Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.14% | — | Gbyte Simple XML SitemapAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gregmolnar Simple XML Sitemap simple-xml-sitemap allows Stored XSS.This issue affects Simple XML Sitemap: from n/a through <= 1.3. | |
| Aplazada | Media (5.3) | 0.25% | — | Auctollo Google XML SitemapsAI | 16/12/2025 | 5/10/2026 | Missing Authorization vulnerability in Auctollo Google XML Sitemaps google-sitemap-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google XML Sitemaps: from n/a through <= 4.1.22. | |
| Analizada | Media (5.4) | 0.22% | — | Gbyte Simple XML Sitemap | 26/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple XML sitemap allows Cross-Site Scripting (XSS).This issue affects Simple XML sitemap: from 0.0.0 before 4.2.2. | |
| Aplazada | Alta (8.1) | 0.74% | — | XML Sitemap Google NewsAI | 14/5/2024 | 17/6/2026 | The XML Sitemap & Google News plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.8 via the 'feed' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those… | |
| Modificada | Alta (8.8) | 0.32% | — | Webternsolutions Video XML Sitemap Generator | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tradebooster Video XML Sitemap Generator.This issue affects Video XML Sitemap Generator: from n/a through 1.0.0. | |
| Modificada | Alta (8.8) | 0.30% | — | Wpgrim Dynamic XML Sitemaps Generator FOR Google | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPGrim Dynamic XML Sitemaps Generator for Google plugin <= 1.3.3 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Digitalinspiration Google XML Sitemap FOR Images | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Images plugin <= 2.1.3 versions. | |
| Modificada | Alta (8.8) | 0.32% | — | Digitalinspiration Google XML Sitemap FOR Mobile | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Digitalinspiration Google XML Sitemap FOR Videos | 15/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions. | |
| Modificada | Media (4.8) | 0.59% | — | Google XML Sitemaps Project Google XML Sitemaps | 20/6/2022 | 17/6/2026 | The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | Xmlsitemapgenerator XML Sitemap Generator | 23/5/2022 | 17/6/2026 | The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbitrary value, thus causing XSS via error message or RCE if allow_url_include is turned on. | |
| Modificada | Media (6.1) | 1.5% | — | Bwp-google-xml-sitemaps Project Bwp-google-xml-sitemaps | 14/3/2022 | 17/6/2026 | The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins | |
| Modificada | Alta (8.8) | 0.52% | — | Xml-sitemaps Unlimited Sitemap Generator | 24/11/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specially crafted web page. | |
| Modificada | Media (4.8) | 0.68% | — | Google XML Sitemaps Project Google XML Sitemaps | 9/1/2019 | 17/6/2026 | Cross-site scripting vulnerability in Google XML Sitemaps Version 4.0.9 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.84% | — | Darren OH XML Sitemap | 9/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the additional links interface in XML Sitemap 5.x-1.6, a module for Drupal, allows remote authenticated users, with "administer site configuration" permission, to inject arbitrary web script or HTML via unspecified vectors, related to link path output. |