Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.40% | — | Sharethis Simple Share Buttons Adder | 18/6/2024 | 17/6/2026 | The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (4.8) | 0.49% | — | Simplesharebuttons Simple Share Buttons Adder | 29/2/2024 | 17/6/2026 | The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and… | |
| Modificada | Alta (8.8) | 0.27% | — | Simplesharebuttons Simple Share Buttons Adder | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Simple Share Buttons Simple Share Buttons Adder plugin <= 8.4.7 versions. | |
| Modificada | Media (6.1) | 0.96% | — | Simplesharebuttons Simple Share Buttons Adder | 12/8/2019 | 17/6/2026 | The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS. | |
| Modificada | Media (6.8) | 2.8% | — | Sharethis Simple Share Buttons Adder | 3/7/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) ssba_share_text parameter in a save action to… |