Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.25% | — | Post Views Stats CounterAI | 30/9/2026 | 30/9/2026 | The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 5/9/2026 | 8/9/2026 | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who… | |
| Aplazada | Alta (8.2) | 0.20% | — | Wp-feedstats Wordpress PluginAI | 2/9/2026 | 3/9/2026 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the plugin settings, clear logs etc | |
| Aplazada | Alta (7.2) | 0.32% | — | Wp-statsAI | 14/8/2026 | 14/8/2026 | The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wp-statsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions. | |
| Aplazada | Alta (7.5) | 0.41% | — | Wp-feedstats Wordpress PluginAI | 31/7/2026 | 26/8/2026 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes. | |
| Aplazada | Media (5.3) | 0.30% | — | Wp-feedstats Wordpress PluginAI | 22/7/2026 | 22/7/2026 | The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making any payment. | |
| Aplazada | Media (5.4) | 0.14% | — | Wp-feedstats Wordpress PluginAI | 20/7/2026 | 20/7/2026 | The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's… | |
| Aplazada | Alta (8.8) | 0.43% | — | Wp-feedstats Wordpress PluginAI | 23/6/2026 | 23/6/2026 | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above. | |
| Aplazada | Crítica (9.1) | 0.57% | — | NET Statsite ClientAI | 22/6/2026 | 22/6/2026 | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for newlines or other protocol control characters… | |
| Aplazada | Media (4.3) | 0.18% | — | GostatsAI | 27/5/2026 | 17/6/2026 | The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the gostats_manage() function. This makes it possible for unauthenticated attackers to update the plugin's settings… | |
| Aplazada | Media (5.3) | 0.40% | — | Mojolicious Plugin StatsdAIPerl NET Statsd TinyAI | 26/5/2026 | 24/7/2026 | Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Version 0.06 changes the module from being a statsd client to using a… | |
| Aplazada | Alta (7.3) | 0.34% | — | NET Statsd LiteAI | 18/5/2026 | 19/6/2026 | Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Note that version 0.9.0 fixed a similar issue CVE-2026-46719 for metric names. | |
| Aplazada | Alta (8.2) | 0.42% | — | NET Statsd TinyAI | 17/5/2026 | 19/6/2026 | Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. | |
| Aplazada | Media (6.5) | 0.36% | — | NET Statsd LiteAI | 16/5/2026 | 19/6/2026 | Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. | |
| Aplazada | Alta (7.5) | 0.36% | — | Catalyst Plugin StatsdAI | 10/5/2026 | 24/7/2026 | Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' session ids may be leaked. This may allow an attacker to use session ids as authentication… | |
| Aplazada | Media (5.3) | 0.26% | — | Plack Middleware StatsdAI | 10/5/2026 | 24/7/2026 | Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses. If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on another network), then users' IP addresses may be leaked. Since version 0.9.0, the IP address is no longer logged to… | |
| Aplazada | Media (5.1) | 0.22% | — | 3dady Real Time WEB StatsAI | 10/5/2026 | 23/9/2026 | WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dady_input_text or dady2_input_text fields via the plugin… | |
| Analizada | Alta (7.8) | 1.0% | — | AwstatsDebian Linux | 20/3/2026 | 17/6/2026 | AWStats 8.0 is vulnerable to Command Injection via the open function | |
| Aplazada | Alta (7.1) | 0.17% | — | Shahjada Visitor Stats WidgetAI | 8/1/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjada Visitor Stats Widget visitor-stats-widget allows Reflected XSS.This issue affects Visitor Stats Widget: from n/a through <= 1.5.0. | |
| Aplazada | Media (6.1) | 0.25% | — | Clik StatsAI | 4/12/2025 | 17/6/2026 | The Clik stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (8.5) | 0.62% | — | IstatsAI | 24/11/2025 | 17/6/2026 | iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via command injection.This issue affects iStats: 7.10.4. | |
| Aplazada | Media (6.4) | 0.19% | — | Easy Plugin StatsAI | 11/10/2025 | 17/6/2026 | The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.3) | 0.28% | — | Jenkins Global Build Stats | 3/9/2025 | 17/6/2026 | Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs. | |
| Analizada | Media (6.1) | 0.16% | — | Hk1993 WP Online Users Stats | 6/6/2025 | 17/6/2026 | The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation within the hk_dataset_results() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged… |