Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.34% | — | Xtendify WofficeAI | 6/10/2026 | 6/10/2026 | Subscriber SQL Injection in Woffice <= 5.4.35 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Xtendify WofficeAI | 1/7/2026 | 1/7/2026 | Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33. | |
| Aplazada | Media (6.5) | 0.31% | — | Wofficeio Woffice CoreAI | 8/1/2026 | 5/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woffice Core: from n/a through <= 5.4.30. | |
| Aplazada | Alta (7.1) | 0.22% | — | Xtendify WofficeAI | 8/1/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice allows Reflected XSS.This issue affects Woffice: from n/a through <= 5.4.30. | |
| Aplazada | Media (5.3) | 0.32% | — | Wofficeio Woffice CoreAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woffice Core: from n/a through <= 5.4.30. | |
| Analizada | Alta (7.5) | 0.91% | — | Xtendify Woffice | 2/8/2025 | 17/6/2026 | The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the woffice_file_manager_delete() function in all versions up to, and including, 5.4.26. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete… | |
| Analizada | Baja (2.1) | 0.76% | — | Yijiusmile Kkfileviewofficeedit | 14/7/2025 | 17/6/2026 | A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. It has been classified as critical. This affects the function deleteFile of the file /deleteFile. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack… | |
| Analizada | Baja (2.1) | 0.49% | — | Yijiusmile Kkfileviewofficeedit | 14/7/2025 | 17/6/2026 | A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this issue is the function fileUpload of the file /fileUpload. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.60% | — | Yijiusmile Kkfileviewofficeedit | 14/7/2025 | 17/6/2026 | A vulnerability has been found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this vulnerability is the function onlinePreview of the file /onlinePreview. The manipulation of the argument url leads to path traversal. The attack can be launched… | |
| Analizada | Baja (2.1) | 0.52% | — | Yijiusmile Kkfileviewofficeedit | 14/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. Affected is the function Download of the file /download. The manipulation of the argument url leads to path traversal. It is possible to launch the attack remotely. The… | |
| Analizada | Crítica (9.8) | 0.66% | — | Xtendify Woffice | 4/4/2025 | 17/6/2026 | The Woffice CRM theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.21. This is due to a misconfiguration of excluded roles during registration. This makes it possible for unauthenticated attackers to register with an Administrator role if a custom login form is being… | |
| Analizada | Media (5.4) | 0.14% | — | Xtendify Woffice | 4/4/2025 | 17/6/2026 | The Woffice Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.4.21. This is due to missing or incorrect nonce validation on the 'woffice_handle_user_approval_actions' function. This makes it possible for unauthenticated attackers to approve registration for… | |
| Analizada | Alta (8.8) | 0.85% | — | Xtendify Woffice | 4/4/2025 | 17/6/2026 | The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'saveFeaturedImage' function in all versions up to, and including, 5.4.21. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Modificada | Crítica (9.8) | 0.66% | — | Xtendify Woffice | 16/12/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WofficeIO Woffice woffice allows Authentication Bypass.This issue affects Woffice: from n/a through <= 5.4.14. | |
| Analizada | Crítica (9.8) | 0.50% | — | Xtendify Woffice | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WofficeIO Woffice Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woffice Core: from n/a through 5.4.8. | |
| Modificada | Crítica (9.8) | 0.62% | — | Xtendify Woffice | 13/8/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10. | |
| Modificada | Media (6.1) | 0.33% | — | Xtendify Woffice | 4/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.8. | |
| Analizada | Media (6.1) | 0.29% | — | Xtendify Woffice | 4/7/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8. |