Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.48% | — | Schiocco Support BoardAI | 17/6/2026 | 17/6/2026 | Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. | |
| Analizada | Media (4.8) | 0.23% | — | Schiocco Support Board | 25/3/2026 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the 'search' parameter in '/supportboard/include/articles.php'. This vulnerability can be… | |
| Analizada | Alta (8.7) | 0.43% | — | Schiocco Support Board | 25/3/2026 | 17/6/2026 | A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve, create, update and delete database via 'calls[0][message_ids][]' parameter in '/supportboard/include/ajax.php' endpoint. | |
| Aplazada | Alta (7.1) | 0.22% | — | Schiocco Support BoardAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board supportboard allows Reflected XSS.This issue affects Support Board: from n/a through < 3.8.7. | |
| Aplazada | Alta (8.1) | 0.66% | — | Schiocco Support BoardAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board supportboard allows PHP Local File Inclusion.This issue affects Support Board: from n/a through <= 3.8.0. | |
| Aplazada | Alta (7.1) | 0.24% | — | Schiocco Support BoardAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board supportboard allows Reflected XSS.This issue affects Support Board: from n/a through <= 3.8.0. | |
| Analizada | Crítica (9.8) | 0.36% | — | Schiocco Support Board | 9/7/2025 | 17/6/2026 | The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to bypass authorization and execute… | |
| Analizada | Crítica (9.8) | 0.90% | — | Schiocco Support Board | 9/7/2025 | 17/6/2026 | The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete function in all versions up to, and including, 3.8.0. This makes it possible for attackers to delete arbitrary files on the server, which can easily lead to remote code… | |
| Modificada | Alta (8.1) | 0.55% | — | Schiocco Support Board | 28/2/2022 | 17/6/2026 | The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files | |
| Modificada | Media (5.4) | 1.4% | — | Schiocco Support Board | 8/11/2021 | 17/6/2026 | The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatically executed. | |
| Modificada | Crítica (9.8) | 5.6% | — | Schiocco Support Board - Chat AND Help Desk | 20/9/2021 | 17/6/2026 | The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users. | |
| Modificada | Media (5.4) | 0.80% | — | Schiocco Support Board - Chat AND Help Desk | 17/10/2018 | 17/6/2026 | In the Schiocco "Support Board - Chat And Help Desk" plugin 1.2.3 for WordPress, a Stored XSS vulnerability has been discovered in file upload areas in the Chat and Help Desk sections via the msg parameter in a /wp-admin/admin-ajax.php sb_ajax_add_message action. |