Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.22% | — | Wpo365AI | 6/10/2026 | 6/10/2026 | Subscriber Broken Access Control in WPO365 <= 44.1 versions. | |
| Aplazada | Alta (8.8) | 0.25% | — | Wpo365 LoginAI | 23/7/2026 | 24/7/2026 | The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options'… | |
| Aplazada | Media (6.4) | 0.27% | — | Marco VAN Wieren Wpo365 LoginAI | 22/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Marco van Wieren WPO365 wpo365-login allows Server Side Request Forgery.This issue affects WPO365: from n/a through <= 40.0. | |
| Analizada | Media (6.1) | 0.29% | — | Wpo365 Microsoft 365 Graph Mailer | 24/2/2025 | 17/6/2026 | The WPO365 | MICROSOFT 365 GRAPH MAILER plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This is due to insufficient validation on the redirect url supplied via the 'redirect_to' parameter. This makes it possible for unauthenticated attackers to redirect users to… | |
| Modificada | Media (6.1) | 0.34% | — | Wpo365 Mail Integration FOR Office 365 / Outlook | 23/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin <= 1.9.0 versions. | |
| Modificada | Media (6.1) | 0.97% | — | Wpo365 Wordpress + Azure AD / Microsoft Office 365 | 19/11/2021 | 17/6/2026 | The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper… | |
| Modificada | Alta (7.5) | 2.1% | — | Wpo365 Wordpress + Azure AD / Microsoft Office 365 | 2/10/2020 | 17/6/2026 | The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass. |