Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

720 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.14%—Slider PROAI6/10/20266/10/2026
The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to retrieve the title, excerpt and permalink of non-public posts, including drafts, pending, scheduled, private and trashed posts, as well as post revisions…
AplazadaMedia (6.5)0.16%—Ghozylab Image Slider WidgetAI5/10/20266/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Image Slider Widget image-slider-widget allows Stored XSS.This issue affects Image Slider Widget: from n/a through 1.1.130.
AplazadaAlta (7.2)0.37%—Responsive Slider GalleryAI30/9/202630/9/2026
Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions.
AplazadaMedia (6.4)0.16%—Nextendweb Smart Slider 3AI30/9/202630/9/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
AplazadaMedia (6.5)0.21%—WP Review Slider PRO Wp-review-slider-proAI26/9/202628/9/2026
The wp-review-slider-pro WordPress plugin before 12.7.12 does not sanitize a value stored through one of its AJAX handlers, which lacks a capability check, before using it in a SQL statement, allowing any authenticated user, such as a subscriber, to perform SQL injection attacks whose results are then returned to…
AplazadaAlta (8)0.23%—WP Review Slider PRO Wp-review-slider-proAI26/9/202628/9/2026
The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to overwrite a live form with field values that are…
AplazadaAlta (8)0.23%—WP Review Slider PRO Wp-review-slider-proAI26/9/202628/9/2026
The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public…
AplazadaAlta (7.2)0.43%—Ljapps WP Yelp Review SliderAI22/9/202622/9/2026
The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up to, and including, 9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaBaja (2.1)0.47%—06ketan SlideshotAI20/9/202621/9/2026
A flaw has been found in 06ketan slideshot up to 4.4.0. This impacts the function render_slides of the file packages/cli/src/renderer.ts. This manipulation of the argument htmlPath causes path traversal. The attack is possible to be carried out remotely. The exploit has been published and may be used. The project was…
AplazadaBaja (3.1)0.21%—Photo Gallery Sliders Proofing AND WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site.
AplazadaMedia (4.2)0.19%—Photo Gallery Sliders Proofing AND WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging…
AplazadaBaja (2.7)0.30%—Photo Gallery Sliders Proofing ANDAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Contributor role and above to read the stored metadata of any image on the site, including images in galleries belonging to…
AplazadaBaja (3.1)0.21%—Photo Gallery Sliders Proofing AND WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including…
AplazadaAlta (7.2)0.50%—Photo Gallery Sliders Proofing WordpressAI20/9/202621/9/2026
The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator…
AplazadaMedia (6.8)0.24%—Masterstickies Master SliderAI20/9/202621/9/2026
The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outputting them in an inline script context, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when the affected post is viewed.…
Pendiente de análisisMedia (5.3)0.53%—OpenslideAILibtiffAI17/9/202623/9/2026
OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes the indirect TIFF tile path in src/openslide-decode-tiff.c and _openslide_tiff_read_tile() to request a full-height destination for a partial bottom tile row, allowing uninitialized heap memory to…
Pendiente de análisisAlta (7.7)0.48%—OpenslideAI17/9/202623/9/2026
OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositive row or column tile counts from a crafted Ventana BIF file. The invalid counts produce attacker-controlled relative memory offsets and…
AplazadaMedia (6.8)0.29%—Codeinwp Ultimate Before After Image Slider AND GalleryAI2/9/20263/9/2026
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including…
AplazadaMedia (6.8)0.29%—Ultimate Before After Image Slider GalleryAI2/9/20263/9/2026
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an…
AplazadaMedia (6.4)0.32%—Nextendweb Smart Slider 3AI28/8/202628/8/2026
The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
AplazadaAlta (8.8)0.51%—Slider Hero With Video Background AnimationAI22/8/202626/8/2026
The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an…
AplazadaMedia (6.8)0.43%—Post Grid Slider Carousel UltimateAI22/8/202626/8/2026
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any…
AplazadaAlta (7.5)0.32%—Depicter SliderAI18/8/202620/8/2026
Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.
AplazadaAlta (7.4)0.17%—10web SliderAI18/8/20266/10/2026
Cross-Site Request Forgery (CSRF) vulnerability in 10Web Slider by 10Web slider-wd allows Cross Site Request Forgery.This issue affects Slider by 10Web: from n/a through 1.2.63.
AplazadaMedia (4.9)0.48%—Quantumcloud Slider HeroAI16/8/202620/8/2026
The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via the qcld_sliderhero_duplicate() function. Slide data (description, title, btn, btn2, image_link, custom, etc.) is stored safely via $wpdb->update() with %s placeholders in the qchero_save_image…