Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.43% | — | Wpjoli Joli Table OF ContentsAI | 5/9/2026 | 8/9/2026 | The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views… | |
| Aplazada | Baja (3.5) | 0.17% | — | Wpjoli Joli Table OF ContentsAI | 5/9/2026 | 8/9/2026 | The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for… | |
| Aplazada | Media (6.5) | 0.22% | — | Table OF Contents BlockAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. | |
| Aplazada | Alta (7.1) | 0.14% | — | Markbeljaars Table OF Contents CreatorAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table of Contents Creator allows Reflected XSS.This issue affects Table of Contents Creator: from n/a through 1.6.4.1. | |
| Aplazada | Media (4.3) | 0.14% | — | Magazine3 Easy Table OF ContentsAI | 13/3/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Magazine3 Easy Table of Contents easy-table-of-contents allows Cross Site Request Forgery.This issue affects Easy Table of Contents: from n/a through <= 2.0.80. | |
| Aplazada | Media (4.3) | 0.19% | — | Wpmessiah TOP Table OF ContentsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Messiah TOP Table Of Contents top-table-of-contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TOP Table Of Contents: from n/a through <= 1.3.31. | |
| Aplazada | Media (6.4) | 0.29% | — | Magazine3 Easy Table OF ContentsAI | 19/2/2026 | 17/6/2026 | The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` shortcode in all versions up to, and including, 2.0.78 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.24% | — | Kaizencoders Table OF ContentAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Table of content content-table allows Stored XSS.This issue affects Table of content: from n/a through <= 1.5.3.1. | |
| Aplazada | Alta (7.1) | 0.21% | — | Intelcaprep Site Table OF ContentsAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in intelcaprep Site Table of Contents site-table-of-contents allows Stored XSS.This issue affects Site Table of Contents: from n/a through <= 0.3. | |
| Aplazada | Media (4.3) | 0.42% | — | Croover Rich Table OF ContentsAI | 9/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Croover.inc Rich Table of Contents rich-table-of-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rich Table of Contents: from n/a through <= 1.4.0. | |
| Analizada | Media (6.1) | 0.22% | — | Theluckywp Luckywp Table OF Contents | 3/4/2025 | 17/6/2026 | The LuckyWP Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.10. This is due to missing or incorrect nonce validation on the 'ajaxEdit' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts via a forged… | |
| Aplazada | Media (6.5) | 0.27% | — | Achal Jain Table OF Contents BlockAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Achal Jain Table of Contents Block table-of-contents allows Stored XSS.This issue affects Table of Contents Block: from n/a through <= 1.0.2. | |
| Analizada | Media (4.8) | 0.37% | — | Theluckywp Luckywp Table OF Contents | 12/12/2024 | 17/6/2026 | The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.4) | 0.57% | — | Magazine3 Easy Table OF ContentsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Magazine3 Easy Table of Contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Table of Contents: from n/a through 2.0.45.2. | |
| Analizada | Media (4.8) | 0.21% | — | Cminds CM Table OF Contents | 21/11/2024 | 17/6/2026 | The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Analizada | Baja (3.8) | 0.20% | — | Cminds CM Table OF Contents | 18/11/2024 | 17/6/2026 | The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack | |
| Analizada | Media (4.8) | 0.37% | — | Dublue Table OF Contents Plus | 5/11/2024 | 17/6/2026 | The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Alta (8.8) | 0.21% | — | Dublue Table OF Contents Plus | 20/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Table of Contents Plus table-of-contents-plus allows Cross Site Request Forgery.This issue affects Table of Contents Plus: from n/a through <= 2408. | |
| Analizada | Media (6.1) | 0.41% | — | Magazine3 Easy Table OF Contents | 6/8/2024 | 17/6/2026 | The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks. | |
| Analizada | Media (6.1) | 0.39% | — | Magazine3 Easy Table OF Contents | 9/7/2024 | 17/6/2026 | The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. | |
| Analizada | Media (5.9) | 0.33% | — | Magazine3 Easy Table OF Contents | 26/6/2024 | 17/6/2026 | The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Analizada | Media (4.6) | 0.34% | — | Theluckywp Luckywp Table OF Contents | 14/6/2024 | 17/6/2026 | The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.33% | — | Theluckywp Luckywp Table OF Contents | 22/5/2024 | 17/6/2026 | The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Contributor permissions and above to inject… | |
| Modificada | Media (6.1) | 0.38% | — | Theluckywp Luckywp Table OF Contents | 22/5/2024 | 17/6/2026 | The LuckyWP Table of Contents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the attrs parameter in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Media (5.4) | 0.30% | — | Theluckywp Luckywp Table OF Contents | 22/5/2024 | 17/6/2026 | The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Header Title' field in all versions up to and including 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… |