Canto
Canto: vulnerabilidades y CVE
Canto tiene 10 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses2
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-6441 | Media (4.3) | 0.36% | — | 17 abr 2026 | The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due to the absence of any capability check or nonce verification in the updateOptions() function,… |
| CVE-2026-3335 | Media (5.3) | 1.3% | — | 21 mar 2026 | The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via the `/wp-content/plugins/canto/includes/lib/copy-media.php` file. This is due to the file being… |
| CVE-2024-4936 | Crítica (9.8) | 1.0% | — | 14 jun 2024 | The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthenticated attackers to include remote files… |
| CVE-2024-25096 | Crítica (9.8) | 0.68% | — | 3 abr 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7. |
| CVE-2023-3452 | Crítica (9.8) | 7.0% | — | 12 ago 2023 | The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote… |
| CVE-2022-40305 | Crítica (9.8) | 1.5% | — | 9 sept 2022 | A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified other impact via the server parameter to… |
| CVE-2020-28978 | Media (5.3) | 15% | — | 30 nov 2020 | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/tree.php?subdomain=SSRF. |
| CVE-2020-28977 | Media (5.3) | 15% | — | 30 nov 2020 | The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/get.php?subdomain=SSRF. |
| CVE-2020-28976 | Media (5.3) | 28% | — | 30 nov 2020 | The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make a request to any internal and external server via /includes/lib/detail.php?subdomain=SSRF. |
| CVE-2020-24063 | Alta (7.2) | 1.5% | — | 10 nov 2020 | The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF. |