Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.44%—Kainelabs YouzifyAI10/9/202611/9/2026
Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.
AplazadaCrítica (9.8)0.56%—Kainelabs YouzifyAI18/8/202620/8/2026
Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.
AplazadaMedia (6.4)0.19%—Kainelabs YouzifyAI18/4/202617/6/2026
The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
AplazadaMedia (4.9)0.17%—Kainelabs YouzifyAI30/12/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Youzify Youzify youzify allows Server Side Request Forgery.This issue affects Youzify: from n/a through <= 1.3.7.
ModificadaMedia (6.5)0.40%—Kainelabs Youzify25/1/202517/6/2026
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the save_addon_key_license() function in all versions up to, and including, 1.3.3. This makes it possible for authenticated…
ModificadaMedia (4.3)0.34%—Kainelabs Youzify25/1/202517/6/2026
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the youzify_offer_banner() function in all versions up to, and including, 1.3.4. This makes it possible for authenticated…
ModificadaMedia (4.3)0.33%—Kainelabs Youzify25/1/202517/6/2026
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_user_review() and delete_review() functions in all versions up to, and including, 1.3.2. This makes it…
AnalizadaAlta (8.8)0.41%—Kainelabs Youzify1/11/202417/6/2026
Missing Authorization vulnerability in KaineLabs Youzify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youzify: from n/a through 1.2.6.
ModificadaMedia (4.3)0.32%—Kainelabs Youzify10/10/202417/6/2026
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'delete_attachment' function in all versions up to, and including, 1.3.0. This makes it possible for…
ModificadaMedia (5.4)0.33%—Kainelabs Youzify10/10/202417/6/2026
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user…
ModificadaAlta (8.8)0.50%—Kainelabs Youzify9/7/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in KaineLabs Youzify.This issue affects Youzify: from n/a through 1.2.5.
ModificadaAlta (8.8)0.50%—Kainelabs Youzify20/6/202417/6/2026
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the order_by shortcode attribute in all versions up to, and including, 1.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient…
ModificadaMedia (6.1)0.35%—Kainelabs Youzify25/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaineLabs Youzify - Buddypress Moderation.This issue affects Youzify - Buddypress Moderation: from n/a through 1.2.5.
ModificadaMedia (6.5)0.43%—Kainelabs Youzify21/12/202317/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in KaineLabs Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress.This issue affects Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress: from n/a through 1.2.2.
ModificadaMedia (5.4)0.47%—Kainelabs Youzify21/2/202317/6/2026
The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaCrítica (9.8)5.9%—Kainelabs Youzify1/8/202217/6/2026
The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection
ModificadaMedia (5.4)0.62%—Kainelabs Youzify2/8/202117/6/2026
The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin before 1.0.7 does not properly sanitise its Biography field, allowing any authenticated user to set Cross-Site Scripting payloads in it, which will be executed when viewing the affected user profile.…