Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.23% | — | Spiffy PluginAI | 28/8/2026 | 1/9/2026 | WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) can exploit this to redirect user to malicious site or control the account. | |
| Aplazada | Media (4.3) | 0.19% | — | Spiffyplugins Spiffy CalendarAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spiffy Calendar: from n/a through <= 5.0.7. | |
| Aplazada | Media (5.9) | 0.18% | — | Spiffyplugins WP Flow PlusAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus wp-imageflow2 allows Stored XSS.This issue affects WP Flow Plus: from n/a through <= 5.2.5. | |
| Modificada | Media (5.4) | 0.28% | — | Spiffyplugins WP Flow Plus | 24/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus wp-imageflow2 allows Stored XSS.This issue affects WP Flow Plus: from n/a through <= 5.2.3. | |
| Aplazada | Alta (7.6) | 0.42% | — | Spiffyplugins Spiffy CalendarAI | 17/9/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.12. | |
| Modificada | Media (6.1) | 0.31% | — | Spiffyplugins Spiffy Calendar | 15/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through <= 4.9.13. | |
| Modificada | Media (5.4) | 0.26% | — | Spiffyplugins Spiffy Calendar | 15/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Stored XSS.This issue affects Spiffy Calendar: from n/a through <= 4.9.13. | |
| Modificada | Alta (7.2) | 0.72% | — | Spiffyplugins Spiffy Calendar | 22/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.11. | |
| Modificada | Media (6.3) | 0.28% | — | Spiffyplugins Spiffy Calendar | 4/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10. | |
| Modificada | Media (5.4) | 0.25% | — | Spiffyplugins WP Flow Plus | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus allows Stored XSS.This issue affects WP Flow Plus: from n/a through 5.2.2. | |
| Modificada | Media (6.1) | 0.41% | — | Spiffyplugins Spiffy Calendar | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.7. | |
| Analizada | Media (5.3) | 0.48% | — | Spiffyplugins Spiffy Calendar | 27/2/2024 | 17/6/2026 | The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+. | |
| Modificada | Media (5.4) | 0.41% | — | Spiffyplugins Spiffy Calendar | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Stored XSS.This issue affects Spiffy Calendar: from n/a through 4.9.5. | |
| Modificada | Crítica (9.8) | 0.55% | — | Spiffyplugins Spiffy Calendar | 3/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.1. | |
| Modificada | Media (6.1) | 0.34% | — | Spiffyplugins Spiffy Calendar | 18/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spiffy Plugins Spiffy Calendar plugin <= 4.9.3 versions. | |
| Modificada | Media (5.4) | 0.70% | — | Spiffyplugins Spiffy Calendar | 20/5/2022 | 17/6/2026 | Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events. | |
| Modificada | Media (4.3) | 0.40% | — | Spiffyplugins Spiffy Calendar | 21/2/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0). | |
| Modificada | Alta (7.5) | 3.1% | — | Call-cc Spiffy | 7/6/2017 | 17/6/2026 | Directory traversal vulnerability in Spiffy before 5.4. | |
| Modificada | Media (6.1) | 1.3% | — | Sunnythemes Spiffy Calendar | 5/6/2017 | 17/6/2026 | Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter. | |
| Modificada | Media (5.1) | 1.2% | — | Spiffyjr Phpraid | 30/6/2006 | 16/6/2026 | SQL injection vulnerability in includes/functions_logging.php in phpRaid 3.0.5, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the log_hack function. | |
| Modificada | Media (5.1) | 17% | — | Spiffyjr Phpraid | 29/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) announcements.php and (2) rss.php, a different set of vectors and affected versions than CVE-2006-3316 and CVE-2006-3116. | |
| Modificada | Media (5.1) | 1.1% | — | Spiffyjr Phpraid | 29/6/2006 | 16/6/2026 | SQL injection vulnerability in view.php in phpRaid 3.0.4, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the raid_id parameter. | |
| Modificada | Media (5.1) | 7.3% | — | Spiffyjr Phpraid | 29/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in phpRaid 3.0.4 and 3.0.5 allow remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) configuration.php, (3) guilds.php, (4) index.php, (5) locations.php, (6) login.php, (7) lua_output.php, (8) permissions.php, (9) profile.php, (10)… | |
| Modificada | Media (5.1) | 1.2% | — | Spiffyjr Phpraid | 29/6/2006 | 16/6/2026 | SQL injection vulnerability in register.php for phpRaid 3.0.6 and possibly other versions, when the authorization type is phpraid, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) email parameters. | |
| Modificada | Media (5.1) | 3.3% | — | Spiffyjr Phpraid | 29/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in phpRaid 3.0.5 allow remote attackers to execute arbitrary code via a URL in the phpraid_dir parameter to (1) logs.php and (2) users.php, a different set of vectors than CVE-2006-3116. |