Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

200 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.19%—Real Estate ManagerAI30/9/202630/9/2026
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_price_text' parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
En análisisMedia (5.3)0.26%—Ordasoft Real Estate ManagerAI28/9/202630/9/2026
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same…
En análisisCrítica (9.3)0.28%—Ordasoft Real Estate ManagerAI28/9/202630/9/2026
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field…
AplazadaAlta (7.1)0.25%—Estatik Real Estate PluginAI19/9/202621/9/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting.
AplazadaAlta (7.1)0.28%—Realtyna Organic IDXAIRealtyna WPL Real EstateAI17/9/202618/9/2026
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link…
AplazadaMedia (4.3)0.10%—Real Estate PapiAI6/9/20268/9/2026
The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion from the WordPress.org repository. Where the request runs in the session of a user who can activate ,…
AplazadaMedia (5.5)0.43%—Itsourcecode Real Estate Management SystemAI24/8/202627/8/2026
A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The attack may be initiated remotely. The…
AplazadaAlta (7.1)0.25%—Simplyrets Real Estate IDXAI19/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.
AplazadaAlta (8.8)0.52%—Essential Real EstateAI18/8/202620/8/2026
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
AplazadaAlta (7.5)0.36%—Real Estate Manager PROAI15/8/202620/8/2026
The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in the allow_attachment_actions() function, which can treat a target user ID as a media attachment ID during user capability checks. This…
AplazadaBaja (3.7)0.14%—Estatik Real Estate PluginAI12/8/202626/8/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To on sites where the form is…
AplazadaAlta (7.5)0.23%—Estatik Real Estate PluginAI7/8/202626/8/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the…
AplazadaMedia (5.3)0.30%—Estatik Real Estate PluginAI6/8/202626/8/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a…
AplazadaMedia (4.3)0.16%—Mlsimport IDX Plugin MLS Plugin FOR Real Estate ListingsAI5/8/202626/8/2026
The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress…
AplazadaCrítica (9.8)4.0%—Realtyna Organic IDXAIRealtyna WPL Real EstateAI31/7/202612/8/2026
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by…
AplazadaCrítica (9.8)0.83%—Realtyna Organic IDXAIRealtyna WPL Real EstateAI27/7/202627/7/2026
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it…
AplazadaAlta (7.1)0.25%—Real Estate Manager PROAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
AplazadaAlta (7.1)0.25%—Webcodingplace Real Estate Manager PROAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Real Estate Manager Pro real-estate-manager-pro allows Reflected XSS.This issue affects Real Estate Manager Pro: from n/a through <= 12.8.3.
AplazadaAlta (7.1)0.36%—Microrealestate Micro Real EstateAI7/7/20267/7/2026
MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects MicroRealEstate: through 1.0.0-alpha3.
AplazadaAlta (7.1)0.25%—Real EstateAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.
AplazadaMedia (6.5)0.17%—Real EstateAI26/6/202626/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.
AplazadaCrítica (9.3)0.40%—Real EstateAI26/6/202626/6/2026
Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.
AplazadaMedia (5.1)0.17%—Zoner Real EstateAI4/6/202622/7/2026
WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field when creating properties. Attackers can inject JavaScript payloads in the property creation form that execute when administrators…
AplazadaMedia (5.5)0.24%—E-plugins Real Estate PROAI22/4/202617/6/2026
The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject…
AplazadaMedia (5.1)0.22%—Jproperty Iproperty Real EstateAI9/4/202626/9/2026
Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter of the all-properties-with-map endpoint…