Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

71 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.18%—Andreamarinucci Notification FOR TelegramAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
AplazadaAlta (7.1)0.21%—Fast-mcp-telegramAI28/9/20261/10/2026
fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's…
Pendiente de análisisAlta (8.3)0.20%—Telegram DesktopAI21/9/202622/9/2026
Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group…
AplazadaAlta (8.2)0.66%—Telegram-searchAI11/8/202624/9/2026
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browsers by sending crafted messages containing unsanitized HTML to a shared Telegram group. The highlightKeyword function in MessageList.vue passes raw message content directly…
AplazadaMedia (4.3)0.47%—Andreamarinucci Notification FOR TelegramAI11/7/202613/7/2026
The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaCrítica (9.4)0.65%—Fast-mcp-telegramAI2/7/20266/7/2026
fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The verifier rejects the exact reserved token telegram, but it does not reject path separators or normalize the path before checking whether the session…
AplazadaAlta (7.1)0.25%—Andreamarinucci Notification FOR TelegramAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5 versions.
AplazadaBaja (2.1)0.51%—Telegram DesktopAI3/5/202617/6/2026
A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is possible to initiate…
AplazadaAlta (7.1)0.18%—Wptelegram-widgetAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Socio WP Telegram Widget and Join Link wptelegram-widget allows Reflected XSS.This issue affects WP Telegram Widget and Join Link: from n/a through <= 2.2.13.
AnalizadaMedia (4.6)0.51%—Telegram Desktop16/1/202617/6/2026
Telegram Desktop 2.9.2 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized message payload. Attackers can generate a 9 million byte buffer and paste it into the messaging interface to trigger an application crash.
AplazadaMedia (5.3)0.25%—Wptelegram WidgetAI24/12/202517/6/2026
Missing Authorization vulnerability in WP Socio WP Telegram Widget and Join Link wptelegram-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Telegram Widget and Join Link: from n/a through <= 2.2.12.
AplazadaMedia (4.3)0.22%—Andreamarinucci Notification FOR TelegramAI9/12/202517/6/2026
Missing Authorization vulnerability in rainafarai Notification for Telegram notification-for-telegram allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notification for Telegram: from n/a through <= 3.5.1.
AplazadaAlta (7.2)0.23%—Telegram BOT ChannelAI25/11/202517/6/2026
The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username in all versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaMedia (4.3)0.14%—Andreamarinucci Notification FOR TelegramAI5/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in rainafarai Notification for Telegram notification-for-telegram allows Cross Site Request Forgery.This issue affects Notification for Telegram: from n/a through <= 3.5.
AplazadaCrítica (9.8)0.50%—Guru Team Site Chat ON TelegramAI16/7/202517/6/2026
Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object Injection.This issue affects Site Chat on Telegram: from n/a through <= 1.0.4.
AplazadaMedia (4.4)0.23%—Telegram FOR WPAI13/6/202517/6/2026
The Telegram for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject…
AnalizadaMedia (5.4)0.27%—Ninjateam Chat FOR Telegram30/5/202517/6/2026
The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…
AplazadaMedia (4.3)0.23%—BOT FOR Telegram ON WoocommerceAI19/5/202517/6/2026
Missing Authorization vulnerability in Guru Team Bot for Telegram on WooCommerce bot-for-telegram-on-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bot for Telegram on WooCommerce: from n/a through <= 1.2.6.
AplazadaMedia (6.8)0.43%—Telegram AndroidAI11/2/202517/6/2026
An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the return value of the checkPasscode method.
AplazadaMedia (5.4)0.18%—Marcomilesi Telegram BOT AND ChannelAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Telegram Bot & Channel telegram-bot allows Cross Site Request Forgery.This issue affects Telegram Bot & Channel: from n/a through <= 3.8.2.
AplazadaMedia (6.4)0.28%—Ninjateam Chat FOR TelegramAI24/12/202417/6/2026
The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njtele_button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaMedia (6.4)0.25%—Elfsight Telegram Chat CCAI18/11/202417/6/2026
The Elfsight Telegram Chat CC plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'updatePreferences' function in all versions up to, and including, 1.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject…
AplazadaMedia (5.4)0.39%—Wpcf7 TelegramAI28/10/202417/6/2026
The Contact Form 7 + Telegram plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'wpcf7_Telegram::ajax' function in versions up to, and including, 0.8.5. This makes it possible for authenticated attackers, with subscriber-level access and…
ModificadaMedia (5.3)0.27%—10web WPS Telegram Chat25/10/202417/6/2026
The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to view the messages that are sent through the Telegram Bot API.
ModificadaMedia (6.5)0.27%—10web WPS Telegram Chat25/10/202417/6/2026
The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Wps_Telegram_Chat_Admin::checkСonnection' function in versions up to, and including, 4.6.0. This makes it possible for authenticated attackers, with subscriber-level…