Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.12% | — | Time SheetsAI | 5/12/2025 | 25/9/2026 | The Time Sheets plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.3. This is due to missing or incorrect nonce validation on several endpoints. This makes it possible for unauthenticated attackers to perform a variety of actions via a forged request granted they… | |
| Aplazada | Alta (7.1) | 0.24% | — | Mrdenny Time SheetsAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mrdenny Time Sheets time-sheets allows Reflected XSS.This issue affects Time Sheets: from n/a through <= 2.1.3. | |
| Modificada | Media (4.8) | 0.44% | — | Dcac Time Sheets | 10/4/2023 | 17/6/2026 | The Time Sheets WordPress plugin before 1.29.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.91% | — | Time Sheets Project Time Sheets | 22/8/2019 | 17/6/2026 | The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 0.91% | — | Time Sheets Project Time Sheets | 22/8/2019 | 17/6/2026 | The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list. | |
| Modificada | Media (5) | 2.8% | — | Riceball Multiple Time Sheets | 20/3/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to read arbitrary files via "../..//" (modified dot dot) sequences in the tab parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Riceball Multiple Time Sheets | 20/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the tab parameter to (1) index.php, as demonstrated using mixed case and encoded whitespace characters in the tag; or (2) clientinfo.php, (3) invoices.php, (4)… |