Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
153 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.36% | — | Pricing Tables FOR WPAI | 12/5/2026 | 17/6/2026 | The Pricing Tables for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.1.0. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (4.3) | 0.25% | — | Wpmanageninja Ninja TablesAI | 6/5/2026 | 17/6/2026 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in all versions up to, and including, 5.2.6. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Crítica (9.1) | 0.89% | — | Create DB TablesAI | 22/4/2026 | 17/6/2026 | The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.1. The plugin registers admin_post action hooks for creating tables (admin_post_add_table) and deleting tables (admin_post_delete_db_table) without implementing any capability checks via… | |
| Aplazada | Media (4.7) | 0.24% | — | WpdatatablesAI | 20/4/2026 | 17/6/2026 | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.5.0.4. This is due to insufficient input sanitization and output escaping in the prepareCellOutput() method of the LinkWDTColumn,… | |
| Aplazada | Media (6.5) | 0.22% | — | Pluginus Active Products Tables FOR WoocommerceAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 Active Products Tables for WooCommerce profit-products-tables-for-woocommerce allows DOM-Based XSS.This issue affects Active Products Tables for WooCommerce: from n/a through <= 1.0.7. | |
| Aplazada | Alta (7.5) | 0.49% | — | WpdatatablesAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpDataTables wpDataTables wpdatatables allows PHP Local File Inclusion.This issue affects wpDataTables: from n/a through <= 6.5.0.1. | |
| Aplazada | Alta (8.5) | 0.37% | — | Pauple TablesomeAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome tablesome allows Blind SQL Injection.This issue affects Tablesome: from n/a through <= 1.2.3. | |
| Aplazada | Media (4.3) | 0.22% | — | Wpmanageninja Ninja TablesAI | 19/2/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Retrieve Embedded Sensitive Data.This issue affects Ninja Tables: from n/a through <= 5.2.5. | |
| Aplazada | Alta (8.8) | 0.36% | — | Pauple TablesomeAI | 19/2/2026 | 17/6/2026 | The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to unauthorized access of data that leads to privilege escalation due to a missing capability check on the get_table_data() function in versions 0.5.4 to 1.2.1. This makes it possible for authenticated… | |
| Aplazada | Media (6.7) | 0.41% | — | ASC TimetablesAI | 7/2/2026 | 17/6/2026 | aSc TimeTables 2020.11.4 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Subject title field with a large buffer. Attackers can generate a 1000-character buffer and paste it into the Subject title to trigger an application crash and potential instability. | |
| Aplazada | Media (6.7) | 0.29% | — | ASC TimetablesAI | 28/1/2026 | 17/6/2026 | aSc TimeTables 2021.6.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting subject title fields with excessive data. Attackers can generate a 10,000-character buffer and paste it into the subject title to trigger application instability and potential crash. | |
| Aplazada | Media (4.3) | 0.26% | — | Pauple TablesomeAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tablesome: from n/a through <= 1.2.8. | |
| Aplazada | Alta (8.5) | 0.24% | — | Wpmanageninja Ninja TablesAI | 6/1/2026 | 5/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows Blind SQL Injection.This issue affects Ninja Tables: from n/a through <= 5.2.4. | |
| Aplazada | Media (5.4) | 0.21% | — | Pauple TablesomeAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tablesome: from n/a through <= 1.1.35.1. | |
| Aplazada | Media (5) | 0.21% | — | Pauple TablesomeAI | 24/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Essekia Tablesome tablesome allows Retrieve Embedded Sensitive Data.This issue affects Tablesome: from n/a through <= 1.1.35.1. | |
| Aplazada | Alta (7.6) | 0.42% | — | Wpmanageninja Ninja TablesAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ninja Tables ninja-tables allows SQL Injection.This issue affects Ninja Tables: from n/a through <= 5.2.3. | |
| Aplazada | Media (4.3) | 0.22% | — | Pauple TablesomeAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tablesome: from n/a through <= 1.1.34. | |
| Analizada | Media (4.3) | 0.28% | — | Nextcloud Tables | 5/12/2025 | 17/6/2026 | Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4. | |
| Analizada | Media (5.3) | 0.29% | — | Nextcloud Tables | 5/12/2025 | 17/6/2026 | Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric ID) is shared with which groups or users and the respective permissions was not limited to privileged users. This vulnerability is fixed in 0.8.9, 0.9.6, and 1.0.1. | |
| Analizada | Media (4.3) | 0.25% | — | Nextcloud Tables | 5/12/2025 | 25/9/2026 | Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 and 0.9.3. | |
| Aplazada | Media (6.5) | 0.62% | — | Supsystic Data Tables GeneratorAI | 13/11/2025 | 17/6/2026 | The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cleanCache() function in all versions up to, and including, 1.10.45. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Pauple TablesomeAI | 1/11/2025 | 17/6/2026 | The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image_from_external_url() function in all versions up to, and including, 1.1.32. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.40% | — | Essekia Tablesome Table PremiumAI | 22/10/2025 | 5/10/2026 | Missing Authorization vulnerability in Essekia Tablesome Table Premium tablesome-premium allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Tablesome Table Premium: from n/a through <= 1.1.23. | |
| Aplazada | Media (6.5) | 0.53% | — | Nextcloud TablesAI | 16/10/2025 | 17/6/2026 | Nextcloud Tables allows you to create your own tables with individual columns. Prior 0.7.6, 0.8.8, and 0.9.5, when importing a table, a user was able to specify files on the server and when their format is supported by the used PhpSpreadsheet library they would be included and their content leaked to the user. It is… | |
| Analizada | Media (5.5) | 0.85% | — | Sprymedia Datatables | 26/9/2025 | 17/6/2026 | A flaw has been found in DataTables up to 1.10.13. The affected element is an unknown function of the file /examples/resources/examples.php. This manipulation of the argument src causes path traversal. It is possible to initiate the attack remotely. The exploit has been published and may be used. Upgrading to version… |