Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 546 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
247 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.39% | — | Template KITAI | 30/9/2026 | 30/9/2026 | Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions. | |
| Pendiente de análisis | Crítica (9.1) | 0.30% | — | Wikimedia Template SandboxAI | 29/9/2026 | 1/10/2026 | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Pendiente de análisis | Media (6.9) | 0.39% | — | Marcos Camara01 Ecommerce TemplateAI | 28/9/2026 | 29/9/2026 | Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The… | |
| Pendiente de análisis | Media (4.8) | 0.29% | — | Wikimedia Mediawiki TemplatesandboxAI | 25/9/2026 | 28/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Aplazada | Media (4.3) | 0.21% | — | Wpgogo Custom Field TemplateAI | 22/9/2026 | 22/9/2026 | The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to delete… | |
| Aplazada | Media (6.5) | 0.58% | — | Wpgogo Custom Field TemplateAI | 19/9/2026 | 21/9/2026 | The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and including, 2.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.9) | 0.37% | — | Regularlabs Advanced Module ManagerAIRegularlabs Conditional ContentAIRegularlabs Content TemplaterAIRegularlabs RereplacerAI+1 | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla - The Conditions editor creates a default Condition Set name from the item to which the set is… | |
| Aplazada | Media (4.3) | 0.25% | — | Starter TemplatesAI | 11/9/2026 | 11/9/2026 | Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions. | |
| Aplazada | Media (4.3) | 0.28% | — | Arma Digital Media INC Website TemplateAI | 11/9/2026 | 11/9/2026 | Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Pendiente de análisis | Alta (7.7) | 0.38% | — | Hashicorp Consul-templateAI | 10/9/2026 | 10/9/2026 | The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task events. This vulnerability (CVE-2026-87993) is fixed in consul-template 0.43.0. | |
| Aplazada | Media (5.3) | 0.33% | — | Dernekplus Website TemplateAI | 10/9/2026 | 10/9/2026 | Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpkoi Templates FOR ElementorAI | 3/9/2026 | 7/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2. | |
| Aplazada | Media (6.9) | 0.27% | — | Appwrite TemplatesAI | 20/8/2026 | 24/9/2026 | The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns "typeof signature !== 'string' || (await verify(...))", so when the X-Hub-Signature-256… | |
| Aplazada | Alta (7.5) | 0.46% | — | Kadencewp Starter TemplatesAI | 18/8/2026 | 20/8/2026 | Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | TemplatelyAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. | |
| Aplazada | Alta (8.8) | 1.3% | — | TemplatelyAI | 15/8/2026 | 20/8/2026 | The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.1 via the fetch_remote_file function. This is due to a filename validation/destination mismatch in… | |
| Pendiente de análisis | Alta (8.8) | 0.32% | — | Anthropic Claude Code TemplatesAI | 11/8/2026 | 9/9/2026 | Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The POST /api/execute… | |
| Aplazada | Media (6.5) | 0.34% | — | TemplatelyAI | 7/8/2026 | 26/8/2026 | The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate administrator and redirecting the… | |
| Aplazada | Media (6.1) | 0.26% | — | Ember Dynamic Render TemplateAIEmber Template CompilationAI | 5/8/2026 | 26/8/2026 | The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property directly into Ember/Glimmer's compileTemplate (from @ember/template-compilation) with no sanitization, allow-listing, or validation of the input. | |
| Aplazada | Alta (7.5) | 0.56% | — | Art-templateAI | 5/8/2026 | 26/8/2026 | art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and extend template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that the result remains inside root. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Vps.org Zulip TemplateAIZulipAI | 31/7/2026 | 8/9/2026 | Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True. | |
| Aplazada | Media (6.1) | 0.25% | — | Polen Media Software AND Information Services Website TemplateAI | 24/7/2026 | 24/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2. | |
| Aplazada | Media (4.3) | 0.27% | — | TemplatespareAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions. | |
| Aplazada | Media (4.7) | 0.13% | 💥 PoC | Hashicorp Consul-templateAI | 8/7/2026 | 9/7/2026 | The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1. | |
| Aplazada | Alta (8.5) | 0.36% | — | Contributor SQL Injection IN Custom Field TemplateAI | 2/7/2026 | 2/7/2026 | Contributor SQL Injection in Custom Field Template <= 2.7.8 versions. |