Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Kaizencoders URL ShortifyAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions. | |
| Aplazada | Media (5.5) | 0.25% | — | Kaizencoders URL ShortifyAI | 19/2/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in KaizenCoders URL Shortify url-shortify allows Server Side Request Forgery.This issue affects URL Shortify: from n/a through <= 1.12.3. | |
| Aplazada | Media (4.7) | 0.59% | — | Kaizencoders URL ShortifyAI | 18/2/2026 | 17/6/2026 | The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites via… | |
| Aplazada | Alta (7.1) | 0.17% | — | Kaizencoders URL ShortifyAI | 15/12/2025 | 17/6/2026 | The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.1) | 0.17% | — | Kaizencoders URL ShortifyAI | 15/12/2025 | 17/6/2026 | The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in the page, leading to a reflected cross site scripting, which could be used against high-privilege users such as admins. | |
| Aplazada | Media (5.9) | 0.41% | — | Kaizencoders URL ShortifyAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders URL Shortify url-shortify allows Stored XSS.This issue affects URL Shortify: from n/a through <= 1.10.5.1. | |
| Modificada | Media (4.8) | 0.41% | — | Kaizencoders URL Shortify | 6/11/2023 | 17/6/2026 | The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.82% | — | Kaizencoders URL Shortify | 11/9/2023 | 17/6/2026 | The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link. | |
| Modificada | Media (4.8) | 0.56% | — | Kaizencoders URL Shortify | 10/7/2023 | 17/6/2026 | The URL Shortify WordPress plugin before 1.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (4.3) | 0.45% | — | Kaizencoders URL Shortify | 29/11/2021 | 17/6/2026 | The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF attack. |