Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—Wp-property-hive PropertyhiveAI17/9/202617/9/2026
Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.
AplazadaAlta (7.1)0.25%—Wp-property-hive PropertyhiveAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3.
AplazadaMedia (4.9)0.48%—Wp-property-hive Houzez Property FeedAI2/7/20262/7/2026
The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.5.46 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the prepare_items() method of the…
AplazadaAlta (7.1)0.25%—Wp-property-hive PropertyhiveAI27/5/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows DOM-Based XSS.This issue affects PropertyHive: from n/a through <= 2.2.2.
AplazadaAlta (7.5)0.27%—Wp-property-hive PropertyhiveAI18/12/202517/6/2026
Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12.
AplazadaMedia (6.5)0.21%—Wp-property-hive PropertyhiveAI3/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Stored XSS.This issue affects PropertyHive: from n/a through <= 2.1.5.
AplazadaCrítica (9.3)1.9%—Wp-propertyAI5/8/202516/6/2026
WP-Property plugin for WordPress up to and including version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution.
AplazadaMedia (6.5)0.32%—Wp-property-hive PropertyhiveAI16/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Stored XSS.This issue affects PropertyHive: from n/a through <= 2.1.2.
AplazadaAlta (7.5)0.60%—Wp-property-hive Houzez Property FeedAI1/4/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Property Hive Houzez Property Feed houzez-property-feed allows Path Traversal.This issue affects Houzez Property Feed: from n/a through <= 2.5.4.
AnalizadaMedia (5.4)0.16%—Wp-property-hive Houzez Property Feed12/2/202517/6/2026
The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due to missing or incorrect nonce validation on the "deleteexport" action. This makes it possible for unauthenticated attackers to delete property feed exports via a forged…
AnalizadaMedia (6.1)0.62%—Wp-property-hive Propertyhive8/1/202517/6/2026
The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AnalizadaMedia (4.3)0.39%—Wp-property-hive Propertyhive1/11/202417/6/2026
Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9.
AnalizadaMedia (6.5)0.35%—Wp-property-hive Propertyhive17/9/202417/6/2026
The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation on the 'save_account_details' function. This makes it possible for unauthenticated attackers to edit the name, email address, and password…
ModificadaMedia (5.4)0.26%—Wp-property-hive Propertyhive8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.13.
ModificadaMedia (5.4)0.33%—Wp-property-hive Propertyhive6/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10.
ModificadaMedia (4.3)0.61%—Wp-property-hive Propertyhive2/5/202417/6/2026
The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts
ModificadaAlta (8.8)0.38%—Wp-property-hive Propertyhive11/4/202417/6/2026
Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9.
ModificadaMedia (6.1)0.40%—Wp-property-hive Propertyhive27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Reflected XSS.This issue affects PropertyHive: from n/a through 2.0.8.
ModificadaMedia (6.5)0.32%—Wp-property-hive Propertyhive26/3/202417/6/2026
Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.
ModificadaCrítica (9.8)0.52%—Wp-property-hive Propertyhive12/2/202417/6/2026
Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5.
ModificadaMedia (6.1)0.38%—Wp-property-hive Propertyhive15/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions.
ModificadaMedia (6.1)0.38%—Wp-property-hive Propertyhive7/4/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.46 versions.
ModificadaMedia (6.1)1.6%—Wp-property-hive Propertyhive31/1/201817/6/2026
The PropertyHive plugin before 1.4.15 for WordPress has XSS via the body parameter to includes/admin/views/html-preview-applicant-matches-email.php.