Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.23%—Clogica SEO RedirectionAI6/8/202626/8/2026
The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs.
AplazadaAlta (7.1)0.25%—Clogica SEO RedirectionAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.
ModificadaAlta (8.8)0.31%—Clogica SEO Redirection18/11/202217/6/2026
Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress.
ModificadaMedia (4.3)0.31%—Clogica SEO Redirection23/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 404 errors and redirection history.
ModificadaAlta (8.8)1.4%—Wp-buy SEO Redirection-301 Redirect Manager17/11/202117/6/2026
The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed
ModificadaMedia (4.8)0.62%—Clogica SEO Redirection Plugin17/5/202117/6/2026
The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads
ModificadaMedia (6.1)0.83%—Clogica SEO Redirection Plugin17/5/202117/6/2026
The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or escaped before being output in an attribute.
ModificadaMedia (5.4)0.63%—Clogica SEO Redirection5/4/202117/6/2026
The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute.
ModificadaMedia (6.1)0.91%—Clogica SEO Redirection21/8/201917/6/2026
The seo-redirection plugin before 4.3 for WordPress has stored XSS.