Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.33% | — | Wikimedia UploadwizardAI | 25/9/2026 | 28/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - UploadWizard Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Aplazada | Baja (3.3) | 0.19% | — | Openzeppelin WizardAIOpenzeppelin Wizard CairoAIOpenzeppelin Wizard StellarAIOpenzeppelin Wizard StylusAI | 14/9/2026 | 30/9/2026 | OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6.2, and @openzeppelin/wizard-stylus 0.3.1, the setInfo code path prints… | |
| Aplazada | Media (6.8) | 0.43% | — | Custom Menu Wizard WidgetAI | 12/9/2026 | 14/9/2026 | The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed. | |
| Aplazada | Media (5.3) | 0.30% | — | Webwizards B2bkingAI | 6/9/2026 | 8/9/2026 | The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer… | |
| Aplazada | Media (5.4) | 0.23% | — | Webwizards B2bkingAI | 18/8/2026 | 21/8/2026 | Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a through 5.2.30. | |
| Aplazada | Alta (8.8) | 0.64% | — | Openzeppelin Contracts WizardAIHardhatAI | 6/8/2026 | 14/9/2026 | OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `opts.name` (ERC20/ERC721) and `opts.uri` (ERC1155) directly into TypeScript string… | |
| Aplazada | Baja (1.9) | 0.15% | — | Minitool Partition WizardAI | 12/7/2026 | 13/7/2026 | A weakness has been identified in MiniTool Partition Wizard up to 13.6. The affected element is an unknown function in the library pwdrvio.sys of the component Signed Kernel Driver. This manipulation causes improper access controls. The attack can only be executed locally. The exploit has been made available to the… | |
| Aplazada | Alta (8.2) | 0.17% | — | Child Theme WizardAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions. | |
| Aplazada | Media (4.9) | 0.33% | — | Webwizards B2bkingAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a before 5.2.10. | |
| Aplazada | Media (6.5) | 0.26% | — | Niaj Morshed LC WizardAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Niaj Morshed LC Wizard ghl-wizard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LC Wizard: from n/a through <= 2.1.1. | |
| Aplazada | Alta (7.1) | 0.25% | — | Soflyy WP Wizard CloakAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soflyy WP Wizard Cloak wp-wizard-cloak allows Reflected XSS.This issue affects WP Wizard Cloak: from n/a through <= 1.0.1. | |
| Aplazada | Alta (8.4) | 0.18% | — | Port Forwarding WizardAI | 30/1/2026 | 17/6/2026 | Port Forwarding Wizard 4.8.0 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code through a long request in the Register feature. Attackers can craft a malicious payload with an egg tag and overwrite SEH handlers to potentially execute shellcode on vulnerable Windows systems. | |
| Aplazada | Alta (8.6) | 0.92% | — | Audio Conversion WizardAI | 13/1/2026 | 17/6/2026 | Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory with a specially crafted registration code. Attackers can generate a payload that overwrites the application's memory stack, potentially enabling remote code execution through a… | |
| Analizada | Media (6.1) | 0.24% | — | Wikimedia Mediawiki-extensions-uploadwizard | 8/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki - UploadWizard extension allows Cross-Site Scripting (XSS).This issue affects MediaWiki - UploadWizard extension: 1.45, 1.44, 1.43, 1.39. | |
| Aplazada | Alta (8.1) | 0.31% | — | LC WizardAI | 7/11/2025 | 17/6/2026 | The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wizard/inc/wp_user.php file in versions 1.2.10 to 1.3.0. This makes it possible for unauthenticated attackers to create new user accounts with the administrator role when the PRO functionality is… | |
| Aplazada | Media (6.9) | 0.45% | — | Wikimedia Mediawiki Uploadwizard ExtensionAI | 18/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - UploadWizard Extension allows Stored XSS.This issue affects Mediawiki - UploadWizard Extension: from master before 1.39. | |
| Aplazada | Media (4.3) | 0.13% | — | MpwizardAI | 3/10/2025 | 17/6/2026 | The MPWizard – Create Mercado Pago Payment Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation in the '/includes/admin/class-mpwizard-table.php' file. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.21% | — | Webwizards MarketkingAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebWizards MarketKing marketking-multivendor-marketplace-for-woocommerce allows Stored XSS.This issue affects MarketKing: from n/a through <= 2.0.92. | |
| Aplazada | Media (6.5) | 0.21% | — | Niaj Morshed Ghl-wizardAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Niaj Morshed LC Wizard ghl-wizard allows Stored XSS.This issue affects LC Wizard: from n/a through <= 2.2.4. | |
| Aplazada | Alta (7.9) | 0.16% | — | Promotion Management WizardAI | 13/5/2025 | 17/6/2026 | Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwise be restricted.This has High impact on Confidentiality with Low impact on Integrity and Availability of the application. | |
| Aplazada | Alta (7.1) | 0.30% | — | Wrenchpilot Essay Wizard WpcresAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wrenchpilot Essay Wizard (wpCRES) essay-wizard-wpcres allows Reflected XSS.This issue affects Essay Wizard (wpCRES): from n/a through <= 1.0.6.4. | |
| Aplazada | Alta (8.6) | 0.19% | — | Configuration Wizard 2AI | 24/1/2025 | 17/6/2026 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in Configuration Wizard 2 installer can lead to privilege escalation and arbitrary code execution when running the impacted installer. | |
| Aplazada | Media (6.4) | 0.27% | — | Solar Wizard LiteAI | 7/1/2025 | 17/6/2026 | The Solar Wizard Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'solar_wizard' shortcode in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.7) | 0.48% | — | ScanwizardAI | 12/12/2024 | 17/6/2026 | Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "Edit Disclaimer Text" function of the configuration menu is vulnerable to stored XSS. Only the users Poweruser and Admin can use this function which is available at… | |
| Aplazada | Media (4.7) | 0.55% | — | ScanwizardAI | 12/12/2024 | 17/6/2026 | Due to missing input sanitization, an attacker can perform cross-site-scripting attacks and run arbitrary Javascript in the browser of other users. The "Edit Disclaimer Text" function of the configuration menu is vulnerable to stored XSS. Only the users Poweruser and Admin can use this function which is available at… |