Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3340▲ 436 respecto a la semana anterior
Críticas / altas1491▲ 179 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)592▲ 119 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.48%—EstatikAI30/9/202630/9/2026
Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.
AplazadaAlta (7.6)0.38%—EstatikAI30/9/202630/9/2026
Administrator SQL Injection in Estatik <= 4.3.5 versions.
AplazadaAlta (7.1)0.25%—Estatik Real Estate PluginAI19/9/202621/9/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting.
AplazadaAlta (7.1)0.25%—EstatikAI2/9/20264/9/2026
Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.
AplazadaBaja (3.7)0.14%—Estatik Real Estate PluginAI12/8/202626/8/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later uses to address the message sent by its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To on sites where the form is…
AplazadaAlta (7.5)0.23%—Estatik Real Estate PluginAI7/8/202626/8/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the…
AplazadaMedia (5.3)0.30%—Estatik Real Estate PluginAI6/8/202626/8/2026
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its property request form, allowing unauthenticated users to send emails to arbitrary recipients with arbitrary subject, body and Reply-To, effectively using the site as a…
AplazadaMedia (6.5)0.20%—EstatikAI27/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatik Estatik estatik allows DOM-Based XSS.This issue affects Estatik: from n/a through <= 4.3.1.
ModificadaAlta (8.8)0.54%—Estatik Mortgage Calculator16/5/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Estatik Mortgage Calculator Estatik estatik-mortgage-calculator allows PHP Local File Inclusion.This issue affects Mortgage Calculator Estatik: from n/a through <= 2.0.12.
AplazadaAlta (7.5)0.49%—Estatik-mortgage-calculatorAI25/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatik Mortgage Calculator Estatik estatik-mortgage-calculator allows Stored XSS.This issue affects Mortgage Calculator Estatik: from n/a through <= 2.0.12.
AplazadaAlta (7.5)0.61%—EstatikAI25/2/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estatik Estatik estatik allows PHP Local File Inclusion.This issue affects Estatik: from n/a through <= 4.3.0.
AplazadaMedia (6.1)0.44%—Estatik Mortgage CalculatorAI7/1/202517/6/2026
The Estatik Mortgage Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'color' parameter in all versions up to, and including, 2.0.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaMedia (6.4)0.35%—Estatik Mortgage CalculatorAI10/12/202417/6/2026
The Property Hive Mortgage Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘price’ parameter in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…
ModificadaMedia (6.1)0.42%—Estatik15/1/202417/6/2026
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaCrítica (9.8)0.93%—Estatik15/1/202417/6/2026
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog
ModificadaMedia (6.5)0.61%—Estatik15/1/202417/6/2026
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting any of the site's options to 1, which could be used to break sites and lead to DoS when certain options are reset
ModificadaMedia (6.1)0.39%—Estatik Mortgage Calculator27/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions.
ModificadaMedia (6.1)0.39%—Estatik Mortgage Calculator6/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions.
ModificadaMedia (6.5)1.1%—Estatik16/9/201917/6/2026
The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin-ajax.php.
ModificadaAlta (7.5)1.9%—Estatik16/9/201917/6/2026
The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admin/admin-ajax.php.