Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.32% | — | WP User ProfilesAI | 6/10/2026 | 6/10/2026 | Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions. | |
| Aplazada | Media (4.3) | 0.34% | — | Profilegrid Memberships AND User Profiles FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid()… | |
| Aplazada | Media (4.3) | 0.14% | — | ADD Google Social Profiles TO Knowledge Graph BOXAI | 21/3/2026 | 17/6/2026 | The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's… | |
| Aplazada | Alta (7) | 0.24% | — | Joomla ProfilesAI | 23/7/2025 | 17/6/2026 | A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered. | |
| Aplazada | Alta (8.8) | 0.39% | — | John James Jacoby WP User ProfilesAI | 10/4/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in John James Jacoby WP User Profiles wp-users-profiles allows Privilege Escalation.This issue affects WP User Profiles: from n/a through <= 2.6.2. | |
| Modificada | Media (4.8) | 0.37% | — | Usbmemorydirect Simple Custom Author Profiles | 9/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in USB Memory Direct Simple Custom Author Profiles plugin <= 1.0.0 versions. | |
| Modificada | Media (5.4) | 0.40% | — | Themekraft Post Form Registration Form Profile Form FOR User Profiles AND Content Forms | 16/3/2023 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions. | |
| Modificada | Media (4.8) | 0.60% | — | Wpsheeteditor Bulk Edit AND Create User Profiles - WP Sheet Editor | 16/5/2022 | 17/6/2026 | The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Alta (7.8) | 0.43% | — | Rockwellautomation Drivetools Add-on ProfilesRockwellautomation Drivetools SP | 18/3/2021 | 17/6/2026 | Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited privileges may be able to exploit resulting in privilege escalation and complete control of the system. | |
| Modificada | Media (4.8) | 0.66% | — | Profiles Project Profiles | 26/4/2019 | 17/6/2026 | XSS exists in the ProFiles 1.5 component for Joomla! via the name or path parameter when creating a new folder in the administrative panel. | |
| Modificada | Alta (7.5) | 1.00% | — | V3chat V3 Chat Profiles Dating Script | 31/12/2008 | 16/6/2026 | SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. | |
| Modificada | Crítica (9.8) | 7.1% | — | V3chat V3 Chat Profiles Dating Script | 31/12/2008 | 16/6/2026 | V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1. | |
| Modificada | Alta (7.5) | 1.0% | — | E107 Alternate Profiles Plugin | 29/10/2008 | 16/6/2026 | SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 21% | — | Phpprofiles | 27/2/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in include/body_comm.inc.php in phpProfiles 4.5.2 BETA allows remote attackers to execute arbitrary PHP code via a URL in the content parameter. | |
| Modificada | Alta (7.5) | 9.5% | — | Phpprofiles | 26/12/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the menu parameter to (1) include/body.inc.php or (2) include/body_admin.inc.php; or a URL in the incpath parameter to (3) index.inc.php, (4) account.inc.php, (5)… | |
| Modificada | Media (4.6) | 0.32% | — | Phpprofiles | 26/12/2006 | 16/6/2026 | phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php. | |
| Modificada | Baja (2.1) | 0.48% | — | Phpprofiles | 26/12/2006 | 16/6/2026 | phpProfiles before 2.1.1 does not have an index.php or other index file in the (1) image_data, (2) graphics/comm, or (3) users read/write directories, which might allow remote attackers to list directory contents or have other unknown impacts. | |
| Modificada | Media (6.8) | 6.2% | — | Phpprofiles | 1/11/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in users/include/; or the (2) usrinc parameter in users/include/upload_ht.inc.php. |