Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2617▼ 302 respecto a la semana anterior
Críticas / altas1346▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.27% | — | WpgraphqlAI | 23/9/2026 | 23/9/2026 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status… | |
| Aplazada | Media (6.5) | 0.34% | — | Wpgraphql Smart CacheAI | 19/9/2026 | 21/9/2026 | The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases before a site's own frontend registers them. | |
| Pendiente de análisis | Media (6.9) | 0.45% | — | WpgraphqlAI | 31/7/2026 | 10/9/2026 | WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in… | |
| Aplazada | Alta (7.5) | 0.32% | — | WpgraphqlAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions. | |
| Aplazada | Alta (8.7) | 0.45% | — | WpgraphqlAI | 15/5/2026 | 17/6/2026 | WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by sending batched GraphQL queries with duplicated fields. Attackers can send POST requests to the GraphQL endpoint with amplified field duplication payloads to trigger server… | |
| Aplazada | Media (5.4) | 0.09% | — | WpgraphqlAI | 7/5/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGraphQL: from n/a through 2.5.3. | |
| Aplazada | Media (4.3) | 0.29% | — | WpgraphqlAI | 24/3/2026 | 17/6/2026 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.10.0, an authorization flaw in updateComment allows an authenticated low-privileged user (including a custom role with zero capabilities) to change moderation status of their own comment (for example to APPROVE) without the moderate_comments… | |
| Aplazada | Alta (7.7) | 1.4% | — | WpgraphqlAI | 26/2/2026 | 17/6/2026 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository contains a GitHub Actions workflow (`release.yml`) vulnerable to OS command injection through direct use of `${{ github.event.pull_request.body }}` inside a `run:` shell block. When a pull request from… | |
| Modificada | Media (5.3) | 0.72% | — | Wpengine Wpgraphql | 16/1/2024 | 17/6/2026 | The WPGraphQL WooCommerce WordPress plugin before 0.12.4 does not prevent unauthenticated attackers from enumerating a shop's coupon codes and values via GraphQL. | |
| Modificada | Media (6.5) | 0.45% | — | Wpengine Wpgraphql | 13/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5. | |
| Modificada | Media (5.3) | 1.8% | — | Wpgraphql | 9/5/2022 | 17/6/2026 | The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site. | |
| Modificada | Media (5.3) | 19% | — | Wpengine Wpgraphql | 10/6/2019 | 17/6/2026 | The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled. | |
| Modificada | Crítica (9.1) | 36% | — | Wpengine Wpgraphql | 10/6/2019 | 17/6/2026 | An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username. | |
| Modificada | Crítica (9.8) | 47% | — | Wpengine Wpgraphql | 10/6/2019 | 17/6/2026 | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation. |