Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.32% | — | Wp-statsAI | 14/8/2026 | 14/8/2026 | The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wp-statsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions. | |
| Modificada | Media (4.3) | 0.51% | — | Wp-stats Project Wp-stats | 1/11/2021 | 17/6/2026 | The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads | |
| Modificada | Alta (7.2) | 1.7% | — | Trivetechnology Wp-stats-dashboard | 20/9/2019 | 17/6/2026 | The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection. | |
| Modificada | Alta (7.5) | 1.4% | — | Gamerz Wp-stats | 18/1/2006 | 16/6/2026 | SQL injection vulnerability in wp-stats.php in GaMerZ WP-Stats 2.0 allows remote attackers to execute arbitrary SQL commands via the author parameter. |