Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.24%—Restaurant Menu AND Food OrderingAI25/9/202625/9/2026
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (5.3)0.16%—Restaurant Menu AND Food OrderingAI4/9/20268/9/2026
The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers to forge a payment notification and mark their own order as paid and completed without making any payment.
AplazadaAlta (8.1)0.47%—Motopress Restaurant MenuAI18/8/202620/8/2026
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
AplazadaAlta (8.5)0.36%—Motopress Restaurant MenuAI26/6/202626/6/2026
Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.
AplazadaAlta (7.5)0.35%—Fivestarplugins Five Star Restaurant MenuAI26/6/202629/6/2026
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
AplazadaMedia (4.3)0.25%—Motopress Restaurant MenuAI26/6/20265/10/2026
Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.
AplazadaMedia (6.5)0.34%—Motopress Mp-restaurant-menuAI18/12/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Retrieve Embedded Sensitive Data.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.7.
AnalizadaBaja (2.1)0.35%—Phpjabbers Restaurant Menu Maker23/9/202517/6/2026
A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of the argument theme causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and…
AplazadaMedia (5.9)0.22%—Will.i.am Simple Restaurant MenuAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Will.I.am Simple Restaurant Menu simple-restaurant-menu allows Stored XSS.This issue affects Simple Restaurant Menu: from n/a through <= 1.2.
AplazadaMedia (6.5)0.21%—Best Restaurant Menu BY PricelistoAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PriceListo Best Restaurant Menu by PriceListo best-restaurant-menu-by-pricelisto allows Stored XSS.This issue affects Best Restaurant Menu by PriceListo: from n/a through <= 1.4.3.
AplazadaMedia (4.3)0.16%—Easy Restaurant Menu ManagerAI13/8/202517/6/2026
The Easy restaurant menu manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the nsc_eprm_save_menu() function. This makes it possible for unauthenticated attackers to upload a menu file via a…
AplazadaMedia (5.4)0.14%—Motopress Mp-restaurant-menuAI16/7/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Cross Site Request Forgery.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.6.
AplazadaMedia (6.4)0.26%—Easy Restaurant Menu ManagerAI4/7/202517/6/2026
The Easy restaurant menu manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's nsc_eprm_menu_link shortcode in versions up to, and including 2.0.1, due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (8.1)1.1%—Exthemes WP Food Ordering AND Restaurant MenuAI11/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Exthemes WP Food ordering and Restaurant Menu wp-food allows PHP Local File Inclusion.This issue affects WP Food ordering and Restaurant Menu: from n/a through <= 2.7.
AplazadaAlta (8.8)0.75%—Motopress Mp-restaurant-menuAIPHPAI27/3/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows PHP Local File Inclusion.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.4.
AplazadaMedia (4.3)0.35%—Best Restaurant Menu BY PricelistoAI31/12/202417/6/2026
Missing Authorization vulnerability in PriceListo Best Restaurant Menu by PriceListo best-restaurant-menu-by-pricelisto.This issue affects Best Restaurant Menu by PriceListo: from n/a through <= 1.4.2.
AnalizadaMedia (6.1)0.32%—Oracle Restaurant Menu - Food Ordering System - Table Reservation20/11/202417/6/2026
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
AplazadaMedia (6.5)0.39%—Marco Piarulli MY Restaurant MenuAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Piarulli My Restaurant Menu my-restaurant-menu allows Stored XSS.This issue affects My Restaurant Menu: from n/a through <= 0.2.0.
AplazadaMedia (6.5)0.39%—Shahjahan Jewel Trendy Restaurant MenuAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjahan Jewel Trendy Restaurant Menu trendy-restaurant-menu allows DOM-Based XSS.This issue affects Trendy Restaurant Menu: from n/a through <= 1.0.0.
AnalizadaAlta (8.8)1.2%—Pricelisto Great Restaurant Menu WP29/8/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PriceListo Best Restaurant Menu by PriceListo allows SQL Injection.This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.4.1.
AplazadaMedia (6.4)0.27%—Restaurant Menu Food Ordering System Table ReservationAI15/6/202417/6/2026
The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
ModificadaMedia (4.3)0.36%—Fivestarplugins Five Star Restaurant Menu5/6/202417/6/2026
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_item', and 'add_menu_page' functions in all versions up to, and including, 2.4.16. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.5)0.32%—Gloriafood Restaurant Menu Food Ordering System Table ReservationAI18/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GloriaFood Restaurant Menu – Food Ordering System – Table Reservation allows Stored XSS.This issue affects Restaurant Menu – Food Ordering System – Table Reservation: from n/a through 2.4.1.
AplazadaMedia (6.5)0.32%—Fivestarplugins Five Star Restaurant MenuAI19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Menu allows Stored XSS.This issue affects Five Star Restaurant Menu: from n/a through 2.4.14.
ModificadaMedia (5.4)0.31%—Fivestarplugins Five Star Restaurant Menu5/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue affects Five Star Restaurant Reviews: from n/a through 2.3.5.