Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.53% | — | Rebelcode Spotlight Social Feeds | 13/2/2023 | 17/6/2026 | The Spotlight Social Feeds WordPress plugin before 1.4.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Crítica (9.1) | 15% | 💥 Exploit | Mooveagency Import XML AND RSS Feeds | 7/7/2021 | 17/6/2026 | Server-side request forgery (SSRF) in the Import XML and RSS Feeds (import-xml-feed) plugin 2.0.1 for WordPress via the data parameter in a moove_read_xml action. | |
| Modificada | Media (6.1) | 1.2% | — | Winwar WP Ebay Product Feeds | 27/12/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter. | |
| Modificada | Alta (8.8) | 0.60% | — | Weblizar Pinterest-feeds | 13/1/2018 | 17/6/2026 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php. | |
| Modificada | Media (6.1) | 0.78% | — | Weblizar Pinterest-feeds | 13/1/2018 | 17/6/2026 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php security parameter. | |
| Modificada | Media (6.1) | 0.95% | — | Weblizar Pinterest-feeds | 13/1/2018 | 17/6/2026 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php PFFREE_Access_Token parameter. | |
| Modificada | Media (6.1) | 0.95% | — | Weblizar Pinterest-feeds | 13/1/2018 | 17/6/2026 | An issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php weblizar_pffree_settings_save_get-users parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Feeds Project Feeds | 3/12/2012 | 16/6/2026 | The Feeds module 7.x-2.x before 7.x-2.0-alpha6 for Drupal, when a field is mapped to the node's author, does not properly check permissions, which allows remote attackers to create arbitrary nodes via a crafted source feed. | |
| Modificada | Media (6.8) | 11% | 💥 Exploit | Affiliatefeeds COM Datafeeds | 19/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomla COM Newsfeeds | 6/5/2010 | 16/6/2026 | SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the feedid parameter in a categories action to index.php. | |
| Modificada | Media (6.4) | 4.9% | 💥 Exploit | Feedburner Feedsmith | 5/10/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and hijack blog feeds via a request to wp-admin/options-general.php that submits parameter values to FeedBurner_FeedSmith_Plugin.php, as demonstrated by the (1) feedburner_url… | |
| Modificada | Media (4.3) | 5.1% | 💥 Exploit | Wp-feedstats Wordpress Plugin | 31/7/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing blog with an XSS sequence in the query string. | |
| Modificada | Media (6.8) | 7.4% | 💥 Exploit | Zebrafeeds | 21/2/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/. | |
| Modificada | Media (5) | 1.4% | — | Chxo Feedsplitter | 6/9/2006 | 16/6/2026 | CHXO Feedsplitter 2006-01-21 allows remote attackers to read the source code of feedsplitter.php via the showsource function. NOTE: this issue is not a vulnerability in standard distributions, but could be an issue if the source has been modified. | |
| Modificada | Alta (7.5) | 1.5% | — | Chxo Feedsplitter | 6/9/2006 | 16/6/2026 | Eval injection vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to execute arbitrary PHP code via (1) the file specified as the value of the format parameter, and possibly (2) the RSS feed. | |
| Modificada | Media (5) | 1.7% | — | Chxo Feedsplitter | 6/9/2006 | 16/6/2026 | Directory traversal vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to read arbitrary XML files via .. (dot dot) sequences in the format parameter with a leading ".", which bypasses a security check. | |
| Modificada | Media (6.8) | 1.3% | — | Chxo Feedsplitter | 6/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to inject arbitrary web script or HTML via the RSS feed. |