon Rundell STE Prayer2 | 22/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Random Prayer 2 (ste_prayer2) extension 0.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.5% | — | Fr.simon Rundell STE Prayer2 | 22/12/2009 | 16/6/2026 | SQL injection vulnerability in the Random Prayer 2 (ste_prayer2) extension 0.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Fr.simon Rundell STE Prayer | 10/4/2009 | 16/6/2026 | SQL injection vulnerability in Random Prayer (ste_prayer) 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. |