Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2576▼ 298 respecto a la semana anterior
Críticas / altas1356▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
90 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.42% | — | Contextual Related PostsAI | 22/9/2026 | 22/9/2026 | The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes' Block Parameter in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and… | |
| Aplazada | Media (6.5) | 0.36% | — | Hedef Media Promotion Interactive Media Marketing INC Related Marketing CloudAI | 12/6/2026 | 17/6/2026 | Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Marketing Cloud (RMC) allows Brute Force. This issue affects Related Marketing Cloud (RMC): through 12052026. | |
| Aplazada | Alta (8.7) | 0.87% | — | Inducer RelateAI | 27/5/2026 | 17/6/2026 | RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize untrusted 'pickle' data. An attacker who can reach the message broker can execute arbitrary commands on the host server. Combined with missing network… | |
| Aplazada | Alta (8.7) | 0.44% | — | Inducer RelateAI | 27/5/2026 | 17/6/2026 | RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execute arbitrary JavaScript in an administrator's browser session, potentially leading to full admin account takeover. The… | |
| Analizada | Alta (8.1) | 0.45% | — | Inducer Relate | 8/5/2026 | 17/6/2026 | RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16. | |
| Pendiente de análisis | Alta (8.7) | 0.42% | — | Inducer RelateAI | 7/5/2026 | 17/6/2026 | RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key() function and exam.py's gen_ticket_code() function. This issue has been patched via commit 2f68e16. | |
| Aplazada | Media (6.4) | 0.26% | — | Contextual Related PostsAI | 18/4/2026 | 17/6/2026 | The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'other_attributes' parameter in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (5.3) | 0.31% | — | Ajay Contextual Related PostsAI | 18/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Ajay Contextual Related Posts contextual-related-posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contextual Related Posts: from n/a through < 4.2.2. | |
| Aplazada | Media (5.3) | 0.29% | — | Ays-pro Advanced Related PostsAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Ays Pro Advanced Related Posts advanced-related-posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Related Posts: from n/a through <= 1.9.1. | |
| Aplazada | Media (4.3) | 0.15% | — | Marynixie Related Posts ThumbnailsAI | 23/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in marynixie Related Posts Thumbnails Plugin for WordPress related-posts-thumbnails allows Cross Site Request Forgery.This issue affects Related Posts Thumbnails Plugin for WordPress: from n/a through <= 4.3.2. | |
| Aplazada | Media (6.4) | 0.26% | — | Related Posts BY TaxonomyAI | 16/1/2026 | 17/6/2026 | The Related Posts by Taxonomy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'related_posts_by_tax' shortcode in all versions up to, and including, 2.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (7.5) | 0.29% | — | Brechtvds Custom Related PostsAI | 5/1/2026 | 30/9/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Brecht Custom Related Posts custom-related-posts allows Retrieve Embedded Sensitive Data.This issue affects Custom Related Posts: from n/a through <= 1.8.0. | |
| Aplazada | Media (4.3) | 0.16% | — | ARK Related PostsAI | 5/12/2025 | 17/6/2026 | The ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to missing or incorrect nonce validation on the ark_rp_options_page function. This makes it possible for unauthenticated attackers to modify the plugin's configuration settings via a forged request… | |
| Aplazada | Media (4.4) | 0.30% | — | Related Posts LiteAI | 18/10/2025 | 17/6/2026 | The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Media (5.9) | 0.24% | — | Sharkthemes Smart Related ProductsAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sharkthemes Smart Related Products ai-related-products allows Stored XSS.This issue affects Smart Related Products: from n/a through <= 2.0.8. | |
| Aplazada | Media (4.3) | 0.13% | — | Related Posts LiteAI | 30/8/2025 | 17/6/2026 | The Related Posts Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify plugin settings via a forged… | |
| Aplazada | Media (6.5) | 0.25% | — | Alexvtn Internal Linking OF Related ContentsAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in alexvtn Internal Linking of Related Contents internal-linking-of-related-contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Internal Linking of Related Contents: from n/a through <= 1.1.8. | |
| Aplazada | Media (5.4) | 0.18% | — | Wikimedia Mediawiki Related Articles ExtensionAI | 7/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RelatedArticles Extension allows Stored XSS.This issue affects Mediawiki - RelatedArticles Extension: from 1.43.X before 1.43.2. | |
| Aplazada | Media (6.5) | 0.23% | — | Prowcplugins Related Products Manager FOR WoocommerceAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ProWCPlugins Related Products Manager for WooCommerce related-products-manager-woocommerce allows DOM-Based XSS.This issue affects Related Products Manager for WooCommerce: from n/a through <= 1.6.2. | |
| Aplazada | Media (6.5) | 0.25% | — | Phpaddicted Igit-related-posts-with-thumb-images-after-postsAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpaddicted IGIT Related Posts With Thumb Image After Posts igit-related-posts-with-thumb-images-after-posts allows Stored XSS.This issue affects IGIT Related Posts With Thumb Image After Posts: from n/a through <=… | |
| Aplazada | Media (6.5) | 0.29% | — | Data443 Inline Related PostsAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Mitigation, Inc. Inline Related Posts intelly-related-posts allows Stored XSS.This issue affects Inline Related Posts: from n/a through <= 3.8.0. | |
| Aplazada | Alta (7.1) | 0.15% | — | ELI Related Posts Footer Links AND WidgetAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Eli ELI's Related Posts Footer Links and Widget spostarbust allows Stored XSS.This issue affects ELI's Related Posts Footer Links and Widget: from n/a through <= 1.2.04.20. | |
| Aplazada | Media (6.5) | 0.29% | — | Ajay Contextual Related PostsAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Contextual Related Posts contextual-related-posts allows DOM-Based XSS.This issue affects Contextual Related Posts: from n/a through <= 4.0.2. | |
| Aplazada | Alta (7.1) | 0.14% | — | Alphasis Related Posts VIA TaxonomiesAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in alphasis Related Posts via Taxonomies related-posts-via-taxonomies allows Stored XSS.This issue affects Related Posts via Taxonomies: from n/a through <= 1.0.1. | |
| Modificada | Media (5.4) | 0.22% | — | Brechtvds Custom Related Posts | 22/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brecht Custom Related Posts custom-related-posts allows Stored XSS.This issue affects Custom Related Posts: from n/a through <= 1.7.4. |