Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 212 respecto a la semana anterior
Críticas / altas1386▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.27% | — | Smashballoon Social Post FeedAI | 2/10/2026 | 3/10/2026 | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message via v-html in Admin Builder Preview in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Media (6.4) | 0.41% | — | Smashballoon Custom Twitter FeedsAI | 18/9/2026 | 18/9/2026 | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.33% | — | Smashballoon Social Post FeedAI | 16/8/2026 | 20/8/2026 | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id' Shortcode Attribute in all versions up to, and including, 4.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (4.7) | 0.39% | — | Smashballoon Social Photo FeedAI | 5/8/2026 | 12/8/2026 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query String in all versions up to, and including, 6.11.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (4.8) | 0.13% | — | Smashballoon Reviews FeedAI | 20/7/2026 | 21/7/2026 | The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the feed by planting a shortcode in a review on the… | |
| Aplazada | Media (4.7) | 0.15% | — | Smashballoon Social Photo FeedAI | 8/7/2026 | 8/7/2026 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.11.1. This is due to missing or incorrect nonce validation on the maybe_connection_data function. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (5.4) | 0.32% | — | Smashballoon Feeds FOR YoutubeAI | 18/5/2026 | 17/6/2026 | The Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4 is vulnerable to unauthorized modification of the Feeds for YouTube (YouTube video, channel, and gallery plugin) WordPress plugin before 2.6.4's license key due to a missing capability check on the 'actions' function. This… | |
| Aplazada | Alta (7.2) | 0.51% | — | Smashballoon Custom Twitter FeedsAI | 13/5/2026 | 17/6/2026 | The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elements::get_post_text() function when rendering cached tweet text. The plugin's ctf_get_more_posts AJAX action is available… | |
| Aplazada | Media (6.5) | 0.22% | — | Desertthemes NewsmashAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in desertthemes NewsMash newsmash allows Stored XSS.This issue affects NewsMash: from n/a through <= 1.0.71. | |
| Modificada | Alta (8.1) | 0.50% | — | Axiomthemes Smash | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Smash smash allows PHP Local File Inclusion.This issue affects Smash: from n/a through <= 1.7. | |
| Aplazada | Media (5.4) | 0.27% | — | Ipmi Smash CLPAI | 18/11/2025 | 17/6/2026 | Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a stack buffer overflow via a crafted SMASH command, overwrite the return address and registers, and achieve arbitrary code execution on the BMC firmware operating system | |
| Aplazada | Media (5.4) | 0.23% | — | Supermicro BMCAIInsyde SmashAI | 13/11/2025 | 17/6/2026 | Supermicro BMC Insyde SMASH shell program has a stacked-based overflow vulnerability | |
| Aplazada | Media (4.3) | 0.24% | — | Smashballoon Social Post FeedAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi Smash Balloon Social Post Feed custom-facebook-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smash Balloon Social Post Feed: from n/a through <= 4.3.2. | |
| Analizada | Media (5.4) | 0.32% | — | Wpbeginner Smash Balloon Social Post Feed | 10/6/2025 | 17/6/2026 | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-color attribute in all versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.4) | 0.22% | — | Smashballoon Social Photo FeedAI | 29/5/2025 | 17/6/2026 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-plugin` attribute in all versions up to, and including, 6.9.0 (Free) and 6.8.0 (Pro) due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.20% | — | Smashballoon Custom Twitter FeedsAI | 20/3/2025 | 17/6/2026 | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5. This is due to missing or incorrect nonce validation on the ctf_clear_cache_admin() function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.1) | 0.39% | — | Tehsmash Ultimate EventsAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tehsmash Ultimate Events ultimate-events allows Reflected XSS.This issue affects Ultimate Events: from n/a through <= 1.3.3. | |
| Aplazada | Media (4.3) | 0.18% | — | Desertthemes NewsmashAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in desertthemes NewsMash newsmash allows Cross Site Request Forgery.This issue affects NewsMash: from n/a through <= 1.0.34. | |
| Aplazada | Media (6.4) | 0.27% | — | NewsmashAI | 6/12/2024 | 17/6/2026 | The NewsMash theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 1.0.71 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Modificada | Alta (8.8) | 0.19% | — | Smashballoon Custom Twitter Feeds | 31/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds allows Cross Site Request Forgery.This issue affects Custom Twitter Feeds (Tweets Widget): from n/a through <= 2.2.3. | |
| Analizada | Media (4.8) | 0.43% | — | Smashballoon Custom Twitter Feeds | 8/10/2024 | 17/6/2026 | Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (4.3) | 0.23% | — | Smashballoon Reviews Feed | 27/8/2024 | 17/6/2026 | The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'update_api_key' function. This makes it… | |
| Analizada | Media (4.3) | 0.40% | — | Smashballoon Reviews Feed | 27/8/2024 | 17/6/2026 | The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_api_key' function in all versions up to, and including, 1.1.2. This makes it possible for… | |
| Modificada | Media (5.4) | 0.42% | — | Smashballoon Feeds FOR Youtube | 11/7/2024 | 17/6/2026 | The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'youtube-feed' shortcode in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Aplazada | Media (4.3) | 0.20% | — | Smashballoon Social Post FeedAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Smash Balloon Social Post Feed.This issue affects Smash Balloon Social Post Feed: from n/a through 4.2.1. |