Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.41% | — | Videowhisper Picture GalleryAI | 23/7/2026 | 23/7/2026 | Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. | |
| Aplazada | Media (5.3) | 0.25% | — | Videowhisper Paid Videochat Turnkey SiteAI | 26/5/2026 | 24/7/2026 | Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Videochat Turnkey Site: from n/a through 7.3.23. | |
| Aplazada | Alta (7.2) | 0.41% | — | Videowhisper Broadcast Live VideoAI | 25/5/2026 | 24/7/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows Code Injection. This issue affects Broadcast Live Video: from n/a before 7.1.3. | |
| Aplazada | Alta (8.8) | 0.38% | — | Videowhisper Paid Videochat Turnkey SiteAI | 7/3/2026 | 17/6/2026 | The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.3.20. This is due to videowhisper_register_form() function not restricting user roles that can be set during registration. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Videowhisper Paid Videochat Turnkey SiteAI | 27/10/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Remote Code Inclusion.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.3.23. | |
| Analizada | Media (4.3) | 0.17% | — | Videowhisper Micropayments | 28/6/2025 | 17/6/2026 | The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Wallet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation on the adminOptions() function. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.18% | — | Videowhisper Live Streaming Integration | 19/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Cross Site Request Forgery.This issue affects Broadcast Live Video: from n/a through <= 6.2.4. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Videowhisper Paid Videochat Turnkey SiteAI | 17/4/2025 | 17/6/2026 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Password Recovery Exploitation.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.3.11. | |
| Aplazada | Media (6.5) | 0.21% | — | Videowhisper MicropaymentsAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in videowhisper MicroPayments paid-membership allows Stored XSS.This issue affects MicroPayments: from n/a through <= 2.9.29. | |
| Aplazada | Alta (7.1) | 0.37% | — | Videowhisper Video Share VODAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper Video Share VOD video-share-vod allows Reflected XSS.This issue affects Video Share VOD: from n/a through <= 2.7.9. | |
| Aplazada | Alta (7.1) | 0.37% | — | Videowhisper Picture GalleryAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper Picture Gallery picture-gallery allows Reflected XSS.This issue affects Picture Gallery: from n/a through <= 1.6.3. | |
| Aplazada | Alta (7.1) | 0.37% | — | Videowhisper MicropaymentsAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper MicroPayments paid-membership allows Reflected XSS.This issue affects MicroPayments: from n/a through <= 3.2.4. | |
| Aplazada | Alta (7.5) | 0.59% | — | Videowhisper Broadcast Live VideoAI | 25/2/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Path Traversal.This issue affects Broadcast Live Video: from n/a through <= 6.2. | |
| Aplazada | Alta (8.6) | 0.54% | — | Videowhisper Broadcast Live VideoAI | 25/2/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Path Traversal.This issue affects Broadcast Live Video: from n/a through <= 6.2. | |
| Aplazada | Alta (8.6) | 0.55% | — | Videowhisper Paid Videochat Turnkey SiteAI | 18/2/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Path Traversal.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.2.12. | |
| Analizada | Media (5.4) | 0.22% | — | Videowhisper Live Streaming Integration | 23/1/2025 | 17/6/2026 | The Broadcast Live Video – Live Streaming : HTML5, WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_hls' shortcode in all versions up to, and including, 6.1.9 due to insufficient input sanitization and output escaping on user supplied attributes.… | |
| Analizada | Media (5.4) | 0.31% | — | Videowhisper Picture Gallery | 22/1/2025 | 17/6/2026 | The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_pictures' shortcode in all versions up to, and including, 1.5.19 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Aplazada | Media (6.4) | 0.35% | — | Videowhisper Rate Star Review VoteAI | 18/1/2025 | 17/6/2026 | The Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_reviews' shortcode in all versions up to, and including, 1.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Aplazada | Media (6.4) | 0.34% | — | Videowhisper Video Share VODAI | 18/1/2025 | 17/6/2026 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_videos' shortcode in all versions up to, and including, 2.6.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (6.4) | 0.28% | — | Videowhisper MicropaymentsAI | 18/1/2025 | 17/6/2026 | The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_content_upload_guest' shortcode in all versions up to, and including, 2.9.29 due to insufficient input sanitization and output… | |
| Aplazada | Media (6.4) | 0.28% | — | Videowhisper Video Share VODAI | 18/12/2024 | 17/6/2026 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_player_html' shortcode in all versions up to, and including, 2.6.30 due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Aplazada | Alta (7.5) | 0.45% | — | Videowhisper Contact FormsAIVideowhisper Live SupportAIVideowhisper CRMAIVideowhisper Video MessagesAI+1 | 17/10/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in videowhisper Contact Forms, Live Support, CRM, Video Messages live-support-tickets allows Retrieve Embedded Sensitive Data.This issue affects Contact Forms, Live Support, CRM, Video Messages: from n/a through <= 1.10.2. | |
| Modificada | Media (5.4) | 0.25% | — | Videowhisper Picture Gallery | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VideoWhisper Picture Gallery allows Stored XSS.This issue affects Picture Gallery: from n/a through 1.5.11. | |
| Modificada | Crítica (9.8) | 1.3% | — | Videowhisper Live Streaming Integration | 3/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Streaming Integration allows OS Command Injection.This issue affects VideoWhisper Live Streaming Integration: from n/a through 5.5.15. | |
| Modificada | Media (6.1) | 0.32% | — | Videowhisper Rate Star Review | 8/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VideoWhisper Rate Star Review – AJAX Reviews for Content, with Star Ratings allows Reflected XSS.This issue affects Rate Star Review – AJAX Reviews for Content, with Star Ratings: from n/a through 1.5.1. |