Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.44% | — | Kainelabs YouzifyAI | 10/9/2026 | 11/9/2026 | Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Kainelabs YouzifyAI | 18/8/2026 | 20/8/2026 | Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. | |
| Aplazada | Media (6.4) | 0.19% | — | Kainelabs YouzifyAI | 18/4/2026 | 17/6/2026 | The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (4.9) | 0.17% | — | Kainelabs YouzifyAI | 30/12/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Youzify Youzify youzify allows Server Side Request Forgery.This issue affects Youzify: from n/a through <= 1.3.7. | |
| Modificada | Media (6.5) | 0.40% | — | Kainelabs Youzify | 25/1/2025 | 17/6/2026 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the save_addon_key_license() function in all versions up to, and including, 1.3.3. This makes it possible for authenticated… | |
| Modificada | Media (4.3) | 0.34% | — | Kainelabs Youzify | 25/1/2025 | 17/6/2026 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the youzify_offer_banner() function in all versions up to, and including, 1.3.4. This makes it possible for authenticated… | |
| Modificada | Media (4.3) | 0.33% | — | Kainelabs Youzify | 25/1/2025 | 17/6/2026 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_user_review() and delete_review() functions in all versions up to, and including, 1.3.2. This makes it… | |
| Analizada | Alta (8.8) | 0.41% | — | Kainelabs Youzify | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in KaineLabs Youzify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youzify: from n/a through 1.2.6. | |
| Modificada | Media (4.3) | 0.32% | — | Kainelabs Youzify | 10/10/2024 | 17/6/2026 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'delete_attachment' function in all versions up to, and including, 1.3.0. This makes it possible for… | |
| Modificada | Media (5.4) | 0.33% | — | Kainelabs Youzify | 10/10/2024 | 17/6/2026 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user… | |
| Modificada | Alta (8.8) | 0.50% | — | Kainelabs Youzify | 9/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaineLabs Youzify.This issue affects Youzify: from n/a through 1.2.5. | |
| Modificada | Alta (8.8) | 0.50% | — | Kainelabs Youzify | 20/6/2024 | 17/6/2026 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the order_by shortcode attribute in all versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Modificada | Media (6.1) | 0.35% | — | Kainelabs Youzify | 25/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaineLabs Youzify - Buddypress Moderation.This issue affects Youzify - Buddypress Moderation: from n/a through 1.2.5. | |
| Modificada | Media (6.5) | 0.43% | — | Kainelabs Youzify | 21/12/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress.This issue affects Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress: from n/a through 1.2.2. | |
| Modificada | Media (5.4) | 0.47% | — | Kainelabs Youzify | 21/2/2023 | 17/6/2026 | The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Crítica (9.8) | 5.9% | — | Kainelabs Youzify | 1/8/2022 | 17/6/2026 | The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection | |
| Modificada | Media (5.4) | 0.62% | — | Kainelabs Youzify | 2/8/2021 | 17/6/2026 | The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it, which will be executed when viewing the affected user profile.… |