Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.14% | — | Fetchdesigns Sign-up SheetsAI | 20/9/2026 | 21/9/2026 | The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Fetchdesigns Sign-up SheetsAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Object Injection.This issue affects Sign-up Sheets: from n/a through <= 2.3.2. | |
| Aplazada | Media (4.3) | 0.13% | — | Fetchdesigns Sign-up SheetsAI | 20/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Cross Site Request Forgery.This issue affects Sign-up Sheets: from n/a through <= 2.3.3. | |
| Aplazada | Media (6.5) | 0.32% | — | Fetchdesigns Sign-up SheetsAI | 15/4/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Code Injection.This issue affects Sign-up Sheets: from n/a through <= 2.3.0.1. | |
| Aplazada | Media (5.3) | 0.36% | — | Fetchdesigns Sign-up SheetsAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.12. | |
| Analizada | Media (6.1) | 0.39% | — | Fetchdesigns Sign-up Sheets | 4/9/2024 | 17/6/2026 | The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to Reflected Cross-Site Scripting. | |
| Aplazada | Media (4.3) | 0.20% | — | Fetchdesigns Sign-up SheetsAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.11.1. | |
| Modificada | Alta (8.8) | 0.25% | — | Fetchdesigns Sign-up Sheets | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets plugin <= 2.2.8 versions. | |
| Modificada | Alta (8) | 1.3% | — | Fetchdesigns Sign-up Sheets | 12/7/2021 | 17/6/2026 | The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the CSV to export, which could lead to a CSV injection issue | |
| Modificada | Media (4.8) | 0.62% | — | Fetchdesigns Sign-up Sheets | 12/7/2021 | 17/6/2026 | The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new sheet, allowing high privilege users to add JavaScript in them, leading to a Stored Cross-Site Scripting issue. The payloads will be triggered when viewing the 'All Sheets' page in the admin dashboard |