Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Notfound AD Inserter PROAI16/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Ad Inserter Pro allows Reflected XSS. This issue affects Ad Inserter Pro: from n/a through 2.7.39.
ModificadaAlta (7.5)0.60%—AD Inserter Project AD Inserter20/10/202317/6/2026
The Ad Inserter for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.30 via the ai-debug-processing-fe URL parameter. This can allow unauthenticated attackers to extract sensitive data including installed plugins (present and active), active theme, various plugin…
ModificadaAlta (7.2)17%—AD Inserter Project AD Inserter15/5/202317/6/2026
The Ad Inserter WordPress plugin before 2.7.27 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present
ModificadaMedia (6.1)3.6%—AD Inserter Project AD Inserter4/4/202217/6/2026
The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters
ModificadaMedia (6.1)2.1%—AD Inserter PRO Project AD Inserter PROAD Inserter Project AD Inserter21/2/202217/6/2026
The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escape the html_element_selection parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
ModificadaAlta (8.8)0.98%—AD Inserter Project AD Inserter22/10/201917/6/2026
The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.
ModificadaAlta (8.8)3.6%—AD Inserter Project AD Inserter22/8/201917/6/2026
The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.
ModificadaAlta (7.5)2.0%—AD Inserter Project AD Inserter22/8/201917/6/2026
The ad-inserter plugin before 2.4.20 for WordPress has path traversal.