Wpo-hr
Wpo-hr NGG Smart Image Search: vulnerabilidades y CVE
Wpo-hr NGG Smart Image Search tiene 5 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses1
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-73185 | Crítica (9.3) | 0.40% | — | 19 ago 2026 | Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. |
| CVE-2025-58027 | Media (6.5) | 0.21% | — | 22 sept 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpo-HR NGG Smart Image Search ngg-smart-image-search allows Stored XSS.This issue affects NGG Smart Image Search:… |
| CVE-2025-52832 | Crítica (9.3) | 0.32% | — | 4 jul 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpo-HR NGG Smart Image Search ngg-smart-image-search allows SQL Injection.This issue affects NGG Smart Image Search:… |
| CVE-2025-47503 | Media (6.5) | 0.26% | — | 7 may 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpo-HR NGG Smart Image Search ngg-smart-image-search allows Stored XSS.This issue affects NGG Smart Image Search:… |
| CVE-2024-13658 | Media (5.4) | 0.30% | — | 12 feb 2025 | The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_nextgen_searchbox' shortcode in all versions up to, and including, 3.2.1 due to insufficient input… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.