Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.25%—Ecoal95 EC Stars RatingAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ecoal95 EC Stars Rating ec-stars-rating allows Stored XSS.This issue affects EC Stars Rating: from n/a through <= 1.0.11.
AplazadaMedia (5.3)0.44%—Dash Labs YET Another Stars RatingAI13/12/202417/6/2026
Missing Authorization vulnerability in Dash Labs Yet Another Stars Rating yet-another-stars-rating allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yet Another Stars Rating: from n/a through <= 3.4.3.
AplazadaAlta (8.5)0.40%—Saleswonder Team 5 Stars Rating FunnelAI9/11/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.4.01.
AplazadaMedia (5.3)0.30%—Saleswonder 5 Stars Rating FunnelAI9/6/202417/6/2026
Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.2.67.
AplazadaAlta (7.5)0.58%—Saleswonder 5 Stars Rating FunnelAI10/4/202417/6/2026
Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue affects 5 Stars Rating Funnel: from n/a through <= 1.2.67.
ModificadaAlta (8.1)0.40%—YET Another Stars Rating Project YET Another Stars Rating30/11/202317/6/2026
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in YetAnotherStarsRating.Com YASR – Yet Another Star Rating Plugin for WordPress.This issue affects YASR – Yet Another Star Rating Plugin for WordPress: from n/a through 3.3.8.
ModificadaMedia (6.1)0.38%—Yasr - YET Another Stars Rating Project Yasr - YET Another Stars Rating16/3/202317/6/2026
Cross-Site Scripting (XSS) vulnerability in Dario Curvino Yasr – Yet Another Stars Rating plugin <= 3.1.2 versions.
ModificadaCrítica (9.8)1.7%—5 Stars Rating Funnel Project 5 Stars Rating Funnel25/4/202217/6/2026
The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue. There is an…
ModificadaMedia (6.1)0.80%—YET Another Stars Rating Project YET Another Stars Rating4/2/202217/6/2026
Cross-Site Scripting (XSS) vulnerability discovered in Yasr – Yet Another Stars Rating WordPress plugin (versions <= 2.9.9), vulnerable at parameter 'source'.
ModificadaAlta (7.5)1.6%—Stars Rating Project Stars Rating3/1/202217/6/2026
The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integer, causing a Denial of Service in the comments section, or pending comment dashboard depending if the user sent it as unauthenticated or authenticated.
ModificadaAlta (8.8)1.9%—YET Another Stars Rating Project YET Another Stars Rating10/10/201917/6/2026
The yet-another-stars-rating plugin before 0.9.1 for WordPress has yasr_get_multi_set_values_and_field SQL injection via the set_id parameter.
Orbitaley — Vulnerabilidades