Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.22% | — | Creativeinteractivemedia Real3d FlipbookAI | 23/9/2026 | 23/9/2026 | The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access and above to delete other users' flipbook content and overwrite administrator-only global settings, which can be leveraged to store… | |
| Aplazada | Media (6.8) | 0.29% | — | Creativeinteractivemedia Real3d FlipbookAI | 23/9/2026 | 23/9/2026 | The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any user who later opens the affected flipbook for… | |
| Aplazada | Media (6.4) | 0.19% | — | Real3d Flipbook LiteAI | 19/9/2026 | 21/9/2026 | The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lightboxtext' shortcode attribute (and other unsanitized attributes handled by on_shortcode()) in versions up to, and including, 5.1.1. This is due to insufficient input sanitization and output escaping in the… | |
| Aplazada | Media (6.5) | 0.17% | — | Creativeinteractivemedia Real3d-flipbook-liteAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativeinteractivemedia Real 3D FlipBook real3d-flipbook-lite allows Stored XSS.This issue affects Real 3D FlipBook: from n/a through <= 4.11.4. | |
| Aplazada | Alta (8.8) | 1.2% | — | Real3d Flipbook LiteAI | 16/11/2024 | 17/6/2026 | The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'r3dfb_save_thumbnail_callback' function in all versions up to, and including, 4.8. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (6.1) | 1.0% | — | Creativeinteractivemedia Real3d Flipbook | 16/9/2019 | 17/6/2026 | The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks.php bookId parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | Creativeinteractivemedia Real3d Flipbook | 16/9/2019 | 17/6/2026 | The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload. | |
| Modificada | Alta (7.5) | 2.2% | — | Creativeinteractivemedia Real3d Flipbook | 16/9/2019 | 17/6/2026 | The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion. |