Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.41% | — | URL Shortener Plugin FOR WordpressAI | 13/12/2025 | 30/9/2026 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ parameter in all versions up to, and including, 3.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.3) | 0.27% | — | URL Shortener Plugin FOR WordpressAI | 24/10/2025 | 17/6/2026 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provided by the API due to a missing capability check on the verifyRequest function in all versions up to, and including, 3.0.7. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (8.6) | 0.35% | — | MD Yeasin UL Haider URL ShortenerAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects URL Shortener: from n/a through <= 3.0.7. | |
| Aplazada | Crítica (9.8) | 0.55% | — | MD Yeasin UL Haider URL Shortener Exact-linksAI | 16/7/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Object Injection.This issue affects URL Shortener: from n/a through <= 3.0.7. | |
| Aplazada | Crítica (9.3) | 0.40% | — | MD Yeasin UL Haider URL Shortener Exact-linksAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows SQL Injection.This issue affects URL Shortener: from n/a through <= 3.0.7. | |
| Aplazada | Media (5.4) | 0.19% | — | MD Yeasin UL Haider URL Shortener Exact LinksAI | 4/7/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Server Side Request Forgery.This issue affects URL Shortener: from n/a through <= 3.0.7. | |
| Aplazada | Media (6.1) | 0.13% | — | WP URL ShortenerAI | 14/6/2025 | 17/6/2026 | The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the 'url_shortener_settings' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web… | |
| Aplazada | Media (4.3) | 0.16% | — | Codehaveli Bitly URL ShortenerAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Codehaveli Bitly URL Shortener codehaveli-bitly-url-shortener allows Cross Site Request Forgery.This issue affects Bitly URL Shortener: from n/a through <= 1.4.1. | |
| Analizada | Baja (3.5) | 0.32% | — | Tahminajannat URL Shortener | Conversion Tracking | AB Testing | Woocommerce | 9/3/2025 | 17/6/2026 | The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in… | |
| Analizada | Media (4.3) | 0.17% | — | Tahminajannat URL Shortener | Conversion Tracking | AB Testing | Woocommerce | 9/3/2025 | 17/6/2026 | The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting customers via CSRF attacks | |
| Analizada | Media (6.1) | 0.32% | — | Tahminajannat URL Shortener | Conversion Tracking | AB Testing | Woocommerce | 6/3/2025 | 17/6/2026 | The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.1) | 0.25% | — | Tahminajannat URL Shortener Conversion Tracking AB Testing WoocommerceAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tahminajannat URL Shortener | Conversion Tracking | AB Testing | WooCommerce easy-broken-link-checker allows Reflected XSS.This issue affects URL Shortener | Conversion Tracking | AB Testing | WooCommerce: from n/a… | |
| Aplazada | Media (6.5) | 0.24% | — | Ironfeet Custom URL ShortenerAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IronFeet Custom URL Shortener custom-url-shorter allows Stored XSS.This issue affects Custom URL Shortener: from n/a through <= 0.3.6. | |
| Modificada | Media (4.8) | 0.40% | — | Mythemeshop URL Shortener | 9/7/2024 | 17/6/2026 | The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Alta (8.8) | 0.52% | — | Mythemeshop URL Shortener | 17/1/2024 | 17/6/2026 | Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0.17. | |
| Modificada | Media (6.1) | 0.61% | — | URL Shortener Project URL Shortener | 27/11/2023 | 17/6/2026 | A vulnerability was found in SourceCodester URL Shortener 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Long URL Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 0.38% | — | Mythemeshop URL Shortener | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MyThemeShop URL Shortener by MyThemeShop plugin <= 1.0.17 versions. |