Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 307 respecto a la semana anterior
Críticas / altas1348▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.24% | — | Markjaquith Subscribe TO CommentsAI | 6/8/2026 | 12/8/2026 | Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions. | |
| Aplazada | Media (6.5) | 0.39% | — | Subscribe TO Comments ReloadedAI | 5/5/2026 | 17/6/2026 | The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a weak hash generation algorithm in all versions up to, and including, 240119. This makes it possible for unauthenticated attackers to extract the global key from any… | |
| Analizada | Alta (7.2) | 2.1% | — | Markjaquith Subscribe TO Comments | 19/7/2025 | 17/6/2026 | The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the Path to header value. This allows authenticated attackers, with administrative privileges and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code… | |
| Analizada | Media (6.1) | 0.41% | — | Markjaquith Subscribe TO Comments | 30/10/2024 | 17/6/2026 | The Subscribe to Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Modificada | Alta (7.5) | 0.51% | — | Wpkube Subscribe TO Comments Reloaded | 10/4/2024 | 12/8/2026 | Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725. | |
| Modificada | Media (5.4) | 0.64% | — | Markjaquith Subscribe TO Comments | 5/3/2023 | 16/6/2026 | A vulnerability, which was classified as problematic, was found in Subscribe to Comments Plugin up to 2.0.7 on WordPress. This affects an unknown part of the file subscribe-to-comments.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.8 is… | |
| Modificada | Media (5.4) | 0.39% | — | Wpkube Subscribe TO Comments Reloaded | 29/4/2022 | 17/6/2026 | Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key, reset all options, change notifications… | |
| Modificada | Alta (8.8) | 0.91% | — | Subscribe TO Comments Reloaded Project Subscribe TO Comments Reloaded | 19/3/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the… |