Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Wp-property-hive PropertyhiveAI | 17/9/2026 | 17/9/2026 | Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wp-property-hive PropertyhiveAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wp-property-hive PropertyhiveAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows DOM-Based XSS.This issue affects PropertyHive: from n/a through <= 2.2.2. | |
| Aplazada | Alta (7.5) | 0.27% | — | Wp-property-hive PropertyhiveAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12. | |
| Aplazada | Media (6.5) | 0.21% | — | Wp-property-hive PropertyhiveAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Stored XSS.This issue affects PropertyHive: from n/a through <= 2.1.5. | |
| Aplazada | Media (6.5) | 0.32% | — | Wp-property-hive PropertyhiveAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Stored XSS.This issue affects PropertyHive: from n/a through <= 2.1.2. | |
| Analizada | Media (6.1) | 0.62% | — | Wp-property-hive Propertyhive | 8/1/2025 | 17/6/2026 | The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (6.4) | 0.31% | — | Propertyhive Stamp Duty CalculatorAI | 13/12/2024 | 17/6/2026 | The Property Hive Stamp Duty Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stamp_duty_calculator_scotland' shortcode in all versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Analizada | Media (4.3) | 0.39% | — | Wp-property-hive Propertyhive | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9. | |
| Analizada | Media (6.5) | 0.35% | — | Wp-property-hive Propertyhive | 17/9/2024 | 17/6/2026 | The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation on the 'save_account_details' function. This makes it possible for unauthenticated attackers to edit the name, email address, and password… | |
| Modificada | Media (5.4) | 0.26% | — | Wp-property-hive Propertyhive | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.13. | |
| Modificada | Media (5.4) | 0.33% | — | Wp-property-hive Propertyhive | 6/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10. | |
| Modificada | Media (4.3) | 0.61% | — | Wp-property-hive Propertyhive | 2/5/2024 | 17/6/2026 | The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts | |
| Modificada | Alta (8.8) | 0.38% | — | Wp-property-hive Propertyhive | 11/4/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9. | |
| Modificada | Media (6.1) | 0.40% | — | Wp-property-hive Propertyhive | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Reflected XSS.This issue affects PropertyHive: from n/a through 2.0.8. | |
| Modificada | Media (6.5) | 0.32% | — | Wp-property-hive Propertyhive | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6. | |
| Modificada | Crítica (9.8) | 0.52% | — | Wp-property-hive Propertyhive | 12/2/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5. | |
| Modificada | Media (6.1) | 0.38% | — | Wp-property-hive Propertyhive | 15/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Wp-property-hive Propertyhive | 7/4/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.46 versions. | |
| Modificada | Media (6.1) | 1.6% | — | Wp-property-hive Propertyhive | 31/1/2018 | 17/6/2026 | The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php. |