Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.8)0.43%—Wpjoli Joli Table OF ContentsAI5/9/20268/9/2026
The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views…
AplazadaBaja (3.5)0.17%—Wpjoli Joli Table OF ContentsAI5/9/20268/9/2026
The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for…
AplazadaMedia (6.5)0.22%—Table OF Contents BlockAI18/8/202620/8/2026
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
AplazadaAlta (7.1)0.14%—Markbeljaars Table OF Contents CreatorAI19/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Markbeljaars Table of Contents Creator allows Reflected XSS.This issue affects Table of Contents Creator: from n/a through 1.6.4.1.
AplazadaMedia (4.3)0.14%—Magazine3 Easy Table OF ContentsAI13/3/202617/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Magazine3 Easy Table of Contents easy-table-of-contents allows Cross Site Request Forgery.This issue affects Easy Table of Contents: from n/a through <= 2.0.80.
AplazadaMedia (4.3)0.19%—Wpmessiah TOP Table OF ContentsAI19/2/202617/6/2026
Missing Authorization vulnerability in WP Messiah TOP Table Of Contents top-table-of-contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TOP Table Of Contents: from n/a through <= 1.3.31.
AplazadaMedia (6.4)0.29%—Magazine3 Easy Table OF ContentsAI19/2/202617/6/2026
The Easy Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ez-toc` shortcode in all versions up to, and including, 2.0.78 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.1)0.24%—Kaizencoders Table OF ContentAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Table of content content-table allows Stored XSS.This issue affects Table of content: from n/a through <= 1.5.3.1.
AplazadaAlta (7.1)0.21%—Intelcaprep Site Table OF ContentsAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in intelcaprep Site Table of Contents site-table-of-contents allows Stored XSS.This issue affects Site Table of Contents: from n/a through <= 0.3.
AplazadaMedia (4.3)0.42%—Croover Rich Table OF ContentsAI9/4/202517/6/2026
Missing Authorization vulnerability in Croover.inc Rich Table of Contents rich-table-of-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rich Table of Contents: from n/a through <= 1.4.0.
AnalizadaMedia (6.1)0.22%—Theluckywp Luckywp Table OF Contents3/4/202517/6/2026
The LuckyWP Table of Contents plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.10. This is due to missing or incorrect nonce validation on the 'ajaxEdit' function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts via a forged…
AplazadaMedia (6.5)0.27%—Achal Jain Table OF Contents BlockAI24/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Achal Jain Table of Contents Block table-of-contents allows Stored XSS.This issue affects Table of Contents Block: from n/a through <= 1.0.2.
AnalizadaMedia (4.8)0.37%—Theluckywp Luckywp Table OF Contents12/12/202417/6/2026
The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaMedia (5.4)0.57%—Magazine3 Easy Table OF ContentsAI9/12/202417/6/2026
Missing Authorization vulnerability in Magazine3 Easy Table of Contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Table of Contents: from n/a through 2.0.45.2.
AnalizadaMedia (4.8)0.21%—Cminds CM Table OF Contents21/11/202417/6/2026
The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
AnalizadaBaja (3.8)0.20%—Cminds CM Table OF Contents18/11/202417/6/2026
The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin perform such action via a CSRF attack
AnalizadaMedia (4.8)0.37%—Dublue Table OF Contents Plus5/11/202417/6/2026
The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaAlta (8.8)0.21%—Dublue Table OF Contents Plus20/10/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Table of Contents Plus table-of-contents-plus allows Cross Site Request Forgery.This issue affects Table of Contents Plus: from n/a through <= 2408.
AnalizadaMedia (6.1)0.41%—Magazine3 Easy Table OF Contents6/8/202417/6/2026
The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.
AnalizadaMedia (6.1)0.39%—Magazine3 Easy Table OF Contents9/7/202417/6/2026
The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
AnalizadaMedia (5.9)0.33%—Magazine3 Easy Table OF Contents26/6/202417/6/2026
The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
AnalizadaMedia (4.6)0.34%—Theluckywp Luckywp Table OF Contents14/6/202417/6/2026
The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (4.8)0.33%—Theluckywp Luckywp Table OF Contents22/5/202417/6/2026
The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Contributor permissions and above to inject…
ModificadaMedia (6.1)0.38%—Theluckywp Luckywp Table OF Contents22/5/202417/6/2026
The LuckyWP Table of Contents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the attrs parameter in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
ModificadaMedia (5.4)0.30%—Theluckywp Luckywp Table OF Contents22/5/202417/6/2026
The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Header Title' field in all versions up to and including 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to…