Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.15% | — | Cozmoslabs TranslatepressAI | 4/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Stored XSS.This issue affects TranslatePress: from n/a through 3.3.6. | |
| Aplazada | Media (6.8) | 0.24% | — | Loco TranslateAI | 3/10/2026 | 6/10/2026 | The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, allowing users with the translator capability and above to perform Stored Cross-Site Scripting attacks against high privilege users such as administrators. | |
| Aplazada | Media (6.8) | 0.32% | — | Loco TranslateAI | 3/10/2026 | 6/10/2026 | The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the Loco Translate WordPress plugin before 2.8.9's translator capability to retrieve the contents of files of certain types from anywhere on the server, including outside… | |
| Pendiente de análisis | Media (6.9) | 0.12% | — | Ctranslate2AI | 29/9/2026 | 30/9/2026 | CTranslate2 before 4.8.1 contains an out-of-bounds heap read vulnerability in the binary model loader when deserializing string fields without null terminators. Attackers can craft malicious model files to trigger heap memory reads past buffer boundaries, causing crashes or disclosing adjacent heap memory contents. | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Ctranslate2AI | 29/9/2026 | 30/9/2026 | CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution. | |
| Pendiente de análisis | Media (5.3) | 0.27% | — | Wikimedia TranslateAI | 25/9/2026 | 28/9/2026 | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Aplazada | Media (4.8) | 0.15% | — | GtranslateAI | 23/9/2026 | 23/9/2026 | The GTranslate WordPress plugin before 5.0.1 does not remove shortcodes from the content of outgoing emails before expanding them which, in a non-default configuration, allows unauthenticated users to have arbitrary shortcodes registered on the site executed server side. | |
| Aplazada | Alta (7.2) | 0.53% | — | Cozmoslabs TranslatepressAI | 22/9/2026 | 23/9/2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Translation Memory Suggestion Panel (v-html on suggestion.original) in all versions up to, and including, 3.3.5 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Media (5.3) | 0.44% | — | GptranslateAI | 18/9/2026 | 18/9/2026 | The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.34.6 via the enqueue_frontend_scripts. This makes it possible for unauthenticated attackers to extract the… | |
| Aplazada | Media (6.9) | 0.53% | — | LibretranslateAI | 16/9/2026 | 22/9/2026 | LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requirements and abuse ban lists to download files without authentication on protected instances. | |
| Aplazada | Baja (3.5) | 0.14% | — | Translate Wordpress With GtranslateAI | 11/9/2026 | 11/9/2026 | The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor to the site. | |
| Aplazada | Alta (7.2) | 0.82% | — | Cozmoslabs TranslatepressAI | 28/8/2026 | 28/8/2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 9.0% | — | Cozmoslabs TranslatepressAI | 26/8/2026 | 26/8/2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated attackers to extract the raw… | |
| Aplazada | Media (6.4) | 0.31% | — | Cozmoslabs TranslatepressAI | 25/8/2026 | 26/8/2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Approved Comment Body Rendered in Translation Editor Strings Dropdown in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Cozmoslabs TranslatepressAI | 24/8/2026 | 27/8/2026 | Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Cozmoslabs TranslatepressAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. | |
| Aplazada | Alta (7.2) | 0.39% | — | Cozmoslabs TranslatepressAI | 19/8/2026 | 20/8/2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including 3.2.5. The special gettext markers '#!trpst#' and '#!trpen#' are unconditionally rewritten to '<' and '>' by translate_page() in… | |
| Aplazada | Media (6.4) | 0.36% | — | Loco TranslateAI | 16/8/2026 | 20/8/2026 | The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with translator-level access and above, to… | |
| Aplazada | Alta (7.2) | 0.40% | — | Cozmoslabs TranslatepressAI | 6/8/2026 | 12/8/2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.85% | — | Cozmoslabs TranslatepressAI | 5/8/2026 | 12/8/2026 | The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replacing the plugin's internal #!trpst# and #!trpen# marker tokens with… | |
| Aplazada | Alta (8.8) | 0.33% | — | Loco TranslateAI | 16/7/2026 | 16/7/2026 | The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by… | |
| Aplazada | Media (6.9) | 0.28% | — | LibretranslateAI | 29/6/2026 | 29/6/2026 | LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address() function that allows unauthenticated attackers to spoof client IP addresses by injecting arbitrary values into the X-Forwarded-For header without trusted proxy validation. Attackers can bypass… | |
| Analizada | Crítica (9.8) | 1.2% | — | Rapid7 Insightconnect Translate | 25/6/2026 | 29/6/2026 | OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command construction. | |
| Aplazada | Crítica (9.3) | 0.40% | — | GptranslateAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions. | |
| Aplazada | Alta (7.2) | 0.51% | — | GptranslateAI | 13/6/2026 | 23/7/2026 | The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Translation Storage in all versions up to, and including, 2.31 due to insufficient input sanitization and output escaping. This makes it possible… |