Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
328 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | — | — | Wpshopmart Tabs ResponsiveAI | 2/10/2026 | 2/10/2026 | The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page. | |
| Aplazada | Alta (7.2) | 0.54% | — | Responsive Slider GalleryAI | 30/9/2026 | 30/9/2026 | Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions. | |
| Pendiente de análisis | Crítica (9.1) | 0.23% | — | Drupal Photoswipe - Responsive Javascript Modal Image GalleryAI | 25/8/2026 | 28/8/2026 | Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0. | |
| Aplazada | Media (5.5) | 0.50% | — | ResponsivefilemanagerAI | 4/8/2026 | 12/8/2026 | A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (6.1) | 0.36% | — | WP Responsive Thumbnail SliderAI | 1/8/2026 | 12/8/2026 | The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management() function, which echoes $_GET['id']… | |
| Aplazada | Crítica (9.8) | 3.0% | — | Advanced Responsive Video EmbedderAI | 29/7/2026 | 30/7/2026 | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs… | |
| Aplazada | Media (5.3) | 0.32% | — | Wpsupportplus WP Support Plus Responsive Ticket SystemAI | 9/7/2026 | 9/7/2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and close that person's support tickets. | |
| Aplazada | Alta (8.6) | 0.45% | — | Wpsupportplus WP Support Plus Responsive Ticket SystemAI | 30/6/2026 | 30/6/2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys before using them in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. | |
| Aplazada | Alta (8.8) | 0.51% | — | Wpsupportplus Responsive Ticket SystemAI | 30/6/2026 | 30/6/2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, allowing unauthenticated users to upload files containing malicious JavaScript (such as HTML or SVG) to a publicly accessible location, leading to Stored Cross-Site Scripting attacks against site… | |
| Aplazada | Alta (7.1) | 0.25% | — | Dfactory Responsive LightboxAI | 26/6/2026 | 29/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions. | |
| Analizada | Alta (8.8) | 0.49% | — | Extro Responsive Portfolio | 19/6/2026 | 19/8/2026 | Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_pofos&view=pofo&id=[SQL] to extract… | |
| Aplazada | Crítica (9.1) | 0.82% | — | Metaslider Responsive SliderAI | 15/6/2026 | 17/6/2026 | Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions. | |
| Aplazada | Crítica (9.3) | 0.71% | — | Responsivefilemanager Responsive FilemanagerAI | 15/6/2026 | 17/6/2026 | Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution. This project is unmaintained at the time of CVE assignment. The vulnerability was found in the latest release 9.14.0 | |
| Aplazada | Media (5.3) | 0.24% | — | Essentialplugin WP Logo Showcase Responsive Slider AND CarouselAI | 11/6/2026 | 23/7/2026 | Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider and Carousel allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Logo Showcase Responsive Slider and Carousel: from n/a through 3.6. | |
| Aplazada | Alta (8) | 0.61% | — | Responsivefilemanager Responsive File ManagerAI | 28/5/2026 | 17/6/2026 | An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component | |
| Aplazada | Media (6.4) | 0.32% | — | Responsive Video EmbedderAI | 27/5/2026 | 17/6/2026 | The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shortcode in versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping on user supplied attributes (notably 'id' and 'list') in the video_shortcode()… | |
| Aplazada | Media (6.4) | 0.33% | — | Responsive CheckAI | 27/5/2026 | 17/6/2026 | The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in versions up to, and including, 0.0.3. This is due to insufficient input sanitization and output escaping on the 'url' (and 'button') shortcode attributes in the rspc_check_shortcode() function, which… | |
| Aplazada | Alta (7.1) | 0.28% | — | Joomla Responsive PortfolioAI | 25/5/2026 | 24/7/2026 | Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers can inject malicious SQL code via the filter_type_id, filter_pid_id, and filter_search parameters in POST requests to extract… | |
| Aplazada | Media (6.1) | 0.22% | — | WP Responsive Popup OptinAI | 22/4/2026 | 17/6/2026 | The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due to the settings form on the admin page (wpo_admin_page.php) lacking nonce generation (wp_nonce_field) and verification (wp_verify_nonce/check_admin_referer). This makes… | |
| Aplazada | Alta (7.2) | 0.54% | — | Metaslider Responsive SliderAI | 21/4/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through 3.106.0. | |
| Aplazada | Media (4.3) | 0.37% | — | Cyberchimps Responsive BlocksAI | 21/4/2026 | 17/6/2026 | The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.44% | — | Cyberchimps Responsive BlocksAI | 21/4/2026 | 17/6/2026 | The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Email Relay in all versions up to, and including, 2.2.0. This is due to insufficient authorization checks and missing server-side validation of the recipient email address supplied via a public REST… | |
| Aplazada | Media (6.5) | 0.32% | — | Responsive PlusAI | 26/3/2026 | 17/6/2026 | The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software allowing unauthenticated users to execute the update_responsive_woo_free_shipping_left_shortcode AJAX action that does not properly validate the content_rech_data parameter before processing it as a… | |
| Analizada | Media (4.8) | 0.24% | — | Pixelite Responsive Favicons | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Responsive Favicons allows Cross-Site Scripting (XSS).This issue affects Responsive Favicons: from 0.0.0 before 2.0.2. | |
| Aplazada | Media (5.3) | 0.29% | — | Cyberchimps Responsive BlocksAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Blocks: from n/a through <= 2.2.0. |