Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
296 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.34% | — | Xtendify WofficeAI | 6/10/2026 | 6/10/2026 | Subscriber SQL Injection in Woffice <= 5.4.35 versions. | |
| Aplazada | Alta (7.2) | 0.31% | — | ExtendifyAI | 1/10/2026 | 3/10/2026 | The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.4) | 0.16% | — | Nextendweb Smart Slider 3AI | 30/9/2026 | 30/9/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Alta (8.6) | 0.53% | — | Studiowombat Advanced Product Fields Extended FOR WoocommerceAI | 10/9/2026 | 11/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended for WooCommerce: from n/a through 3.1.6. | |
| Aplazada | Alta (8.1) | 0.37% | 💥 PoC | Acfextended Advanced Custom Fields ExtendedAI | 2/9/2026 | 3/9/2026 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not restrict the role submitted through its front-end user forms to the roles the form actually offers, and its safeguard against privileged roles is incomplete, allowing unauthenticated visitors to register an account with elevated capabilities… | |
| Aplazada | Alta (8.1) | 0.23% | — | Advancedcustomfields Advanced Custom Fields ExtendedAI | 2/9/2026 | 3/9/2026 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a… | |
| Aplazada | Media (6.9) | 0.41% | — | Extendthemes Kubio AI Website BuilderAI | 31/8/2026 | 8/9/2026 | Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1. | |
| Aplazada | Media (4.3) | 0.25% | — | Acfextended ACF ExtendedAI | 28/8/2026 | 28/8/2026 | Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions. | |
| Aplazada | Media (6.4) | 0.32% | — | Nextendweb Smart Slider 3AI | 28/8/2026 | 28/8/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Pendiente de análisis | Alta (7) | 0.24% | — | Sonicwall NetextenderAI | 25/8/2026 | 28/8/2026 | The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths. | |
| Pendiente de análisis | Alta (8.8) | 0.50% | — | Sonicwall NetextenderAI | 25/8/2026 | 31/8/2026 | A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to write arbitrary file as root. | |
| Aplazada | Media (4.3) | 0.41% | — | Nextendweb Smart Slider 3AI | 13/7/2026 | 14/7/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles and full content excerpts of private, draft,… | |
| Aplazada | Media (5.3) | 0.29% | — | Xtendify WofficeAI | 1/7/2026 | 1/7/2026 | Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33. | |
| Aplazada | Media (4.3) | 0.12% | — | Extendthemes Skyline WPAI | 17/6/2026 | 1/10/2026 | Cross-Site request forgery (CSRF) vulnerability in Extend Themes Skyline WP allows Cross Site Request Forgery. This issue affects Skyline WP: from n/a through 1.0.10. | |
| Aplazada | Alta (8.6) | 0.64% | — | Contact Form Extender FOR DiviAI | 15/6/2026 | 17/6/2026 | Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi – Save Entries, File Upload & Country Code Field <= 1.0.6 versions. | |
| Aplazada | Media (4.9) | 0.84% | — | Nextendweb Smart Slider 3AI | 6/6/2026 | 23/7/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can… | |
| Aplazada | Crítica (9.8) | 0.87% | 💥 PoC | Acfextended Advanced Custom Fields ExtendedAI | 28/5/2026 | 21/7/2026 | The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with… | |
| Aplazada | Media (6.5) | 0.38% | — | Acfextended Advanced Custom Fields ExtendedAI | 12/5/2026 | 7/10/2026 | The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for… | |
| Aplazada | Media (5.5) | 0.56% | — | 1024bit Extend-deepAI | 20/4/2026 | 17/6/2026 | A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the file index.js. This manipulation of the argument __proto__ causes improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Crítica (9.3) | 0.97% | — | Nextendweb Smart Slider 3AI | 9/4/2026 | 17/6/2026 | Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system that allows unauthenticated attackers to execute arbitrary code and commands. Attackers can trigger pre-authentication remote shell execution via HTTP headers,… | |
| Aplazada | Media (5.4) | 0.32% | — | Nextendweb Smart Slider 3AI | 7/4/2026 | 24/7/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all versions up to, and including, 3.5.1.33. The display_admin_ajax() method does not call checkForCap() (which requires… | |
| Aplazada | Media (6.5) | 0.22% | — | Extendthemes Kubio AI Page BuilderAI | 31/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder allows Stored XSS.This issue affects Kubio AI Page Builder: from n/a through 2.7.0. | |
| Aplazada | Media (6.5) | 0.41% | 💥 PoC | Nextendweb Smart Slider 3AI | 27/3/2026 | 17/6/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can… | |
| Aplazada | Alta (8.8) | 0.52% | — | Wpextended WP ExtendedAI | 22/3/2026 | 17/6/2026 | The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the `isDashboardOrProfileRequest()` method in the Menu Editor module using an insecure `strpos()` check against `$_SERVER['REQUEST_URI']` to… | |
| Aplazada | Alta (7.1) | 0.19% | — | Hugh Mungus Visitor Maps Extended Referer FieldAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hugh Mungus Visitor Maps Extended Referer Field visitor-maps-extended-referer-field allows Reflected XSS.This issue affects Visitor Maps Extended Referer Field: from n/a through <= 1.2.6. |