Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3071▲ 536 respecto a la semana anterior
Críticas / altas1456▲ 257 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)384▲ 177 respecto a la semana anterior
1079 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.1) | — | — | If-so Dynamic ContentAI | 1/10/2026 | 1/10/2026 | The If-So Dynamic Content WordPress plugin before 1.10.2 does not sanitize a conversion name before storing it, nor escape it when rendering the analytics page, allowing users with editor-level access to store JavaScript that executes in the session of a higher-privileged user who views that page. | |
| Aplazada | Media (4.7) | — | — | IF SO Dynamic ContentAI | 1/10/2026 | 1/10/2026 | The If-So Dynamic Content WordPress plugin before 1.10.2 does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served as HTML, allowing attackers to execute arbitrary JavaScript in the browser of a visitor who opens a crafted link. | |
| Aplazada | Media (6.5) | 0.30% | — | MCP Content Manager LiteAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Keywordrush Content EGGAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | If-so Dynamic Content PersonalizationAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions. | |
| Aplazada | Media (6.8) | 0.24% | — | Keywordrush Content EGGAI | 30/9/2026 | 30/9/2026 | The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary… | |
| Pendiente de análisis | Media (6.5) | 0.76% | — | Plone APP DexterityAIPlone APP ContenttypesAI | 22/9/2026 | 26/9/2026 | plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, and 5.0.0, and plone.app.contenttypes versions through 3.0.11, 4.0.0 through 4.0.9, and 5.0.0… | |
| Pendiente de análisis | Media (5.5) | 0.25% | — | Adobe Content CredentialsAI | 22/9/2026 | 23/9/2026 | CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a… | |
| Pendiente de análisis | Media (4.3) | 1.0% | — | CAI Content CredentialsAI | 22/9/2026 | 22/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim… | |
| En análisis | Media (6.5) | 1.3% | — | CAI Content CredentialsAI | 22/9/2026 | 26/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must… | |
| En análisis | Media (4.3) | 1.0% | — | CAI Content CredentialsAI | 22/9/2026 | 22/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue requires user interaction in that a victim… | |
| En análisis | Media (5.5) | 0.24% | — | CAI Content CredentialsAI | 22/9/2026 | 26/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim… | |
| En análisis | Alta (7.5) | 0.90% | — | CAI Content CredentialsAI | 22/9/2026 | 23/9/2026 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user… | |
| En análisis | Alta (7.5) | 0.65% | — | CAI Content CredentialsAI | 22/9/2026 | 22/9/2026 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. | |
| Aplazada | Alta (8.8) | 0.57% | — | BM Content BuilderAI | 22/9/2026 | 22/9/2026 | The BM Content Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ux_cb_remove_layout_ajax() and ux_cb_tools_export_ajax() functions in all versions up to, and excluding, 3.17.1. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (6.5) | 0.53% | — | BM Content BuilderAI | 22/9/2026 | 22/9/2026 | The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the ux_cb_page_customize_save_layout_ajax() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the… | |
| Aplazada | Alta (7.8) | 0.14% | — | Oracle Webcenter ContentAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Content executes to… | |
| Aplazada | Alta (7.7) | 0.41% | — | Contentful MCP ServerAIContentful MCP ToolsAI | 15/9/2026 | 30/9/2026 | Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-to-space-migration/exportSpace.ts and… | |
| Aplazada | Crítica (9.4) | 0.67% | — | Regularlabs Conditional ContentAI | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 - Conditional Content Pro accepts inline PHP Condition Rules in article syntax. In affected versions, the PHP is passed to the Conditions evaluator without checking who authored the… | |
| Aplazada | Media (6.9) | 0.37% | — | Regularlabs Advanced Module ManagerAIRegularlabs Conditional ContentAIRegularlabs Content TemplaterAIRegularlabs RereplacerAI+1 | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla - The Conditions editor creates a default Condition Set name from the item to which the set is… | |
| Aplazada | Media (5.3) | 0.27% | — | Typo3 Content ConsentAI | 14/9/2026 | 22/9/2026 | An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to display various content elements, leading to an insecure direct object reference… | |
| Aplazada | Media (6.8) | 0.28% | — | Content MaskAI | 9/9/2026 | 9/9/2026 | The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post before outputting it in the pages it generates, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks against any user viewing or previewing the affected page.… | |
| Pendiente de análisis | Media (6.5) | 0.39% | — | SAP WEB DispatcherAISAP Internet Communication ManagerAISAP Content ServerAI | 8/9/2026 | 8/9/2026 | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Content Management SystemAI | 6/9/2026 | 8/9/2026 | A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (6.8) | 0.43% | — | Wpjoli Joli Table OF ContentsAI | 5/9/2026 | 8/9/2026 | The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views… |