Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | Andreamarinucci Notification FOR TelegramAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions. | |
| Aplazada | Alta (7.1) | 0.21% | — | Fast-mcp-telegramAI | 28/9/2026 | 1/10/2026 | fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools accept files as a list of http(s) URLs, which the server downloads and attaches to the outgoing Telegram message. Downloads are guarded by _validate_url_security, an SSRF denylist that checks the URL's… | |
| Pendiente de análisis | Alta (8.3) | 0.20% | — | Telegram DesktopAI | 21/9/2026 | 22/9/2026 | Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group… | |
| Aplazada | Alta (8.2) | 0.66% | — | Telegram-searchAI | 11/8/2026 | 24/9/2026 | telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browsers by sending crafted messages containing unsanitized HTML to a shared Telegram group. The highlightKeyword function in MessageList.vue passes raw message content directly… | |
| Aplazada | Media (4.3) | 0.47% | — | Andreamarinucci Notification FOR TelegramAI | 11/7/2026 | 13/7/2026 | The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Crítica (9.4) | 0.65% | — | Fast-mcp-telegramAI | 2/7/2026 | 6/7/2026 | fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The verifier rejects the exact reserved token telegram, but it does not reject path separators or normalize the path before checking whether the session… | |
| Aplazada | Alta (7.1) | 0.25% | — | Andreamarinucci Notification FOR TelegramAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5 versions. | |
| Aplazada | Baja (2.1) | 0.51% | — | Telegram DesktopAI | 3/5/2026 | 17/6/2026 | A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is possible to initiate… | |
| Aplazada | Alta (7.1) | 0.18% | — | Wptelegram-widgetAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Socio WP Telegram Widget and Join Link wptelegram-widget allows Reflected XSS.This issue affects WP Telegram Widget and Join Link: from n/a through <= 2.2.13. | |
| Analizada | Media (4.6) | 0.51% | — | Telegram Desktop | 16/1/2026 | 17/6/2026 | Telegram Desktop 2.9.2 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized message payload. Attackers can generate a 9 million byte buffer and paste it into the messaging interface to trigger an application crash. | |
| Aplazada | Media (5.3) | 0.25% | — | Wptelegram WidgetAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Socio WP Telegram Widget and Join Link wptelegram-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Telegram Widget and Join Link: from n/a through <= 2.2.12. | |
| Aplazada | Media (4.3) | 0.22% | — | Andreamarinucci Notification FOR TelegramAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in rainafarai Notification for Telegram notification-for-telegram allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notification for Telegram: from n/a through <= 3.5.1. | |
| Aplazada | Alta (7.2) | 0.23% | — | Telegram BOT ChannelAI | 25/11/2025 | 17/6/2026 | The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username in all versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (4.3) | 0.14% | — | Andreamarinucci Notification FOR TelegramAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in rainafarai Notification for Telegram notification-for-telegram allows Cross Site Request Forgery.This issue affects Notification for Telegram: from n/a through <= 3.5. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Guru Team Site Chat ON TelegramAI | 16/7/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Guru Team Site Chat on Telegram site-chat-on-telegram allows Object Injection.This issue affects Site Chat on Telegram: from n/a through <= 1.0.4. | |
| Aplazada | Media (4.4) | 0.23% | — | Telegram FOR WPAI | 13/6/2025 | 17/6/2026 | The Telegram for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Analizada | Media (5.4) | 0.27% | — | Ninjateam Chat FOR Telegram | 30/5/2025 | 17/6/2026 | The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (4.3) | 0.23% | — | BOT FOR Telegram ON WoocommerceAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Guru Team Bot for Telegram on WooCommerce bot-for-telegram-on-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bot for Telegram on WooCommerce: from n/a through <= 1.2.6. | |
| Aplazada | Media (6.8) | 0.43% | — | Telegram AndroidAI | 11/2/2025 | 17/6/2026 | An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the return value of the checkPasscode method. | |
| Aplazada | Media (5.4) | 0.18% | — | Marcomilesi Telegram BOT AND ChannelAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Telegram Bot & Channel telegram-bot allows Cross Site Request Forgery.This issue affects Telegram Bot & Channel: from n/a through <= 3.8.2. | |
| Aplazada | Media (6.4) | 0.28% | — | Ninjateam Chat FOR TelegramAI | 24/12/2024 | 17/6/2026 | The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njtele_button shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.25% | — | Elfsight Telegram Chat CCAI | 18/11/2024 | 17/6/2026 | The Elfsight Telegram Chat CC plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the 'updatePreferences' function in all versions up to, and including, 1.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject… | |
| Aplazada | Media (5.4) | 0.39% | — | Wpcf7 TelegramAI | 28/10/2024 | 17/6/2026 | The Contact Form 7 + Telegram plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'wpcf7_Telegram::ajax' function in versions up to, and including, 0.8.5. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Modificada | Media (5.3) | 0.27% | — | 10web WPS Telegram Chat | 25/10/2024 | 17/6/2026 | The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to view the messages that are sent through the Telegram Bot API. | |
| Modificada | Media (6.5) | 0.27% | — | 10web WPS Telegram Chat | 25/10/2024 | 17/6/2026 | The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Wps_Telegram_Chat_Admin::checkСonnection' function in versions up to, and including, 4.6.0. This makes it possible for authenticated attackers, with subscriber-level… |