Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.23% | — | Clogica SEO RedirectionAI | 6/8/2026 | 26/8/2026 | The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs. | |
| Aplazada | Alta (7.1) | 0.25% | — | Clogica SEO RedirectionAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Clogica SEO Redirection | 18/11/2022 | 17/6/2026 | Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress. | |
| Modificada | Media (4.3) | 0.31% | — | Clogica SEO Redirection | 23/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SEO Redirection plugin <= 8.9 at WordPress, leading to deletion of 404 errors and redirection history. | |
| Modificada | Alta (8.8) | 1.4% | — | Wp-buy SEO Redirection-301 Redirect Manager | 17/11/2021 | 17/6/2026 | The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the redirection plugin is also installed | |
| Modificada | Media (4.8) | 0.62% | — | Clogica SEO Redirection Plugin | 17/5/2021 | 17/6/2026 | The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Redirect To fields when creating a new redirect in the dashboard, allowing high privilege users (even with the unfiltered_html disabled) to set XSS payloads | |
| Modificada | Media (6.1) | 0.83% | — | Clogica SEO Redirection Plugin | 17/5/2021 | 17/6/2026 | The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflected Cross-Site Scripting (XSS) issue as user input is not properly sanitised or escaped before being output in an attribute. | |
| Modificada | Media (5.4) | 0.63% | — | Clogica SEO Redirection | 5/4/2021 | 17/6/2026 | The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to reflected Cross-Site Scripting (XSS) as user input is not properly sanitised before being output in an attribute. | |
| Modificada | Media (6.1) | 0.91% | — | Clogica SEO Redirection | 21/8/2019 | 17/6/2026 | The seo-redirection plugin before 4.3 for WordPress has stored XSS. |