Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
382 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.52% | — | Ninjaforms Ninja Forms File UploadsAI | 2/10/2026 | 2/10/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used… | |
| Aplazada | Crítica (9.3) | 0.24% | — | Wordpress File UploadAI | 1/10/2026 | 1/10/2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. | |
| Aplazada | Media (6.4) | 0.19% | — | Viable URL Media UploaderAI | 30/9/2026 | 30/9/2026 | The Viable URL Media Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Aplazada | Media (4.3) | 0.15% | — | ALL IN ONE Files UploadAI | 30/9/2026 | 30/9/2026 | The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them. | |
| Aplazada | Alta (8.8) | 0.28% | — | Wpeverest ALL IN ONE Files UploadAI | 30/9/2026 | 30/9/2026 | The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim… | |
| Pendiente de análisis | Media (5.3) | 0.33% | — | Wikimedia UploadwizardAI | 25/9/2026 | 28/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - UploadWizard Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Aplazada | Media (6.4) | 0.25% | — | Auto Upload ImagesAI | 18/9/2026 | 18/9/2026 | The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Multi Uploader FOR Gravity FormsAI | 17/9/2026 | 19/9/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload… | |
| Aplazada | Alta (7.5) | 0.63% | — | Palletsprojects FlaskAIJugmac00 Flask-reuploadedAI | 14/9/2026 | 30/9/2026 | Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension helper for a caller-supplied name before extension_allowed evaluates an AllExcept… | |
| Aplazada | Crítica (9.8) | 0.67% | — | WP Images Upload ON PiclectAI | 12/9/2026 | 14/9/2026 | The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server. | |
| Aplazada | Crítica (9.8) | 1.0% | — | Drag AND Drop File Upload FOR Elementor FormsAI | 10/9/2026 | 10/9/2026 | The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled… | |
| Aplazada | Alta (7.1) | 0.25% | — | Ninjaforms File Uploads ExtensionAI | 3/9/2026 | 5/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| Aplazada | Alta (8.7) | 0.35% | — | Actions Upload-artifactAIActions Download-artifactAI | 24/8/2026 | 24/9/2026 | act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact and DeleteArtifact, accept a caller-supplied workflow_run_backend_id and… | |
| Aplazada | Alta (8.1) | 0.54% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 21/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after stripping characters from it, allowing unauthenticated users to defeat its file type restrictions and execute arbitrary code on the server. | |
| Aplazada | Baja (3.5) | 0.24% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 21/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it as an HTML tag name in front-end output, allowing users with administrator access to inject arbitrary web scripts that execute on any front-end page rendering its upload field. | |
| Aplazada | Media (6.5) | 0.41% | — | Image Uploader FOR WelcartAI | 15/8/2026 | 20/8/2026 | The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (8.8) | 1.0% | — | MaxuploadAI | 15/8/2026 | 20/8/2026 | The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation mismatch in the handle_upload function where extension and MIME checks are… | |
| Aplazada | Alta (8.6) | 0.45% | — | Iptanus File UploadAI | 9/8/2026 | 26/8/2026 | The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wordpress File UploadAI | 6/8/2026 | 12/8/2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. | |
| Aplazada | Crítica (9.1) | 0.49% | — | Codedropz Drag AND Drop Multiple File Upload FOR WoocommerceAI | 6/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy… | |
| Aplazada | Media (5.3) | 0.32% | — | Peprodev Woocommerce Receipt UploaderAI | 6/8/2026 | 26/8/2026 | The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they… | |
| Aplazada | Media (5.3) | 0.16% | — | Peprodev Pepro Bacs Receipt Upload FOR WoocommerceAI | 6/8/2026 | 26/8/2026 | PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated… | |
| Aplazada | Crítica (9.1) | 0.66% | — | Gravity Forms Multi Uploader Multi Uploader FOR Gravity FormsAI | 5/8/2026 | 12/8/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via `wp_ajax_nopriv_gfmu_delete_file`. The nonce… | |
| Aplazada | Crítica (9.6) | 0.20% | — | Ninjaforms File Uploads ExtensionAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. | |
| Aplazada | Media (4.3) | 0.41% | — | MUX Video UploaderAI | 11/7/2026 | 13/7/2026 | The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive data including Mux API… |