Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.33% | — | Realestateconnected Easy Property ListingsAI | 1/8/2026 | 12/8/2026 | The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Method in all versions up to, and including, 3.5.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Alta (7.1) | 0.54% | — | MicrorealestateAI | 7/7/2026 | 7/7/2026 | Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. This issue affects MicroRealEstate: through 1.0.0-alpha3. | |
| Aplazada | Media (5.3) | 0.36% | — | MicrorealestateAI | 7/7/2026 | 7/7/2026 | Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3. | |
| Aplazada | Alta (7.1) | 0.36% | — | MicrorealestateAI | 7/7/2026 | 7/7/2026 | Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3. | |
| Aplazada | Alta (7.1) | 0.36% | — | Microrealestate Micro Real EstateAI | 7/7/2026 | 7/7/2026 | MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects MicroRealEstate: through 1.0.0-alpha3. | |
| Aplazada | Alta (8.8) | 0.60% | — | MicrorealestateAI | 7/7/2026 | 7/7/2026 | MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This issue affects MicroRealEstate: through 1.0.0-alpha3. | |
| Aplazada | Alta (8.8) | 0.38% | — | Inout RealestateAI | 12/3/2026 | 17/6/2026 | Inout RealEstate contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the city parameter. Attackers can send POST requests to the agents/agentlistdetails endpoint with malicious SQL payloads in the city parameter to extract sensitive… | |
| Aplazada | Media (6.5) | 0.32% | — | Realestateconnected Easy Property ListingsAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from n/a through <= 3.5.20. | |
| Aplazada | Media (4.3) | 0.22% | — | Realestateconnected Easy Property ListingsAI | 16/12/2025 | 5/10/2026 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from n/a through <= 3.5.22. | |
| Analizada | Media (4.8) | 0.31% | — | Realestateconnected Easy Property Listings | 15/5/2025 | 17/6/2026 | The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Crítica (9.8) | 0.45% | — | WP RealestateAI | 1/4/2025 | 17/6/2026 | The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions up to, and including, 1.6.26. This is due to insufficient role restrictions in the 'process_register' function. This makes it possible for unauthenticated attackers to register an account with the… | |
| Analizada | Media (4.3) | 0.23% | — | Realestateconnected Easy Property Listings | 12/9/2024 | 17/6/2026 | The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack | |
| Analizada | Crítica (9.8) | 0.36% | — | Realestateconnected Easy Property Listings | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings.This issue affects Easy Property Listings: from n/a through 3.5.3. | |
| Modificada | Alta (8.8) | 0.77% | — | Realestateconnected Easy Property Listings | 9/4/2024 | 17/6/2026 | The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shortcode attribute in all versions up to, and including, 3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Modificada | Crítica (9.3) | 1.4% | — | Realestate Project Realestate | 11/7/2022 | 17/6/2026 | The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (8.8) | 0.82% | — | Realestateconnected Easy Property Listings | 18/2/2020 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (6.1) | 1.00% | — | Realestateconnected Easy Property Listings | 30/8/2019 | 17/6/2026 | The easy-property-listings plugin before 3.4 for WordPress has XSS. | |
| Modificada | Media (4.8) | 0.49% | — | Responsive Realestate Script Project Responsive Realestate Script | 27/12/2017 | 17/6/2026 | PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter. | |
| Modificada | Alta (8.8) | 0.46% | — | Responsive Realestate Script Project Responsive Realestate Script | 27/12/2017 | 17/6/2026 | PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general. | |
| Modificada | Crítica (9.8) | 2.2% | — | Responsive Realestate Script Project Responsive Realestate Script | 13/12/2017 | 17/6/2026 | Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter. | |
| Modificada | Crítica (9.8) | 4.4% | — | Realestate Crowdfunding Script Project Realestate Crowdfunding Script | 13/12/2017 | 17/6/2026 | Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Wcs4web Easywebrealestate | 4/10/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in EasyWebRealEstate allow remote attackers to execute arbitrary SQL commands via the (1) lstid parameter to listings.php or (2) infoid parameter to index.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Extensionsforjoomla COM Vikrealestate | 15/12/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract parameter in a results action and (2) imm parameter in a show action to index.php. | |
| Modificada | Alta (7.5) | 1.0% | — | Eicrasoft Eicra Realestate Script | 21/6/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.1% | — | Realestatephp Real Estate Manager | 14/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Real Estate Manager 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. NOTE: some of these details are obtained from third party information. |