Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.32% | — | Sharedfilespro Shared Files PROAI | 28/8/2026 | 28/8/2026 | The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL. | |
| Aplazada | Media (5.3) | 0.22% | — | Shared FilesAIShared Files PROAI | 28/8/2026 | 28/8/2026 | The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and protected only by a nonce that is output on public pages, so an unauthenticated visitor can upload files to… | |
| Aplazada | Media (6.8) | 0.33% | — | Shared FilesAIShared Files PROAI | 28/8/2026 | 28/8/2026 | The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that points outside the uploads directory.… | |
| Aplazada | Media (6.4) | 0.23% | — | Shared FilesAI | 24/8/2026 | 24/8/2026 | Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions. | |
| Aplazada | Alta (7.5) | 0.50% | — | Shared FilesAI | 15/6/2026 | 17/6/2026 | Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions. | |
| Aplazada | Media (6.8) | 0.43% | — | Shared FilesAI | 26/3/2026 | 17/6/2026 | The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector | |
| Aplazada | Media (5.3) | 0.27% | — | Anssi Laitila Shared FilesAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.19. | |
| Aplazada | Alta (7.2) | 0.36% | — | Shared FilesAI | 3/6/2025 | 17/6/2026 | The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads in all versions up to, and including, 1.7.48 due to insufficient input sanitization and output escaping within the sanitize_file() function. This makes it possible… | |
| Aplazada | Alta (7.2) | 0.39% | — | Anambis Shared FilesAI | 31/1/2025 | 17/6/2026 | The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Modificada | Alta (7.5) | 0.37% | — | Sharedfilespro Shared Files | 26/8/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.28. | |
| Aplazada | Media (5.3) | 0.39% | — | Anssi Laitila Shared FilesAI | 23/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.16. | |
| Modificada | Media (6.1) | 0.42% | — | Tammersoft Shared Files | 16/10/2023 | 17/6/2026 | The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts. | |
| Modificada | Media (4.8) | 0.67% | — | Tammersoft Shared Files | 17/11/2021 | 17/6/2026 | The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.8) | 0.64% | — | Tammersoft Shared Files | 18/10/2021 | 17/6/2026 | The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues. |