Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Webfactoryltd Under ConstructionAI3/9/20267/9/2026
Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.
AplazadaAlta (7.5)0.16%—Analytify Under Construction Coming Soon AND Maintenance ModeAI7/4/202617/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.This issue affects Under Construction, Coming Soon & Maintenance Mode: from n/a through 2.1.1.
AplazadaMedia (5.3)0.30%—Seedprod Coming Soon Page Under Construction Maintenance ModeAI19/2/202617/6/2026
Missing Authorization vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <= 6.19.8.
AplazadaMedia (4.3)0.16%—Wp-buy Wp-maintenance-mode-site-under-constructionAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Maintenance Mode & Site Under Construction wp-maintenance-mode-site-under-construction allows Cross Site Request Forgery.This issue affects WP Maintenance Mode & Site Under Construction: from n/a through <= 4.3.
AplazadaMedia (5.9)0.27%—Jonashjalmarsson Really Simple Under Construction PageAI7/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonas Hjalmarsson Really Simple Under Construction Page really-simple-under-construction allows Stored XSS.This issue affects Really Simple Under Construction Page: from n/a through <= 1.4.6.
AplazadaAlta (7.1)0.29%—ROB Scott Eazy-under-constructionAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob Scott Eazy Under Construction eazy-under-construction allows Reflected XSS.This issue affects Eazy Under Construction: from n/a through <= 1.0.
AplazadaAlta (7.1)0.39%—Mojowill Mojo Under ConstructionAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojowill Mojo Under Construction mojo-under-construction allows Reflected XSS.This issue affects Mojo Under Construction: from n/a through <= 1.1.2.
AplazadaMedia (4.3)0.16%—Seedprod Coming Soon Page Under Construction AND Maintenance ModeAI27/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Cross Site Request Forgery.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <= 6.18.9.
AplazadaMedia (5.9)0.27%—Seedprod Coming Soon Page Under Construction Maintenance ModeAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Stored XSS.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <=…
ModificadaMedia (5.3)0.30%—Acurax Under Construction / Maintenance Mode10/6/202417/6/2026
Authentication Bypass by Spoofing vulnerability in Acurax Under Construction / Maintenance Mode from Acurax allows Authentication Bypass.This issue affects Under Construction / Maintenance Mode from Acurax: from n/a through 2.6.
AplazadaMedia (5.9)0.34%—Happykite Ultimate Under ConstructionAI3/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyKite Ultimate Under Construction allows Stored XSS.This issue affects Ultimate Under Construction: from n/a through 1.9.3.
AplazadaMedia (4.3)0.21%—Seedprod Coming Soon Page Under Construction Maintenance ModeAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through 6.15.20.
AplazadaMedia (5.3)0.59%—Dazzler Coming Soon Under Construction Maintenance ModeAI20/3/202417/6/2026
The Coming Soon, Under Construction & Maintenance Mode By Dazzler plugin for WordPress is vulnerable to maintenance mode bypass in all versions up to, and including, 2.1.2. This is due to the plugin relying on the REQUEST_URI to determine if the page being accesses is an admin area. This makes it possible for…
ModificadaMedia (5.3)0.47%—Acurax Under Construction / Maintenance Mode28/2/202417/6/2026
The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6 via the REST API. This makes it possible for unauthenticated attackers to obtain the contents of posts and pages when maintenance mode is active thus…
ModificadaMedia (6.5)0.49%—Acurax Under Construction / Maintenance Mode28/2/202417/6/2026
The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.6 via the 'acx_csma_subscribe_ajax' function. This can allow authenticated attackers to extract sensitive data such as names and email addresses of subscribed…
ModificadaMedia (6.1)0.41%—Acurax Under Construction / Maintenance Mode16/11/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Acurax Under Construction / Maintenance Mode from Acurax plugin <= 2.6 versions.
ModificadaMedia (4.3)0.24%—Webfactoryltd Under Construction9/6/202317/6/2026
The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.96. This is due to missing or incorrect nonce validation on the install_weglot function called via the admin_action_install_weglot action. This makes it possible for unauthenticated attackers to…
ModificadaMedia (4.3)0.25%—Webfactoryltd Under Construction9/6/202317/6/2026
The Under Construction plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.96. This is due to missing or incorrect nonce validation on the dismiss_notice function called via the admin_action_ucp_dismiss_notice action. This makes it possible for unauthenticated attackers…
ModificadaMedia (4.8)0.59%—Dazzlersoftware Coming Soon, Under Construction & Maintenance Mode BY Dazzler1/11/202117/6/2026
The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or escape its description setting when outputting it in the frontend when the Coming Soon mode is enabled, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored…
ModificadaMedia (5.7)0.42%—Catchplugins Catch Scroll Progress BARCatchplugins Catch Sticky MenuCatchplugins Catch Themes Demo ImportCatchplugins Catch Under Construction+618/10/202117/6/2026
Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before…
ModificadaCrítica (9.8)4.3%—Egavilanmedia Under Construction Page With Cpanel24/12/202017/6/2026
EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
ModificadaMedia (5.4)3.8%—Seedprod Coming Soon Page, Under Construction & Maintenance Mode24/6/202017/6/2026
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
ModificadaMedia (4.3)1.0%—Under Construction Baby Pc2m9/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in Under Construction, Baby (UCB) PC2M 0.9.22.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.