Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.20% | — | Radiustheme Testimonial Slider AND ShowcaseAI | 10/5/2026 | 25/7/2026 | WordPress Plugin Testimonial Slider and Showcase 2.2.6 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malicious scripts by failing to sanitize the post_title parameter. Attackers with editor privileges can inject JavaScript payloads through the testimonial title field… | |
| Aplazada | Media (6.5) | 0.33% | — | Pickplugins Testimonial SliderAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Testimonial Slider testimonial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Testimonial Slider: from n/a through <= 2.0.15. | |
| Aplazada | Media (4.4) | 0.31% | — | Client Testimonial SliderAI | 19/2/2026 | 17/6/2026 | The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Testimonial Heading' setting in all versions up to, and including, 2.0. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.25% | — | Client Testimonial SliderAI | 9/1/2026 | 17/6/2026 | The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aft_testimonial_meta_name' custom field in the Client Information metabox in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes… | |
| Analizada | Media (4.9) | 0.30% | — | I13websolution Easy Testimonial Slider AND Form | 29/10/2025 | 17/6/2026 | The Easy Testimonial Slider and Form plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.33% | — | Pickplugins Testimonial SliderAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Testimonial Slider testimonial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Testimonial Slider: from n/a through <= 2.0.15. | |
| Aplazada | Alta (7.5) | 0.61% | — | Radiustheme Testimonial Slider AND Showcase PROAI | 22/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slider And Showcase Pro testimonial-slider-showcase-pro allows PHP Local File Inclusion.This issue affects Testimonial Slider And Showcase Pro: from n/a through <= 2.1.7. | |
| Aplazada | Alta (8.8) | 0.48% | — | Pluginops Testimonial SliderAI | 26/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PluginOps Testimonial Slider testimonial-add allows PHP Local File Inclusion.This issue affects Testimonial Slider: from n/a through <= 3.5.8.6. | |
| Aplazada | Media (5.3) | 0.36% | — | Gsplugins GS Testimonial SliderAI | 7/5/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in GS Plugins GS Testimonial Slider gs-testimonial allows Code Injection.This issue affects GS Testimonial Slider: from n/a through <= 3.2.9. | |
| Aplazada | Media (4.3) | 0.29% | — | Gsplugins GS Testimonial SliderAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in GS Plugins GS Testimonial Slider gs-testimonial allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GS Testimonial Slider: from n/a through <= 3.3.0. | |
| Aplazada | Alta (8.1) | 0.93% | — | Radiustheme Testimonial Slider AND Showcase PROAI | 11/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slider And Showcase Pro testimonial-slider-showcase-pro allows PHP Local File Inclusion.This issue affects Testimonial Slider And Showcase Pro: from n/a through <= 2.3.15. | |
| Aplazada | Alta (8.8) | 0.49% | — | Pickplugins Testimonial SliderAI | 3/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider testimonial allows Object Injection.This issue affects Testimonial Slider: from n/a through <= 2.0.13. | |
| Aplazada | Media (6.5) | 0.28% | — | Sazzadh Testimonial Slider ShortcodeAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sazzad Testimonial Slider Shortcode testimonial-slider-shortcode allows Stored XSS.This issue affects Testimonial Slider Shortcode: from n/a through <= 1.1.9. | |
| Aplazada | Media (6.4) | 0.43% | — | Social Proof Testimonial SliderAI | 13/11/2024 | 17/6/2026 | The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spslider-block shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.35% | — | Testimonial SliderAI | 14/5/2024 | 17/6/2026 | The Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'testimonialcategory' shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.4) | 0.44% | — | Radiustheme Testimonial Slider AND Showcase | 15/4/2024 | 17/6/2026 | The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (6.5) | 0.36% | — | Gsplugins GS Testimonial SliderAI | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GS Plugins GS Testimonial Slider allows Stored XSS.This issue affects GS Testimonial Slider: from n/a through 3.1.4. | |
| Analizada | Media (4.3) | 0.38% | — | Radiustheme Testimonial Slider AND Showcase | 26/3/2024 | 17/6/2026 | The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities to edit certain sensitive Testimonial Slider WordPress plugin before 2.3.7 settings, making it possible for users with at least the Author role to edit them. | |
| Modificada | Media (4.8) | 0.42% | — | I13websolution Easy Testimonial Slider AND Form | 25/10/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form allows Stored XSS.This issue affects Easy Testimonial Slider and Form: from n/a through 1.0.18. | |
| Modificada | Media (5.4) | 0.47% | — | Sazzadh Testimonial Slider Shortcode | 16/10/2023 | 17/6/2026 | The Testimonial Slider Shortcode WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users… | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Easy Testimonial Slider AND Form | 8/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form plugin <= 1.0.15 versions. | |
| Modificada | Alta (8.8) | 0.33% | — | Slidervilla Testimonial Slider | 8/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) in David Anderson Testimonial Slider plugin <= 1.3.1 on WordPress. | |
| Modificada | Media (5.4) | 0.51% | — | Gsplugins GS Testimonial Slider | 23/9/2022 | 17/6/2026 | Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in GS Testimonial Slider plugin <= 1.9.6 at WordPress. | |
| Modificada | Media (4.8) | 0.57% | — | Gsplugins GS Testimonial Slider | 28/7/2022 | 17/6/2026 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in GS Plugins GS Testimonial Slider plugin <= 1.9.5 at WordPress. | |
| Modificada | Media (5.4) | 0.57% | — | Web-settler Testimonial Slider | 4/4/2022 | 17/6/2026 | Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – Free Testimonials Slider Plugin (WordPress plugin) via parameters mpsp_posts_bg_color, mpsp_posts_description_color, mpsp_slide_nav_button_color. |