Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.43% | — | Sportspress PROAI | 2/7/2026 | 2/7/2026 | Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions. | |
| Aplazada | Alta (8.8) | 0.84% | — | Themeboy SportspressAI | 4/2/2026 | 17/6/2026 | The SportsPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.7.26 via shortcodes 'template_name' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server,… | |
| Aplazada | Media (6.5) | 0.28% | — | Brian Legacy EplayerAISportspress TVAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Legacy ePlayer sportspress-tv allows Stored XSS.This issue affects Legacy ePlayer: from n/a through <= 0.9.9. | |
| Modificada | Media (4.8) | 0.41% | — | Themeboy Sportspress | 30/7/2024 | 17/6/2026 | The SportsPress WordPress plugin before 2.7.22 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.3) | 0.25% | — | Themeboy Sportspress | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in ThemeBoy SportsPress – Sports Club & League Manager.This issue affects SportsPress – Sports Club & League Manager: from n/a through 2.7.20. | |
| Modificada | Media (5.3) | 0.43% | — | Themeboy Sportspress | 5/3/2024 | 17/6/2026 | The SportsPress – Sports Club & League Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings_save() function in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to update the permalink structure… | |
| Modificada | Media (6.1) | 0.80% | — | Themeboy Sportspress | 21/12/2021 | 17/6/2026 | The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting back in the Events backend page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (5.4) | 0.70% | — | Themeboy Sportspress | 9/6/2020 | 17/6/2026 | The SportsPress plugin before 2.7.2 for WordPress allows XSS. |