Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.2)——Boldgrid W3 Total CacheAI2/10/20262/10/2026
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, and including, 2.10.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (7.2)0.50%—Boldgrid W3 Total CacheAI5/9/20268/9/2026
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaCrítica (10)0.57%—Boldgrid W3 Total CacheAI19/8/202626/8/2026
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occupies the target name. On Apache, the…
AplazadaAlta (7.2)0.43%—Boldgrid W3 Total CacheAI14/8/202614/8/2026
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
AplazadaMedia (6.5)0.41%—W3 Total CacheAI6/8/202612/8/2026
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
AplazadaAlta (7.5)2.9%—Boldgrid W3 Total CacheAI11/7/202614/7/2026
The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation…
AplazadaCrítica (9)0.53%—W3 Total CacheAI2/7/20262/7/2026
Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.
AplazadaMedia (4.7)0.29%—Boldgrid W3 Total CacheAI17/6/202617/6/2026
Author Broken Access Control in W3 Total Cache <= 2.9.1 versions.
AplazadaAlta (7.5)2.7%—Boldgrid W3 Total CacheAI2/4/202617/6/2026
The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.3. This is due to the plugin bypassing its entire output buffering and processing pipeline when the request's User-Agent header contains "W3 Total Cache", which causes raw mfunc/mclude dynamic…
AplazadaCrítica (9)0.43%—Boldgrid W3 Total CacheAI5/3/202617/6/2026
Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects W3 Total Cache: from n/a through <= 2.9.1.
AplazadaCrítica (9)23%—Boldgrid W3 Total CacheAI17/11/202517/6/2026
The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.
AnalizadaAlta (8.5)1.8%—Boldgrid W3 Total Cache14/1/202517/6/2026
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_w3tc_admin_page function in all versions up to, and including, 2.8.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain the plugin's nonce…
AnalizadaAlta (7.5)2.3%—Boldgrid W3 Total Cache14/1/202517/6/2026
The W3 Total Cache plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 through the publicly exposed debug log file. This makes it possible for unauthenticated attackers to view potentially sensitive information in the exposed log file. For example, the log file may…
AnalizadaMedia (5.3)0.51%—Boldgrid W3 Total Cache14/1/202517/6/2026
The W3 Total Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to deactivate the plugin as well as activate and deactivate plugin…
AnalizadaAlta (7.5)0.81%—Boldgrid W3 Total Cache25/9/202417/6/2026
The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets stored in plaintext in the publicly visible plugin source. This can allow unauthenticated attackers to impersonate W3 Total Cache and gain access to user account…
ModificadaMedia (6.1)1.9%—Boldgrid W3 Total Cache19/7/202117/6/2026
The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the "extension" parameter in the Extensions dashboard, when the 'Anonymously track usage to improve product quality' setting is enabled, as the parameter is output in a JavaScript context without proper…
ModificadaMedia (6.1)1.9%—Boldgrid W3 Total Cache19/7/202117/6/2026
The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulnerability within the "extension" parameter in the Extensions dashboard, which is output in an attribute without being escaped first. This could allow an attacker, who can convince an authenticated…
ModificadaMedia (4.8)0.62%—Boldgrid W3 Total Cache12/7/202117/6/2026
The W3 Total Cache WordPress plugin before 2.1.3 did not sanitise or escape some of its CDN settings, allowing high privilege users to use JavaScript in them, which will be output in the page, leading to an authenticated Stored Cross-Site Scripting issue
ModificadaCrítica (9.8)74%—Automattic WP Super CacheBoldgrid W3 Total Cache12/2/202016/6/2026
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
ModificadaAlta (7.5)2.1%—Boldgrid W3 Total Cache22/11/201916/6/2026
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.
ModificadaAlta (7.5)2.3%—Boldgrid W3 Total Cache22/11/201916/6/2026
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
ModificadaAlta (7.5)5.4%—Boldgrid W3 Total Cache22/11/201916/6/2026
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
ModificadaAlta (7.5)19%—Boldgrid W3 Total Cache1/4/201917/6/2026
pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via the SubscribeURL field in SubscriptionConfirmation JSON data.
ModificadaMedia (6.8)1.4%—Boldgrid W3 Total Cache24/12/201417/6/2026
The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and hijack the authentication of administrators for requests that change the mobile site redirect URI via the mobile_groups[*][redirect]…
ModificadaMedia (4.3)2.1%—Boldgrid W3 Total Cache19/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the W3 Total Cache plugin before 0.9.4.1 for WordPress, when debug mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the "Cache key" in the HTML-Comments, as demonstrated by the PATH_INFO to the default URI.