Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 453 respecto a la semana anterior
Críticas / altas1281▼ 64 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.7)0.30%—TAG Category Taxonomy ManagerAI3/8/202626/8/2026
The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.
AplazadaMedia (6.5)0.29%—Acmeit TAG Category Taxonomy ManagerAI6/12/202517/6/2026
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'existing_terms_orderby' parameter in the AI preview AJAX endpoint in all versions up to, and including, 3.40.1. This is due to insufficient escaping on user-supplied…
AplazadaMedia (4.9)0.31%—TAG Category AND Taxonomy Manager AI Autotagger With OpenaiAI8/11/202517/6/2026
The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection via the 'post_types' parameter in all versions up to, and including, 3.40.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
ModificadaMedia (6.1)0.44%—Xydac Ultimate Taxonomy Manager25/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XYDAC Ultimate Taxonomy Manager plugin <= 2.0 versions.
ModificadaAlta (8.8)0.21%—Xydac Ultimate Taxonomy Manager16/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in XYDAC Ultimate Taxonomy Manager plugin <= 2.0 versions.
ModificadaMedia (5.1)0.68%—Mattias Hutterer Taxonomy Manager27/3/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-rc1 for Drupal allows remote attackers to hijack the authentication of users with 'administer taxonomy' permissions via unspecified vectors.
ModificadaBaja (3.5)0.90%—Mattias Hutterer Taxonomy Manager16/6/200916/6/2026
Cross-site scripting (XSS) vulnerability in the term data detail page in Taxonomy manager 5.x before 5.x-1.2, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy terms, to inject arbitrary web script or HTML via "Parent and…
ModificadaBaja (3.5)1.0%—Drupal Taxonomy Manager16/6/200916/6/2026
Cross-site scripting (XSS) vulnerability in the administrative page interface in Taxonomy manager 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy terms, to inject arbitrary web…