Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—Wp-property-hive PropertyhiveAI17/9/202617/9/2026
Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.
AplazadaAlta (7.1)0.25%—Wp-property-hive PropertyhiveAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3.
AplazadaAlta (7.1)0.25%—Wp-property-hive PropertyhiveAI27/5/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows DOM-Based XSS.This issue affects PropertyHive: from n/a through <= 2.2.2.
AplazadaAlta (7.5)0.27%—Wp-property-hive PropertyhiveAI18/12/202517/6/2026
Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12.
AplazadaMedia (6.5)0.21%—Wp-property-hive PropertyhiveAI3/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Stored XSS.This issue affects PropertyHive: from n/a through <= 2.1.5.
AplazadaMedia (6.5)0.32%—Wp-property-hive PropertyhiveAI16/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Stored XSS.This issue affects PropertyHive: from n/a through <= 2.1.2.
AnalizadaMedia (6.1)0.62%—Wp-property-hive Propertyhive8/1/202517/6/2026
The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaMedia (6.4)0.31%—Propertyhive Stamp Duty CalculatorAI13/12/202417/6/2026
The Property Hive Stamp Duty Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stamp_duty_calculator_scotland' shortcode in all versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
AnalizadaMedia (4.3)0.39%—Wp-property-hive Propertyhive1/11/202417/6/2026
Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9.
AnalizadaMedia (6.5)0.35%—Wp-property-hive Propertyhive17/9/202417/6/2026
The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation on the 'save_account_details' function. This makes it possible for unauthenticated attackers to edit the name, email address, and password…
ModificadaMedia (5.4)0.26%—Wp-property-hive Propertyhive8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.13.
ModificadaMedia (5.4)0.33%—Wp-property-hive Propertyhive6/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10.
ModificadaMedia (4.3)0.61%—Wp-property-hive Propertyhive2/5/202417/6/2026
The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts
ModificadaAlta (8.8)0.38%—Wp-property-hive Propertyhive11/4/202417/6/2026
Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9.
ModificadaMedia (6.1)0.40%—Wp-property-hive Propertyhive27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Reflected XSS.This issue affects PropertyHive: from n/a through 2.0.8.
ModificadaMedia (6.5)0.32%—Wp-property-hive Propertyhive26/3/202417/6/2026
Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.
ModificadaCrítica (9.8)0.52%—Wp-property-hive Propertyhive12/2/202417/6/2026
Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5.
ModificadaMedia (6.1)0.38%—Wp-property-hive Propertyhive15/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions.
ModificadaMedia (6.1)0.38%—Wp-property-hive Propertyhive7/4/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.46 versions.
ModificadaMedia (6.1)1.6%—Wp-property-hive Propertyhive31/1/201817/6/2026
The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php.