Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
121 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (4.3) | — | — | Burst-statistics Burst StatisticsAI | 3/10/2026 | 3/10/2026 | The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Account Persistence in all versions up to, and including, 3.7.1. This is due to the `maybe_load_shared_dashboard()` handler issuing a genuine WordPress session… | |
| Recibida | Alta (7.5) | — | — | WP Visitor StatisticsAI | 3/10/2026 | 3/10/2026 | The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Recibida | Alta (7.2) | — | — | Wp-buy Visitor Traffic Real Time StatisticsAI | 3/10/2026 | 3/10/2026 | The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header in all versions up to, and including, 8.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.1) | 0.46% | — | Wp-statistics WP StatisticsAI | 2/10/2026 | 2/10/2026 | The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key in all versions up to, and including, 14.16.14 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.19% | — | Visitors Traffic Real Time Statistics PROAI | 2/10/2026 | 2/10/2026 | The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers… | |
| Aplazada | Alta (7.1) | 0.20% | — | Wp-statistics WP StatisticsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Visitor Traffic Real Time Statistics PROAI | 17/9/2026 | 17/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions. | |
| Aplazada | Media (6.1) | 0.25% | — | Wp-statistics WP StatisticsAI | 3/9/2026 | 5/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Visitor Traffic Real Time Statistics PROAI | 27/8/2026 | 28/8/2026 | Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions. | |
| Aplazada | Alta (7.2) | 0.65% | — | Wp-statistics WP StatisticsAI | 19/8/2026 | 20/8/2026 | The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.5) | 0.36% | — | Visitor Traffic Real Time Statistics PROAI | 13/8/2026 | 14/8/2026 | Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Visitor Traffic Real Time Statistics PROAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Visitors Traffic Real Time StatisticsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Visitors Traffic Real Time Statistics <= 8.11 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | Wp-statistics WP StatisticsAI | 8/8/2026 | 26/8/2026 | The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data. | |
| Aplazada | Alta (7.1) | 0.25% | — | Visitor Traffic Real Time Statistics PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Veronalabs WP StatisticsAI | 1/6/2026 | 22/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. This issue affects WP Statistics: from n/a through 14.16.6. | |
| Aplazada | Crítica (9.8) | 3.0% | — | Burst-statistics Burst StatisticsAI | 14/5/2026 | 17/6/2026 | The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticated()` function when validating application passwords from the… | |
| Aplazada | Alta (7.2) | 0.42% | — | Wp-statistics WP StatisticsAI | 17/4/2026 | 17/6/2026 | The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and including, 14.16.4. This is due to insufficient input sanitization and output escaping. The plugin's referral parser copies the raw utm_source value into the source_name field… | |
| Aplazada | Media (6.5) | 0.44% | — | Wp-statistics WP StatisticsAI | 17/4/2026 | 17/6/2026 | The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing capability checks on multiple AJAX handlers including `wp_statistics_get_filters`, `wp_statistics_getPrivacyStatus`, `wp_statistics_updatePrivacyStatus`, and… | |
| Aplazada | Media (6.4) | 0.36% | — | WP Visitor StatisticsAI | 8/4/2026 | 20/7/2026 | The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wsm_showDayStatsGraph' shortcode in all versions up to, and including, 8.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.32% | — | Wp-buy Visitor Traffic Real Time StatisticsAI | 4/4/2026 | 24/7/2026 | The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Alta (8.7) | 0.53% | — | Gotac Statistics Database System | 16/1/2026 | 17/6/2026 | Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly exploit a specific functionality to query database contents. | |
| Analizada | Alta (8.7) | 0.66% | — | Gotac Statistics Database System | 16/1/2026 | 17/6/2026 | Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. | |
| Aplazada | Media (6.5) | 0.20% | — | Osama.esh WP Visitor Statistics Real Time TrafficAI | 16/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows DOM-Based XSS.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 8.3. | |
| Aplazada | Alta (7.2) | 9.7% | — | Wp-statistics WP StatisticsAI | 27/9/2025 | 17/6/2026 | The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent Header in all versions up to, and including, 14.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… |