Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.2) | — | — | Strong TestimonialsAI | 3/10/2026 | 3/10/2026 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (6.5) | 0.26% | — | OptimoleAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in Optimole <= 4.2.14 versions. | |
| Aplazada | Media (6.5) | 0.15% | — | Strong TestimonialsAI | 30/9/2026 | 2/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Strong Testimonials strong-testimonials allows Stored XSS.This issue affects Strong Testimonials: from n/a through 3.3.11. | |
| Aplazada | Media (5.8) | 0.19% | — | Axelerant Testimonials WidgetAI | 26/9/2026 | 28/9/2026 | The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses. | |
| Aplazada | Alta (7.5) | 0.21% | — | Axelerant Testimonials WidgetAI | 26/9/2026 | 28/9/2026 | The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post. | |
| Aplazada | Media (6.8) | 0.24% | — | OptimoleAI | 26/9/2026 | 28/9/2026 | The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an… | |
| Aplazada | Media (6.4) | 0.33% | — | Strong TestimonialsAI | 18/9/2026 | 18/9/2026 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Alta (8.8) | 0.51% | — | OptimoleAI | 16/9/2026 | 17/9/2026 | The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an image tag attribute, allowing unauthenticated users to inject arbitrary attributes into pages served to every visitor, which leads to Stored Cross-Site Scripting. | |
| Pendiente de análisis | Crítica (9.8) | 0.52% | — | Fortinet FortimonitoronsightAI | 11/9/2026 | 11/9/2026 | A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here> | |
| Aplazada | Alta (7.2) | 0.53% | — | OptimoleAI | 28/8/2026 | 28/8/2026 | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a' (above_fold_images) parameter in all versions up to, and including, 4.2.10 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (5.4) | 0.23% | — | BNE TestimonialsAI | 7/8/2026 | 26/8/2026 | The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into an inline script, allowing users with the contributor role and above to inject arbitrary JavaScript that executes in the browser of anyone viewing the affected content. | |
| Aplazada | Alta (7.2) | 0.54% | — | Shapedplugin Real TestimonialsAI | 13/7/2026 | 13/7/2026 | Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Injection.This issue affects Real Testimonials: from n/a through <= 3.1.15. | |
| Aplazada | Alta (7.1) | 0.25% | — | OptimoleAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Optimole <= 4.2.7 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | BNE TestimonialsAI | 26/6/2026 | 29/9/2026 | Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Shapedsmart Smart Post Show PROAIReal Testimonials PROAIProduct Slider FOR Woocommerce PROAI | 24/6/2026 | 25/6/2026 | Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for… | |
| Aplazada | Media (6.4) | 0.32% | — | Fancy TestimonialsAI | 18/6/2026 | 18/6/2026 | The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attribute in the 'testimonial' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.23% | — | OptimoleAI | 18/6/2026 | 18/6/2026 | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.6. This is due to missing or incorrect nonce validation on the replace_file function. This makes it possible for… | |
| Aplazada | Alta (7.6) | 0.34% | — | ValtimoAI | 14/5/2026 | 17/6/2026 | Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClientCustomizer in the web module automatically intercepts all outgoing HTTP calls made via Spring's RestClient and logs the full request body, response body, and response headers. When an error response… | |
| Aplazada | Crítica (9.1) | 0.82% | — | Ritense ValtimoAI | 14/5/2026 | 17/6/2026 | Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case from 13.0.0 to before 13.23.0, and com.ritense.valtimo:contract from 13.4.0 to before 13.23.0 evaluate Spring Expression Language (SpEL) expressions from user-supplied… | |
| Aplazada | Media (5.1) | 0.20% | — | Radiustheme Testimonial Slider AND ShowcaseAI | 10/5/2026 | 25/7/2026 | WordPress Plugin Testimonial Slider and Showcase 2.2.6 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malicious scripts by failing to sanitize the post_title parameter. Attackers with editor privileges can inject JavaScript payloads through the testimonial title field… | |
| Aplazada | Media (4.9) | 0.48% | — | ValtimoAI | 16/4/2026 | 17/6/2026 | Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingService logs the full content of every incoming inbox message at INFO level. Inbox messages can contain highly sensitive information including personal data (PII), citizen identifiers (BSN), and case… | |
| Aplazada | Media (6.1) | 0.45% | — | OptimoleAI | 11/4/2026 | 17/6/2026 | The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL paths in versions up to, and including, 4.2.3 This is due to insufficient output escaping on user-supplied URL paths in the get_current_url() function, which are inserted into JavaScript code via… | |
| Aplazada | Alta (7.2) | 0.42% | — | OptimoleAI | 11/4/2026 | 17/6/2026 | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.2.2. This is due to insufficient input sanitization and output escaping on the user-supplied 's' parameter (srcset… | |
| Aplazada | Media (6.4) | 0.26% | — | Strong TestimonialsAI | 8/4/2026 | 25/7/2026 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonial_view shortcode in all versions up to, and including, 3.2.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Media (6.1) | 0.25% | — | Auntvt Timo | 26/3/2026 | 17/6/2026 | Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field. |