Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.2) | 0.19% | — | Rtcamp RtmediaAI | 13/9/2026 | 14/9/2026 | The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's… | |
| Aplazada | Alta (7.5) | 0.34% | — | Rtcamp RtmediaAI | 12/9/2026 | 15/9/2026 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Rtcamp RtmediaAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Rtcamp RtmediaAI | 27/7/2026 | 27/7/2026 | Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Rtcamp RtmediaAI | 27/7/2026 | 27/7/2026 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions. | |
| Aplazada | Media (6.5) | 0.38% | — | Rtcamp RtmediaAI | 10/7/2026 | 10/7/2026 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the order_by parameter in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Aplazada | Media (6.5) | 0.30% | — | Rtcamp RtmediaAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions. | |
| Aplazada | Alta (8.8) | 0.27% | — | Netartmedia Vlog SystemAI | 24/3/2026 | 17/6/2026 | Netartmedia Vlog System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with malicious email values in the forgotten_password module to extract sensitive… | |
| Analizada | Alta (8.8) | 0.46% | — | Netartmedia Real Estate Portal | 12/3/2026 | 17/6/2026 | Netartmedia Real Estate Portal 5.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can submit POST requests to index.php with malicious SQL payloads in the page field to bypass authentication,… | |
| Analizada | Alta (8.8) | 0.46% | — | Netartmedia Real Estate Portal | 12/3/2026 | 17/6/2026 | Netartmedia Real Estate Portal 5.0 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user_email parameter. Attackers can send POST requests to index.php with malicious payloads in the user_email field to bypass authentication,… | |
| Analizada | Alta (8.8) | 0.37% | — | Netartmedia PHP Mall | 12/3/2026 | 17/6/2026 | Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through unvalidated parameters. Attackers can inject time-based blind SQL payloads via the 'id' parameter in index.php or the 'Email' parameter in loginaction.php to extract… | |
| Analizada | Alta (8.8) | 0.36% | — | Netartmedia PHP Mall | 12/3/2026 | 17/6/2026 | Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through various parameters. Attackers can craft malicious requests with SQL payloads to extract sensitive database information including user credentials… | |
| Aplazada | Alta (8.8) | 0.25% | — | Netartmedia Event PortalAI | 12/3/2026 | 17/6/2026 | Netartmedia Event Portal 2.0 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with malicious SQL payloads in the Email field to extract… | |
| Analizada | Alta (8.8) | 0.32% | — | Netartmedia Real Estate Portal | 12/3/2026 | 17/6/2026 | Netartmedia PHP Real Estate Agency 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can send POST requests to index.php with crafted SQL payloads in the features[] parameter to… | |
| Aplazada | Alta (8.8) | 0.25% | — | Netartmedia PHP Dating SiteAI | 12/3/2026 | 17/6/2026 | Netartmedia PHP Dating Site contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with time-based SQL injection payloads in the Email field to extract sensitive… | |
| Aplazada | Alta (8.8) | 0.25% | — | Netartmedia PHP CAR DealerAI | 12/3/2026 | 17/6/2026 | Netartmedia PHP Car Dealer contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can submit POST requests to index.php with crafted SQL payloads in the features[] parameter to extract… | |
| Aplazada | Alta (8.8) | 0.30% | — | Netartmedia PHP Business DirectoryAI | 12/3/2026 | 17/6/2026 | Netartmedia PHP Business Directory 4.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to the loginaction.php endpoint with crafted SQL payloads in the Email field to extract… | |
| Aplazada | Alta (8.8) | 0.32% | — | Netartmedia Jobs PortalAI | 12/3/2026 | 17/6/2026 | Netartmedia Jobs Portal 6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with crafted SQL payloads in the Email field to extract sensitive database… | |
| Aplazada | Alta (8.8) | 0.30% | — | Netartmedia Deals PortalAI | 12/3/2026 | 17/6/2026 | Netartmedia Deals Portal contains an SQL injection vulnerability in the Email parameter of loginaction.php that allows unauthenticated attackers to manipulate database queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive information or bypass authentication mechanisms. | |
| Aplazada | Media (5.3) | 0.33% | — | Rtcamp Rtmedia FOR Wordpress Buddypress AND BbpressAI | 19/2/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Retrieve Embedded Sensitive Data.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through <= 4.7.8. | |
| Aplazada | Baja (3.7) | 0.32% | — | Rtcamp RtmediaAI | 13/12/2025 | 17/6/2026 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to to Information Disclosure due to missing authorization in the handle_rest_pre_dispatch() function when the Godam plugin is active, in versions 4.7.0 to 4.7.3. This makes it possible for unauthenticated attackers to retrieve media… | |
| Aplazada | Media (4.3) | 0.56% | — | Rtcamp RtmediaAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.6.14. | |
| Aplazada | Alta (8.8) | 1.4% | — | Rtcamp RtmediaAI | 23/4/2024 | 17/6/2026 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtmedia_gallery shortcode in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Modificada | Alta (7.2) | 1.3% | — | Rtcamp Rtmedia | 26/12/2023 | 17/6/2026 | The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file in an unsafe manner, leading to remote code execution by privileged users. | |
| Modificada | Alta (8.8) | 0.82% | — | Rtcamp Rtmedia | 26/12/2023 | 17/6/2026 | The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server |