Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.27% | — | Slim SEOAI | 11/9/2026 | 11/9/2026 | Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions. | |
| Aplazada | Baja (2.7) | 0.30% | — | Slim SEOAI | 9/8/2026 | 26/8/2026 | The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published posts they do not own, including… | |
| Aplazada | Media (4.3) | 0.42% | — | Slim SEOAI | 1/7/2026 | 1/7/2026 | The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Content Disclosure in all versions up to, and including, 4.9.8 via the `/wp-json/slim-seo/meta-tags/ai` REST API endpoint. This is due to the endpoint's `permission_callback` performing only a… | |
| Aplazada | Media (6.5) | 0.34% | — | Slim SEOAI | 25/6/2026 | 25/6/2026 | Contributor Broken Access Control in Slim SEO <= 4.6.2 versions. | |
| Aplazada | Alta (7.6) | 0.32% | — | Anhtransen Slim SEOAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Anh Tran Slim SEO slim-seo allows SQL Injection.This issue affects Slim SEO: from n/a through <= 4.5.4. | |
| Aplazada | Media (6.4) | 0.51% | — | Slim SEOAI | 21/5/2025 | 17/6/2026 | The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… |