Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.51% | — | Comments WpdiscuzAI | 3/7/2026 | 6/7/2026 | The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAuthor() function, which interpolates the stored comment_author_url value directly into… | |
| Aplazada | Alta (8.6) | 0.74% | — | Discuz X5AI | 15/6/2026 | 17/6/2026 | Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbitrary code by importing a specially crafted plugin configuration containing path traversal sequences in the directory attribute. Attackers can trigger an exception during… | |
| Aplazada | Media (6.9) | 0.48% | — | Discuz X5AI | 15/6/2026 | 17/6/2026 | Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remote attackers to defeat challenge controls by exploiting limited complexity and predictable character sets in generated CAPTCHA images. Attackers can train a custom optical character recognition model… | |
| Aplazada | Crítica (9.3) | 3.7% | — | Discuz X5AI | 15/6/2026 | 17/6/2026 | Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key between UCenter integration and the database backup API exposed… | |
| Analizada | Media (6.9) | 0.32% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | wpDiscuz before 7.6.47 contains a missing rate limiting vulnerability that allows unauthenticated attackers to subscribe arbitrary email addresses to post notifications by sending POST requests to the wpdAddSubscription handler in class.WpdiscuzHelperAjax.php. Attackers can exploit LIKE wildcard characters in the… | |
| Analizada | Media (5.3) | 0.15% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that allows attackers to trigger unauthorized actions without nonce validation. Attackers can craft malicious requests to enumerate follow relationships and manipulate user follow data by exploiting the missing… | |
| Analizada | Baja (2.1) | 0.16% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability that allows attackers to inject malicious code through unescaped attachment URLs in HTML output by exploiting the WpdiscuzHelperUpload class. Attackers can craft malicious attachment records or filter hooks to inject arbitrary JavaScript into img and… | |
| Modificada | Media (5.1) | 0.22% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators to inject malicious scripts by breaking out of style tags. Attackers with admin access can inject payloads like </style><script>alert(1)</script> in the custom CSS setting to execute arbitrary… | |
| Analizada | Media (6.3) | 0.22% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | wpDiscuz before 7.6.47 contains an email header injection vulnerability that allows attackers to manipulate mail recipients by injecting malicious data into the comment_author_email cookie. Attackers can craft a malicious cookie value that, when processed through urldecode() and passed to wp_mail() functions, enables… | |
| Analizada | Media (6.9) | 0.27% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | wpDiscuz before 7.6.47 contains an information disclosure vulnerability that allows administrators to inadvertently expose OAuth secrets by exporting plugin options as JSON. Attackers can obtain exported files containing plaintext API secrets like fbAppSecret, googleClientSecret, twitterAppSecret, and other social… | |
| Analizada | Media (6.1) | 0.17% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email address by crafting a malicious GET request with a valid HMAC key. Attackers can embed the deletecomments action URL in image tags or other resources to trigger permanent… | |
| Analizada | Media (6.9) | 0.15% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Attackers can set HTTP_CLIENT_IP or HTTP_X_FORWARDED_FOR headers to spoof their IP address and circumvent security controls. | |
| Modificada | Alta (8.7) | 0.98% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitrary files on the device filesystem by supplying directory traversal sequences in the params parameter. Attackers can exploit this… | |
| Analizada | Crítica (9.2) | 0.30% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parameters lack proper quote escaping in SQL queries. Attackers can inject malicious SQL code through email, activation_key, subscription_date, and imported_from parameters to manipulate database queries… | |
| Modificada | Alta (8.8) | 0.27% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attackers can modify client-side authentication state to bypass server-side access controls and gain… | |
| Modificada | Media (5.1) | 0.36% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | Beghelli Sicuro24 SicuroWeb contains a template injection vulnerability that allows attackers to inject arbitrary AngularJS expressions by exploiting improper rendering of untrusted input in AngularJS template contexts. Attackers can inject malicious expressions that are compiled and executed by the AngularJS 1.5.2… | |
| Analizada | Media (5.3) | 0.17% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality that allows authenticated users to inject malicious scripts by submitting comments with unescaped content. Attackers with unfiltered_html capabilities can inject JavaScript directly through comment… | |
| Analizada | Alta (8.7) | 0.52% | — | Gvectors Wpdiscuz | 13/3/2026 | 17/6/2026 | wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigger mass notification emails by exploiting the checkNotificationType() function. Attackers can repeatedly call the wpdiscuz-ajax.php endpoint with arbitrary postId and comment_id parameters to flood… | |
| Aplazada | Media (5.3) | 0.34% | — | Gvectors WpdiscuzAI | 30/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.43. | |
| Aplazada | Media (4.3) | 0.20% | — | Gvectors WpdiscuzAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.33. | |
| Aplazada | Media (5.1) | 0.27% | — | Descreekert WX DiscuzAI | 18/7/2025 | 17/6/2026 | A vulnerability was found in descreekert wx-discuz up to 12bd4745c63ec203cb32119bf77ead4a923bf277. It has been classified as problematic. This affects the function validToken of the file /wx.php. The manipulation of the argument echostr leads to cross site scripting. It is possible to initiate the attack remotely.… | |
| Modificada | Alta (7.3) | 0.35% | — | Gvectors Wpdiscuz | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.10. | |
| Modificada | Alta (8.8) | 0.41% | — | Gvectors Wpdiscuz | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in AdvancedCoding wpDiscuz wpdiscuz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpDiscuz: from n/a through <= 7.6.3. | |
| Analizada | Crítica (9.8) | 0.81% | — | Gvectors Wpdiscuz | 25/10/2024 | 17/6/2026 | The Comments – wpDiscuz plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.6.24. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the… | |
| Analizada | Media (6.1) | 0.60% | — | Gvectors Wpdiscuz | 2/8/2024 | 17/6/2026 | The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.21. This is due to a lack of filtering of HTML tags in comments. This makes it possible for unauthenticated attackers to add HTML such as hyperlinks to comments when rich editing is disabled. |