Bootstrapped
Bootstrapped Visual Link Preview: vulnerabilidades y CVE
Bootstrapped Visual Link Preview tiene 6 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-54821 | Alta (7.4) | 0.28% | — | 25 jun 2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. |
| CVE-2026-48878 | Media (6.5) | 0.37% | — | 15 jun 2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions. |
| CVE-2026-39670 | Media (6) | 0.21% | — | 8 abr 2026 | Server-Side Request Forgery (SSRF) vulnerability in Brecht Visual Link Preview visual-link-preview allows Server Side Request Forgery.This issue affects Visual Link Preview: from n/a through <= 2.3.0. |
| CVE-2026-24984 | Media (6.5) | 0.33% | — | 3 feb 2026 | Missing Authorization vulnerability in Brecht Visual Link Preview visual-link-preview allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visual Link Preview: from n/a through <=… |
| CVE-2025-11987 | Media (6.4) | 0.22% | — | 5 nov 2025 | The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-preview shortcode in versions up to, and including, 2.2.7 due to insufficient input sanitization and… |
| CVE-2021-24635 | Media (5.4) | 0.64% | — | 20 sept 2021 | The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as… |