Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

632 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.6)0.28%—Ultimatemember Ultimate MemberAI1/10/20261/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1.
AplazadaMedia (5.3)0.20%—Smackcoders WP Ultimate CSV ImporterAI1/10/20261/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate CSV Importer: from n/a through 9.1.
AplazadaCrítica (9.8)0.58%—Ultimate MultisiteAI1/10/20261/10/2026
The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible…
AplazadaMedia (6.5)0.16%—Supsystic Ultimate MapsAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.
AplazadaAlta (7.2)0.40%—Themefic Ultimate Addons FOR Contact Form 7AI30/9/202630/9/2026
Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions.
AplazadaAlta (7.1)0.18%—Supsystic Ultimate MapsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
AplazadaMedia (6.5)0.16%—Contact Form 7AIThemefic Ultimate Addons FOR Contact Form 7AI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.
AplazadaMedia (6.5)0.17%—Etoilewebdesign Ultimate FAQAI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.
AplazadaAlta (8.1)0.36%—Wpmet WP Ultimate ReviewAI22/9/202622/9/2026
The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated…
AplazadaAlta (8.8)0.51%—Ultimatemember Ultimate MemberAI19/9/202621/9/2026
The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that…
AplazadaAlta (7.5)0.26%—Wpswings Ultimate Gift Cards FOR WoocommerceAI10/9/202610/9/2026
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption…
AplazadaAlta (7.5)0.21%—Ultimate Gift CardsAI10/9/202610/9/2026
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to obtain store credit worth more than they paid.
AplazadaMedia (6.5)0.30%—Ultimate Gift CardsAI9/9/20269/9/2026
The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not verify that the user redeeming a gift card is its intended recipient, allowing any authenticated user, such as a subscriber, to redeem gift cards belonging to other users, zeroing their balance and crediting the value to themselves. In…
AplazadaMedia (5.3)0.29%—Supsystic Ultimate MapsAI3/9/20265/9/2026
Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3.
AplazadaMedia (5.3)0.31%—Wpswings Ultimate Gift Cards FOR WoocommerceAI2/9/20262/9/2026
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
AplazadaMedia (5.3)0.23%—Ultimatemember Ultimate MemberAI2/9/20263/9/2026
The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, before returning profile activity to unauthenticated visitors, allowing them to read the content of comments still awaiting moderation.
AplazadaMedia (6.8)0.29%—Codeinwp Ultimate Before After Image Slider AND GalleryAI2/9/20263/9/2026
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including…
AplazadaMedia (6.8)0.29%—Ultimate Before After Image Slider GalleryAI2/9/20263/9/2026
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an…
AplazadaMedia (5.3)0.41%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal.
AplazadaAlta (8.9)0.43%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict MIME verification and GD binary raster…
AplazadaAlta (8.6)0.42%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual escaping, allowing injection of malicious…
AplazadaMedia (5.1)0.39%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or core.admin). An authenticated user could submit…
AplazadaMedia (5.1)0.39%—Joomshaper Helix UltimateAI31/8/202631/8/2026
Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized to edit the article ID passed in the request, but did not verify whether the specified image path (src) belonged to that article. On…
AplazadaMedia (4.1)0.31%—Smackcoders WP Ultimate CSV ImporterAI29/8/202631/8/2026
The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.
AplazadaAlta (8.1)0.23%—Ultimatemember Ultimate MemberAI28/8/202628/8/2026
The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register…