Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.43% | — | Boldgrid Total UpkeepAI | 12/8/2026 | 3/9/2026 | The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore functionality and exposes it to unauthenticated users, allowing them to disclose sensitive backup information and to force a full site restore that overwrites the live site's files and database.… | |
| Aplazada | Alta (8.2) | 0.37% | — | Boldgrid Total UpkeepAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions. | |
| Aplazada | Media (5.3) | 0.40% | — | Boldgrid Total UpkeepAI | 1/5/2026 | 17/6/2026 | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_cli_cancel' function in all versions up to, and including, 1.17.1. This makes it possible for unauthenticated attackers… | |
| Analizada | Alta (7.5) | 1.7% | — | Boldgrid Total Upkeep | 12/7/2025 | 17/6/2026 | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.14.9 via the env-info.php and restore-info.json files. This makes it possible for unauthenticated attackers to find the location of… | |
| Analizada | Alta (7.2) | 0.86% | — | Boldgrid Total Upkeep | 26/3/2025 | 17/6/2026 | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.10 via the compression_level setting. This is due to the plugin using the compression_level setting in proc_open() without any validation.… | |
| Analizada | Media (6.5) | 0.47% | — | Boldgrid Total Upkeep | 27/2/2025 | 17/6/2026 | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.16.8 via the 'download' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Analizada | Alta (7.2) | 1.0% | — | Boldgrid Total Upkeep | 26/11/2024 | 17/6/2026 | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization. This makes it possible for authenticated… | |
| Analizada | Alta (7.5) | 0.66% | — | Boldgrid Total Upkeep | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep allows Relative Path Traversal.This issue affects Total Upkeep: from n/a through 1.15.8. | |
| Modificada | Media (4.3) | 0.57% | — | Boldgrid Total Upkeep | 7/3/2023 | 17/6/2026 | The Total Upkeep plugin for WordPress is vulnerable to information disclosure in versions up to, and including 1.14.13. This is due to missing authorization on the heartbeat_received() function that triggers on WordPress heartbeat. This makes it possible for authenticated attackers, with subscriber-level permissions… |