Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3072▲ 552 respecto a la semana anterior
Críticas / altas1458▲ 273 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.54% | — | Keywordrush Content EGGAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. | |
| Aplazada | Media (6.8) | 0.24% | — | Keywordrush Content EGGAI | 30/9/2026 | 30/9/2026 | The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they select, and switches to the preset author's identity before creating the resulting post, allowing users with contributor-level access and above to store arbitrary… | |
| Aplazada | Alta (8.1) | 1.2% | — | Keywordrush Content EGGAI | 5/8/2026 | 12/8/2026 | The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in versions up to and including 11.3.0. This is due to insufficient validation of the 'img_file' field within the cegg_data post metadata: the value passes only through… | |
| Aplazada | Alta (7.2) | 0.47% | — | Keywordrush Content EGGAI | 14/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in keywordrush Content Egg content-egg allows Object Injection.This issue affects Content Egg: from n/a through <= 7.0.0. | |
| Modificada | Alta (8.8) | 0.32% | — | Keywordrush Content EGG | 3/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Keywordrush Content Egg plugin <= 5.4.0 on WordPress. | |
| Modificada | Media (6.1) | 0.80% | — | Keywordrush Content EGG | 2/5/2022 | 17/6/2026 | The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in an attribute in the Autoblogging admin dashboard, leading to a Reflected Cross-Site Scripting |