Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Notfound AD Inserter PROAI | 16/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ad Inserter Pro allows Reflected XSS. This issue affects Ad Inserter Pro: from n/a through 2.7.39. | |
| Modificada | Alta (7.5) | 0.60% | — | AD Inserter Project AD Inserter | 20/10/2023 | 17/6/2026 | The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow unauthenticated attackers to extract sensitive data including installed plugins (present and active), active theme, various plugin… | |
| Modificada | Alta (7.2) | 17% | — | AD Inserter Project AD Inserter | 15/5/2023 | 17/6/2026 | The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present | |
| Modificada | Media (6.1) | 3.6% | — | AD Inserter Project AD Inserter | 4/4/2022 | 17/6/2026 | The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters | |
| Modificada | Media (6.1) | 2.1% | — | AD Inserter PRO Project AD Inserter PROAD Inserter Project AD Inserter | 21/2/2022 | 17/6/2026 | The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escape the html_element_selection parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (8.8) | 0.98% | — | AD Inserter Project AD Inserter | 22/10/2019 | 17/6/2026 | The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php. | |
| Modificada | Alta (8.8) | 3.6% | — | AD Inserter Project AD Inserter | 22/8/2019 | 17/6/2026 | The ad-inserter plugin before 2.4.22 for WordPress has remote code execution. | |
| Modificada | Alta (7.5) | 2.0% | — | AD Inserter Project AD Inserter | 22/8/2019 | 17/6/2026 | The ad-inserter plugin before 2.4.20 for WordPress has path traversal. |