Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▲ 27 respecto a la semana anterior
Críticas / altas1477▲ 294 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.51% | — | Pickplugins Question AnswerAI | 28/7/2026 | 28/7/2026 | The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization of user-supplied input via the 'id' GET parameter in the user profile template combined with the use of wp_unslash() which removes WordPress's magic… | |
| Aplazada | Crítica (9.1) | 0.42% | — | Question2answerAI | 22/7/2026 | 7/8/2026 | Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the sessioncode field in qa-include/app/users-edit.php. While the normal… | |
| Aplazada | Alta (8.8) | 0.48% | — | Pickplugins Question AnswerAI | 17/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PickPlugins Question Answer question-answer allows Object Injection.This issue affects Question Answer: from n/a through <= 1.2.73. | |
| Aplazada | Alta (7.1) | 0.29% | — | Pickplugins Question AnswerAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Question Answer question-answer allows Reflected XSS.This issue affects Question Answer: from n/a through <= 1.2.70. | |
| Aplazada | Media (5.3) | 0.45% | — | Pickplugins Question AnswerAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Question Answer question-answer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Question Answer: from n/a through <= 1.2.73. | |
| Modificada | Alta (7.5) | 1.6% | — | Question2answer | 29/8/2017 | 17/6/2026 | qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts. |