Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
59 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.27% | — | Openclaw WhatsappAI | 26/9/2026 | 29/9/2026 | @openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the originating sender's owner status, so the owner-only tool boundary is not enforced. An admitted non-owner sender able to steer the tool can request a forced login and receive a new QR… | |
| Analizada | Alta (7.1) | 0.21% | — | Verygoodplugins Whatsapp MCP Server | 20/7/2026 | 18/8/2026 | WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp messages. Prior to version 0.2.1, the `whatsapp-bridge` HTTP API listens on `127.0.0.1:8080` without authentication and without Host header validation, and the `/api/send` endpoint accepts an absolute… | |
| Aplazada | Baja (2) | 0.27% | — | Lharries Whatsapp-mcpAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the function SendMessageRequest of the file whatsapp-bridge/main.go of the component Send API Endpoint. This manipulation of the argument mediaPath causes path traversal. The exploit has been publicly disclosed and may be… | |
| Analizada | Media (4.3) | 0.46% | — | 1/5/2026 | 17/6/2026 | Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device, including triggering OS-controlled custom… | ||
| Analizada | Media (6.5) | 0.53% | — | 1/5/2026 | 17/6/2026 | An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the application as one type of file but run as an executable when opened. We have not seen evidence of exploitation in the… | ||
| Aplazada | Media (6.5) | 0.22% | — | Elfsight Whatsapp Chat CCAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elfsight Elfsight WhatsApp Chat CC elfsight-whatsapp-chat allows DOM-Based XSS.This issue affects Elfsight WhatsApp Chat CC: from n/a through <= 1.2.0. | |
| Analizada | Media (5.4) | 0.17% | — | WhatsappWhatsapp Business | 18/11/2025 | 17/6/2026 | Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.25.23.82, and WhatsApp for Mac v2.25.23.83 could have allowed a user to trigger processing of media content from an arbitrary URL on another user’s device. We have not seen evidence of exploitation in… | |
| Aplazada | Alta (7.1) | 0.24% | — | Themewarriors Whatsapp Chat FOR Wordpress AND WoocommerceAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeWarriors WhatsApp Chat for WordPress and WooCommerce tw-whatsapp-chat-rotator allows Reflected XSS.This issue affects WhatsApp Chat for WordPress and WooCommerce: from n/a through <= 1.2.1. | |
| Analizada | Media (5.4) | 4.3% | ⚠ Explotación activa | WhatsappWhatsapp Business | 29/8/2025 | 17/6/2026 | Incomplete authorization of linked device synchronization messages in WhatsApp for iOS prior to v2.25.21.73, WhatsApp Business for iOS v2.25.21.78, and WhatsApp for Mac v2.25.21.78 could have allowed an unrelated user to trigger processing of content from an arbitrary URL on a target’s device. We assess that this… | |
| Aplazada | Alta (7.5) | 0.55% | — | Indie Plugins Whatsapp Click TO ChatAI | 19/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Indie_Plugins WhatsApp Click to Chat Plugin for WordPress wpt-whatsapp.This issue affects WhatsApp Click to Chat Plugin for WordPress: from n/a through <= 2.2.12. | |
| Modificada | Media (6.7) | 21% | — | 5/4/2025 | 17/6/2026 | A spoofing issue in WhatsApp for Windows prior to version 2.2450.6 displayed attachments according to their MIME type but selected the file opening handler based on the attachment’s filename extension. A maliciously crafted mismatch could have caused the recipient to inadvertently execute arbitrary code rather than… | ||
| Aplazada | Baja (3.5) | 0.26% | — | Whatsapp Cloud ServiceAI | 20/3/2025 | 17/6/2026 | The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for installation of Android malware associated with BIGPRETZEL. | |
| Aplazada | Alta (7.1) | 0.17% | — | Rishi ON Page SEO Whatsapp Chat ButtonAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rishi On Page SEO + Whatsapp Chat Button ops-robots-txt allows Stored XSS.This issue affects On Page SEO + Whatsapp Chat Button: from n/a through <= 2.0.0. | |
| Aplazada | Media (6.1) | 0.35% | — | Whatsapp Click TO ChatAI | 9/1/2025 | 17/6/2026 | The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts_code' parameter in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (5.3) | 14% | — | Secreto31126 Whatsapp-api-js | 12/9/2024 | 17/6/2026 | whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload validation using the WhatsAppAPI.verifyRequestSignature and expect false when the signature is valid. Incorrect Access Control, anyone using the post or verifyRequestSignature methods to handle… | |
| Modificada | Media (5.4) | 0.34% | — | Firecask Whatsapp Share Button | 20/10/2023 | 17/6/2026 | The WhatsApp Share Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'whatsapp' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (5) | 0.23% | — | 4/10/2023 | 17/6/2026 | A race condition in an event subsystem led to a heap use-after-free issue in established audio/video calls that could have resulted in app termination or unexpected control flow with very low probability. | ||
| Modificada | Media (5.6) | 0.28% | — | 4/10/2023 | 17/6/2026 | A race condition in a network transport subsystem led to a heap use-after-free issue in established or unsilenced incoming audio/video calls that could have resulted in app termination or unexpected control flow with very low probability. | ||
| Modificada | Alta (7.8) | 0.53% | — | 23/9/2022 | 17/6/2026 | An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file. | ||
| Analizada | Crítica (9.8) | 2.4% | — | WhatsappWhatsapp Business | 22/9/2022 | 17/6/2026 | An integer overflow in WhatsApp could result in remote code execution in an established video call. | |
| Modificada | Media (4.8) | 0.59% | — | Miniorange Login With OTP Over Sms, Email, Whatsapp AND Google Authenticator | 27/6/2022 | 17/6/2026 | The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed | |
| Modificada | Media (6.5) | 1.4% | — | 23/3/2022 | 17/6/2026 | Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages. | ||
| Modificada | Crítica (9.1) | 1.1% | — | WhatsappWhatsapp Business | 2/2/2022 | 17/6/2026 | A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business for iOS 2.21.230.7, and WhatsApp Desktop v2.2145.0 could have allowed an out-of-bounds heap read if a user sent a malformed RTCP packet… | |
| Modificada | Crítica (9.8) | 1.2% | — | 4/1/2022 | 17/6/2026 | The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior to v2.21.230, WhatsApp for KaiOS prior to v2.2143, WhatsApp Desktop prior to v2.2146 could have allowed an out-of-bounds write if a user… | ||
| Modificada | Crítica (9.8) | 1.5% | — | WhatsappWhatsapp Business | 7/12/2021 | 17/6/2026 | A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowed an out-of-bounds write if a user sent a malicious image. |