Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2634▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.17% | — | Etoilewebdesign Ultimate FAQAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions. | |
| Aplazada | Media (6.4) | 0.38% | — | Ultimate FAQ AccordionAI | 9/4/2026 | 17/6/2026 | The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all versions up to, and including, 2.4.7. This is due to the plugin calling html_entity_decode() on post_content during rendering in the set_display_variables() function (View.FAQ.class.php, line 746), which… | |
| Aplazada | Media (4.3) | 0.12% | — | Rustaurius Ultimate FAQAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate FAQ ultimate-faqs allows Cross Site Request Forgery.This issue affects Ultimate FAQ: from n/a through <= 2.4.3. | |
| Modificada | Media (5.7) | 0.43% | — | Etoilewebdesign Ultimate FAQ | 24/1/2022 | 17/6/2026 | The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_page AJAX actions, available to any authenticated users. As a result, any users, with a role as low as Subscriber could create FAQ and FAQ questions | |
| Modificada | Media (6.1) | 2.2% | — | Etoilewebdesign Ultimate FAQ | 16/1/2020 | 17/6/2026 | The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php. | |
| Modificada | Media (6.1) | 1.8% | — | Etoilewebdesign Ultimate FAQ | 7/10/2019 | 17/6/2026 | Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection. | |
| Modificada | Alta (7.5) | 3.5% | — | Etoilewebdesign Ultimate FAQ | 7/10/2019 | 17/6/2026 | Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows unauthenticated options import. | |
| Modificada | Media (6.1) | 0.93% | — | Etoilewebdesign Ultimate FAQ | 27/8/2019 | 17/6/2026 | The ultimate-faqs plugin before 1.8.22 for WordPress has XSS. |