Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

382 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.52%—Ninjaforms Ninja Forms File UploadsAI2/10/20262/10/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used…
AplazadaCrítica (9.3)0.24%—Wordpress File UploadAI1/10/20261/10/2026
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
AplazadaMedia (6.4)0.19%—Viable URL Media UploaderAI30/9/202630/9/2026
The Viable URL Media Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject…
AplazadaMedia (4.3)0.15%—ALL IN ONE Files UploadAI30/9/202630/9/2026
The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.
AplazadaAlta (8.8)0.28%—Wpeverest ALL IN ONE Files UploadAI30/9/202630/9/2026
The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim…
Pendiente de análisisMedia (5.3)0.33%—Wikimedia UploadwizardAI25/9/202628/9/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - UploadWizard Extension: from * before 1.46.1, 1.45.5, 1.43.10.
AplazadaMedia (6.4)0.25%—Auto Upload ImagesAI18/9/202618/9/2026
The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations…
AplazadaCrítica (9.8)1.1%—Multi Uploader FOR Gravity FormsAI17/9/202619/9/2026
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload…
AplazadaAlta (7.5)0.63%—Palletsprojects FlaskAIJugmac00 Flask-reuploadedAI14/9/202630/9/2026
Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension helper for a caller-supplied name before extension_allowed evaluates an AllExcept…
AplazadaCrítica (9.8)0.67%—WP Images Upload ON PiclectAI12/9/202614/9/2026
The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.
AplazadaCrítica (9.8)1.0%—Drag AND Drop File Upload FOR Elementor FormsAI10/9/202610/9/2026
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled…
AplazadaAlta (7.1)0.25%—Ninjaforms File Uploads ExtensionAI3/9/20265/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
AplazadaAlta (8.7)0.35%—Actions Upload-artifactAIActions Download-artifactAI24/8/202624/9/2026
act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact and DeleteArtifact, accept a caller-supplied workflow_run_backend_id and…
AplazadaAlta (8.1)0.54%—Drag AND Drop Multiple File Upload FOR Contact Form 7AI21/8/202626/8/2026
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server.
AplazadaBaja (3.5)0.24%—Drag AND Drop Multiple File Upload FOR Contact Form 7AI21/8/202626/8/2026
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field.
AplazadaMedia (6.5)0.41%—Image Uploader FOR WelcartAI15/8/202620/8/2026
The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaAlta (8.8)1.0%—MaxuploadAI15/8/202620/8/2026
The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation mismatch in the handle_upload function where extension and MIME checks are…
AplazadaAlta (8.6)0.45%—Iptanus File UploadAI9/8/202626/8/2026
The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.
AplazadaCrítica (9.3)0.40%—Wordpress File UploadAI6/8/202612/8/2026
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.
AplazadaCrítica (9.1)0.49%—Codedropz Drag AND Drop Multiple File Upload FOR WoocommerceAI6/8/202626/8/2026
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy…
AplazadaMedia (5.3)0.32%—Peprodev Woocommerce Receipt UploaderAI6/8/202626/8/2026
The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they…
AplazadaMedia (5.3)0.16%—Peprodev Pepro Bacs Receipt Upload FOR WoocommerceAI6/8/202626/8/2026
PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated…
AplazadaCrítica (9.1)0.66%—Gravity Forms Multi Uploader Multi Uploader FOR Gravity FormsAI5/8/202612/8/2026
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via `wp_ajax_nopriv_gfmu_delete_file`. The nonce…
AplazadaCrítica (9.6)0.20%—Ninjaforms File Uploads ExtensionAI23/7/202623/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
AplazadaMedia (4.3)0.41%—MUX Video UploaderAI11/7/202613/7/2026
The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive data including Mux API…