Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
–

328 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaSin puntuar——Wpshopmart Tabs ResponsiveAI2/10/20262/10/2026
The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page.
AplazadaAlta (7.2)0.54%—Responsive Slider GalleryAI30/9/202630/9/2026
Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions.
Pendiente de análisisCrítica (9.1)0.23%—Drupal Photoswipe - Responsive Javascript Modal Image GalleryAI25/8/202628/8/2026
Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.
AplazadaMedia (5.5)0.50%—ResponsivefilemanagerAI4/8/202612/8/2026
A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for…
AplazadaMedia (6.1)0.36%—WP Responsive Thumbnail SliderAI1/8/202612/8/2026
The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management() function, which echoes $_GET['id']…
AplazadaCrítica (9.8)3.0%—Advanced Responsive Video EmbedderAI29/7/202630/7/2026
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs…
AplazadaMedia (5.3)0.32%—Wpsupportplus WP Support Plus Responsive Ticket SystemAI9/7/20269/7/2026
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and close that person's support tickets.
AplazadaAlta (8.6)0.45%—Wpsupportplus WP Support Plus Responsive Ticket SystemAI30/6/202630/6/2026
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys before using them in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.
AplazadaAlta (8.8)0.51%—Wpsupportplus Responsive Ticket SystemAI30/6/202630/6/2026
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, allowing unauthenticated users to upload files containing malicious JavaScript (such as HTML or SVG) to a publicly accessible location, leading to Stored Cross-Site Scripting attacks against site…
AplazadaAlta (7.1)0.25%—Dfactory Responsive LightboxAI26/6/202629/6/2026
Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.
AnalizadaAlta (8.8)0.49%—Extro Responsive Portfolio19/6/202619/8/2026
Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_pofos&view=pofo&id=[SQL] to extract…
AplazadaCrítica (9.1)0.82%—Metaslider Responsive SliderAI15/6/202617/6/2026
Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.
AplazadaCrítica (9.3)0.71%—Responsivefilemanager Responsive FilemanagerAI15/6/202617/6/2026
Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution. This project is unmaintained at the time of CVE assignment. The vulnerability was found in the latest release 9.14.0
AplazadaMedia (5.3)0.24%—Essentialplugin WP Logo Showcase Responsive Slider AND CarouselAI11/6/202623/7/2026
Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider and Carousel allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Logo Showcase Responsive Slider and Carousel: from n/a through 3.6.
AplazadaAlta (8)0.61%—Responsivefilemanager Responsive File ManagerAI28/5/202617/6/2026
An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component
AplazadaMedia (6.4)0.32%—Responsive Video EmbedderAI27/5/202617/6/2026
The Responsive Video Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rem_video' shortcode in versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping on user supplied attributes (notably 'id' and 'list') in the video_shortcode()…
AplazadaMedia (6.4)0.33%—Responsive CheckAI27/5/202617/6/2026
The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in versions up to, and including, 0.0.3. This is due to insufficient input sanitization and output escaping on the 'url' (and 'button') shortcode attributes in the rspc_check_shortcode() function, which…
AplazadaAlta (7.1)0.28%—Joomla Responsive PortfolioAI25/5/202624/7/2026
Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers can inject malicious SQL code via the filter_type_id, filter_pid_id, and filter_search parameters in POST requests to extract…
AplazadaMedia (6.1)0.22%—WP Responsive Popup OptinAI22/4/202617/6/2026
The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due to the settings form on the admin page (wpo_admin_page.php) lacking nonce generation (wp_nonce_field) and verification (wp_verify_nonce/check_admin_referer). This makes…
AplazadaAlta (7.2)0.54%—Metaslider Responsive SliderAI21/4/202617/6/2026
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through 3.106.0.
AplazadaMedia (4.3)0.37%—Cyberchimps Responsive BlocksAI21/4/202617/6/2026
The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.2.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.44%—Cyberchimps Responsive BlocksAI21/4/202617/6/2026
The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Email Relay in all versions up to, and including, 2.2.0. This is due to insufficient authorization checks and missing server-side validation of the recipient email address supplied via a public REST…
AplazadaMedia (6.5)0.32%—Responsive PlusAI26/3/202617/6/2026
The Responsive Plus WordPress plugin before 3.4.3 is vulnerable to arbitrary shortcode execution due to the software allowing unauthenticated users to execute the update_responsive_woo_free_shipping_left_shortcode AJAX action that does not properly validate the content_rech_data parameter before processing it as a…
AnalizadaMedia (4.8)0.24%—Pixelite Responsive Favicons25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Responsive Favicons allows Cross-Site Scripting (XSS).This issue affects Responsive Favicons: from 0.0.0 before 2.0.2.
AplazadaMedia (5.3)0.29%—Cyberchimps Responsive BlocksAI13/3/202617/6/2026
Missing Authorization vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Responsive Blocks: from n/a through <= 2.2.0.