Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2699▼ 550 respecto a la semana anterior
Críticas / altas1265▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 242 respecto a la semana anterior
–

1101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.6)0.38%—Sarah Giles Dynamic User DirectoryAI7/10/20267/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sarah Giles Dynamic User Directory dynamic-user-directory allows Blind SQL Injection.This issue affects Dynamic User Directory: from n/a through 2.4.
AplazadaMedia (4.3)0.18%—Userprivatefiles User Private FilesAI7/10/20267/10/2026
The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that user's email address, allowing any authenticated user, such as a Subscriber, to obtain the email address of any registered account, including administrators.
AplazadaCrítica (9.3)0.25%—User Subscriptions FormAI6/10/20266/10/2026
Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.
AplazadaAlta (7.1)0.24%—Wedevs WP User FrontendAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in WP User Frontend Pro <= 4.2.13 versions.
AplazadaAlta (8.8)0.32%—WP User ProfilesAI6/10/20266/10/2026
Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions.
AplazadaAlta (7.2)0.32%—Codection Import AND Export Users AND CustomersAI6/10/20266/10/2026
Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions.
AplazadaBaja (2)0.23%—Phpgurukul User Registration Login AND User Management SystemAI6/10/20266/10/2026
A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect…
AplazadaMedia (6.5)0.23%—Ayecode UserswpAI5/10/20266/10/2026
Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.74.
AplazadaMedia (6.5)0.20%—Wpusermanager WP User ManagerAI5/10/20266/10/2026
Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20.
AplazadaMedia (5.3)0.19%—Userprivatefiles User Private FilesAI4/10/20266/10/2026
The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.
AplazadaMedia (4.3)0.18%—Wedevs WP User FrontendAI2/10/20262/10/2026
The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted…
AplazadaAlta (7.5)0.37%—Comelit Multi User GatewayAI1/10/20265/10/2026
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface, sensitive device configuration data - including the Remote Configuration Password - can be read in cleartext by a…
AplazadaAlta (8.8)0.25%—Comelit Multi User GatewayAI1/10/20265/10/2026
Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated user level can invoke this function to overwrite the installer (administrator) account password.
AplazadaMedia (6.5)0.13%—Plugin-planet User Submitted PostsAI30/9/202630/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS. This issue affects User Submitted Posts: from n/a through 20260810.
AplazadaAlta (7.5)0.30%—Codection Import AND Export Users AND CustomersAI30/9/202630/9/2026
Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.
AplazadaMedia (5.3)0.23%—Wpexperts NEW User ApproveAI30/9/202630/9/2026
The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is unconfigured, allowing unauthenticated attackers to retrieve personal data (id, username, email address and registration date) of registered users.
AplazadaMedia (5.3)0.22%—User FrontendAI30/9/202630/9/2026
The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled. The created account receives the site's default role.
AplazadaAlta (7.4)0.25%—Wedevs User FrontendAI30/9/202630/9/2026
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a…
Pendiente de análisisAlta (7.5)0.25%—Wikimedia UserpageviewtrackerAI29/9/20261/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wikimedia Foundation Mediawiki - UserPageViewTracker Extension allows SQL Injection. This issue affects Mediawiki - UserPageViewTracker Extension: from * before 1.46.1, 1.45.5, 1.43.10.
AplazadaAlta (7.2)0.26%—User Profile BuilderAI25/9/202625/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.4)0.20%—Codeselling User Profile BuilderAI25/9/202625/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (8.8)0.33%—Codection Import AND Export Users AND CustomersAI23/9/202624/9/2026
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape…
AplazadaMedia (6.5)0.47%—Wedevs WP User FrontendAI23/9/202623/9/2026
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
AplazadaMedia (5.3)0.25%—Wedevs WP User FrontendAI23/9/202623/9/2026
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
AplazadaMedia (6.5)0.34%—Wedevs WP User FrontendAI23/9/202623/9/2026
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.