Kaizencoders
Kaizencoders URL Shortify: vulnerabilidades y CVE
Kaizencoders URL Shortify tiene 10 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-73362 | Alta (7.1) | 0.25% | — | 18 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions. |
| CVE-2026-25385 | Media (5.5) | 0.25% | — | 19 feb 2026 | Server-Side Request Forgery (SSRF) vulnerability in KaizenCoders URL Shortify url-shortify allows Server Side Request Forgery.This issue affects URL Shortify: from n/a through <= 1.12.3. |
| CVE-2026-1277 | Media (4.7) | 0.59% | — | 18 feb 2026 | The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This… |
| CVE-2025-13355 | Alta (7.1) | 0.17% | — | 15 dic 2025 | The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege… |
| CVE-2025-12684 | Alta (7.1) | 0.17% | — | 15 dic 2025 | The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in the page, leading to a reflected cross site scripting, which could be used against high-privilege… |
| CVE-2025-32134 | Media (5.9) | 0.41% | — | 4 abr 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders URL Shortify url-shortify allows Stored XSS.This issue affects URL Shortify: from n/a through <=… |
| CVE-2023-5605 | Media (4.8) | 0.41% | — | 6 nov 2023 | The URL Shortify WordPress plugin before 1.7.9.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2023-4294 | Media (6.1) | 0.82% | — | 11 sept 2023 | The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin… |
| CVE-2023-3129 | Media (4.8) | 0.56% | — | 10 jul 2023 | The URL Shortify WordPress plugin before 1.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2021-24749 | Media (4.3) | 0.45% | — | 29 nov 2021 | The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, which could allow attackers to make a logged in admin delete arbitrary link and group via a CSRF… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.