Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 307 respecto a la semana anterior
Críticas / altas1348▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.24%—Markjaquith Subscribe TO CommentsAI6/8/202612/8/2026
Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.
AplazadaMedia (6.5)0.39%—Subscribe TO Comments ReloadedAI5/5/202617/6/2026
The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leaked secret key and usage of a weak hash generation algorithm in all versions up to, and including, 240119. This makes it possible for unauthenticated attackers to extract the global key from any…
AnalizadaAlta (7.2)2.1%—Markjaquith Subscribe TO Comments19/7/202517/6/2026
The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 via the Path to header value. This allows authenticated attackers, with administrative privileges and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code…
AnalizadaMedia (6.1)0.41%—Markjaquith Subscribe TO Comments30/10/202417/6/2026
The Subscribe to Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if…
ModificadaAlta (7.5)0.51%—Wpkube Subscribe TO Comments Reloaded10/4/202412/8/2026
Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.
ModificadaMedia (5.4)0.64%—Markjaquith Subscribe TO Comments5/3/202316/6/2026
A vulnerability, which was classified as problematic, was found in Subscribe to Comments Plugin up to 2.0.7 on WordPress. This affects an unknown part of the file subscribe-to-comments.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.8 is…
ModificadaMedia (5.4)0.39%—Wpkube Subscribe TO Comments Reloaded29/4/202217/6/2026
Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 211130 on WordPress allows attackers to clean up Log archive, download system info file, plugin system settings, plugin options settings, generate a new key, reset all options, change notifications…
ModificadaAlta (8.8)0.91%—Subscribe TO Comments Reloaded Project Subscribe TO Comments Reloaded19/3/201817/6/2026
Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the…