Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Wp-property-hive PropertyhiveAI | 17/9/2026 | 17/9/2026 | Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wp-property-hive PropertyhiveAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3. | |
| Aplazada | Media (4.9) | 0.48% | — | Wp-property-hive Houzez Property FeedAI | 2/7/2026 | 2/7/2026 | The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.5.46 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the prepare_items() method of the… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wp-property-hive PropertyhiveAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows DOM-Based XSS.This issue affects PropertyHive: from n/a through <= 2.2.2. | |
| Aplazada | Alta (7.5) | 0.27% | — | Wp-property-hive PropertyhiveAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12. | |
| Aplazada | Media (6.5) | 0.21% | — | Wp-property-hive PropertyhiveAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Stored XSS.This issue affects PropertyHive: from n/a through <= 2.1.5. | |
| Aplazada | Crítica (9.3) | 1.9% | — | Wp-propertyAI | 5/8/2025 | 16/6/2026 | WP-Property plugin for WordPress up to and including version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution. | |
| Aplazada | Media (6.5) | 0.32% | — | Wp-property-hive PropertyhiveAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Stored XSS.This issue affects PropertyHive: from n/a through <= 2.1.2. | |
| Aplazada | Alta (7.5) | 0.60% | — | Wp-property-hive Houzez Property FeedAI | 1/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Property Hive Houzez Property Feed houzez-property-feed allows Path Traversal.This issue affects Houzez Property Feed: from n/a through <= 2.5.4. | |
| Analizada | Media (5.4) | 0.16% | — | Wp-property-hive Houzez Property Feed | 12/2/2025 | 17/6/2026 | The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due to missing or incorrect nonce validation on the "deleteexport" action. This makes it possible for unauthenticated attackers to delete property feed exports via a forged… | |
| Analizada | Media (6.1) | 0.62% | — | Wp-property-hive Propertyhive | 8/1/2025 | 17/6/2026 | The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (4.3) | 0.39% | — | Wp-property-hive Propertyhive | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9. | |
| Analizada | Media (6.5) | 0.35% | — | Wp-property-hive Propertyhive | 17/9/2024 | 17/6/2026 | The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation on the 'save_account_details' function. This makes it possible for unauthenticated attackers to edit the name, email address, and password… | |
| Modificada | Media (5.4) | 0.26% | — | Wp-property-hive Propertyhive | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.13. | |
| Modificada | Media (5.4) | 0.33% | — | Wp-property-hive Propertyhive | 6/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10. | |
| Modificada | Media (4.3) | 0.61% | — | Wp-property-hive Propertyhive | 2/5/2024 | 17/6/2026 | The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts | |
| Modificada | Alta (8.8) | 0.38% | — | Wp-property-hive Propertyhive | 11/4/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9. | |
| Modificada | Media (6.1) | 0.40% | — | Wp-property-hive Propertyhive | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Reflected XSS.This issue affects PropertyHive: from n/a through 2.0.8. | |
| Modificada | Media (6.5) | 0.32% | — | Wp-property-hive Propertyhive | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6. | |
| Modificada | Crítica (9.8) | 0.52% | — | Wp-property-hive Propertyhive | 12/2/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5. | |
| Modificada | Media (6.1) | 0.38% | — | Wp-property-hive Propertyhive | 15/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Wp-property-hive Propertyhive | 7/4/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.46 versions. | |
| Modificada | Media (6.1) | 1.6% | — | Wp-property-hive Propertyhive | 31/1/2018 | 17/6/2026 | The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php. |