Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.20% | — | Spotify Embed CreatorAI | 12/9/2025 | 30/9/2026 | The Spotify Embed Creator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotify' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.6) | 1.1% | — | Spotify LuigiAI | 10/12/2024 | 17/6/2026 | Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function. | |
| Aplazada | Media (6.4) | 0.42% | — | Spotify Play ButtonAI | 26/11/2024 | 17/6/2026 | The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spotifyplaybutton shortcode in all versions up to, and including, 2.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.62% | — | SpotifyAI | 28/10/2024 | 17/6/2026 | The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat. | |
| Modificada | Media (5.4) | 0.36% | — | Wolfiezero Spotify Play Button | 26/6/2024 | 17/6/2026 | The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Analizada | Media (6.5) | 0.64% | — | Yooooomi Your Spotify | 13/3/2024 | 17/6/2026 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 allows users to create a public token in the settings, which can be used to provide guest-level access to the information of that specific user in YourSpotify. The /me API endpoint discloses Spotify API access and… | |
| Analizada | Media (5.3) | 0.60% | — | Yooooomi Your Spotify | 13/3/2024 | 17/6/2026 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 is vulnerable to NoSQL injection in the public access token processing logic. Attackers can fully bypass the public token authentication mechanism, regardless if a public token has been generated before or not, without… | |
| Analizada | Crítica (9.8) | 0.82% | — | Yooooomi Your Spotify | 13/3/2024 | 17/6/2026 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.8.0 use a hardcoded JSON Web Token (JWT) secret to sign authentication tokens. Attackers can use this well-known value to forge valid authentication tokens for arbitrary users. This vulnerability allows attackers to bypass… | |
| Analizada | Media (6.1) | 0.44% | — | Yooooomi Your Spotify | 13/3/2024 | 17/6/2026 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version < 1.9.0 does not prevent other pages from displaying it in an iframe and is thus vulnerable to clickjacking. Clickjacking can be used to trick an existing user of YourSpotify to trigger actions, such as allowing signup of other… | |
| Analizada | Alta (8.8) | 0.37% | — | Yooooomi Your Spotify | 13/3/2024 | 17/6/2026 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.9.0 do not protect the API and login flow against Cross-Site Request Forgery (CSRF). Attackers can use this to execute CSRF attacks on victims, allowing them to retrieve, modify or delete data on the affected YourSpotify… | |
| Modificada | Alta (8.8) | 0.21% | — | Followingmedarling Spotify Play Button | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jonk @ Follow me Darling Sp*tify Play Button for WordPress plugin <= 2.10 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Jesweb Anchor Episodes Index (spotify FOR Podcasters) | 2/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in jesweb.Dev Anchor Episodes Index (Spotify for Podcasters) plugin <= 2.1.7 versions. | |
| Modificada | Media (5.4) | 0.37% | — | Followmedarling Spotify-play-button-for-wordpress | 5/4/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Jonk @ Follow me Darling Sp*tify Play Button for WordPress plugin <= 2.05 versions. | |
| Modificada | Media (4.8) | 0.35% | — | Followmedarling Spotify-play-button-for-wordpress | 4/4/2023 | 17/6/2026 | The Sp*tify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.07 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and… | |
| Modificada | Media (6.1) | 0.84% | — | Alfred-spotify-mini-player Alfred Spotify Mini Player | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in callback.php in Spotify-for-Alfred 0.13.9 and below allows remote attackers to inject arbitrary web script or HTML via the error parameter. | |
| Modificada | Alta (8.8) | 0.81% | — | Spotify Luigi | 20/12/2018 | 17/6/2026 | Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 contains a Cross ite Request Forgery (CSRF) vulnerability in API endpoint: /api/<method> that can result in Task metadata such as task name, id, parameter, etc. will be leaked to… | |
| Modificada | Alta (8.8) | 4.6% | — | Spotify | 19/4/2018 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI… |