Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.32%—Sharedfilespro Shared Files PROAI28/8/202628/8/2026
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.
AplazadaMedia (5.3)0.22%—Shared FilesAIShared Files PROAI28/8/202628/8/2026
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and protected only by a nonce that is output on public pages, so an unauthenticated visitor can upload files to…
AplazadaMedia (6.8)0.33%—Shared FilesAIShared Files PROAI28/8/202628/8/2026
The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that points outside the uploads directory.…
AplazadaMedia (6.4)0.23%—Shared FilesAI24/8/202624/8/2026
Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.
AplazadaAlta (7.5)0.50%—Shared FilesAI15/6/202617/6/2026
Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
AplazadaMedia (6.8)0.43%—Shared FilesAI26/3/202617/6/2026
The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector
AplazadaMedia (5.3)0.27%—Anssi Laitila Shared FilesAI20/2/202617/6/2026
Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.19.
AplazadaAlta (7.2)0.36%—Shared FilesAI3/6/202517/6/2026
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads in all versions up to, and including, 1.7.48 due to insufficient input sanitization and output escaping within the sanitize_file() function. This makes it possible…
AplazadaAlta (7.2)0.39%—Anambis Shared FilesAI31/1/202517/6/2026
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
ModificadaAlta (7.5)0.37%—Sharedfilespro Shared Files26/8/202417/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.28.
AplazadaMedia (5.3)0.39%—Anssi Laitila Shared FilesAI23/4/202417/6/2026
Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.16.
ModificadaMedia (6.1)0.42%—Tammersoft Shared Files16/10/202317/6/2026
The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.
ModificadaMedia (4.8)0.67%—Tammersoft Shared Files17/11/202117/6/2026
The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (4.8)0.64%—Tammersoft Shared Files18/10/202117/6/2026
The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.