Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2598▼ 321 respecto a la semana anterior
Críticas / altas1342▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

485 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (6.1)0.22%—Wpfront Notification BARAI3/10/20263/10/2026
The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.1. This is due to the debug-log output path (write_debug_logs) reflecting the raw value of $_SERVER['REQUEST_URI'] through vprintf() directly inside a <script> block emitted on…
AplazadaMedia (4.3)0.18%—Wedevs WP User FrontendAI2/10/20262/10/2026
The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted…
AplazadaMedia (5.3)0.22%—User FrontendAI30/9/202630/9/2026
The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled. The created account receives the site's default role.
AplazadaAlta (7.4)0.25%—Wedevs User FrontendAI30/9/202630/9/2026
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a…
AplazadaAlta (7.2)0.25%—Frontend Post Submission Manager LiteAI30/9/202630/9/2026
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes…
AplazadaMedia (6.5)0.47%—Wedevs WP User FrontendAI23/9/202623/9/2026
Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.
AplazadaMedia (5.3)0.25%—Wedevs WP User FrontendAI23/9/202623/9/2026
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
AplazadaMedia (6.5)0.34%—Wedevs WP User FrontendAI23/9/202623/9/2026
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
AplazadaCrítica (9.8)0.44%—Metabox Meta BOX AIOAIMetabox Meta BOX Frontend SubmissionAIMetabox Meta BOX User ProfileAI22/9/202622/9/2026
The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET…
AplazadaAlta (8.5)0.39%—FrontmcpAIFrontmcp Mcp-from-openapiAI@frontmcp/adaptersAI15/9/202630/9/2026
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISpec() forwards untrusted OpenAPI url and spec inputs and loadOptions.refResolution…
AplazadaAlta (8.3)0.36%—Zabbix FrontendAI13/9/202624/9/2026
Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing…
AplazadaCrítica (9.8)0.63%—Frontegg Saml SSOAI12/9/202614/9/2026
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.
AplazadaCrítica (9.8)0.91%—Dynamiapps Frontend AdminAI6/9/20268/9/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its…
AplazadaMedia (5.9)0.38%—Dynamiapps Frontend AdminAI4/9/20268/9/2026
The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the…
AplazadaMedia (5.3)0.22%—User FrontendAI2/9/20263/9/2026
The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to…
AplazadaAlta (8.8)0.52%—Wedevs WP User FrontendAI2/9/20262/9/2026
Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.
AplazadaAlta (8.8)0.41%—User FrontendAI2/9/20263/9/2026
The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code…
AplazadaAlta (7.5)0.96%—Dynamiapps Frontend AdminAI1/9/20261/9/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can…
AplazadaMedia (6.4)0.20%—Dynamiapps Frontend AdminAI1/9/20261/9/2026
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
AplazadaMedia (4.3)0.25%—Dynamiapps Frontend AdminAI29/8/202631/8/2026
The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.
AplazadaMedia (5.3)0.25%—User FrontendAI28/8/202628/8/2026
The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators.
AplazadaAlta (7.2)0.52%—User FrontendAI28/8/202628/8/2026
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable…
AplazadaAlta (8.2)0.31%—FrontaccountingAI27/8/202623/9/2026
FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_POST['password']) to add_user() and update_user_password(), admin/change_current_user_password.php does the same when a user changes their own password, the forgotten-password path in…
AplazadaAlta (7.1)0.22%—FrontaccountingAI27/8/202623/9/2026
FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but only admin/users.php and admin/change_current_user_password.php call check_csrf_token() to validate it. No financial transaction handler validates…
AplazadaMedia (6.5)0.22%—Dynamiapps Frontend AdminAI18/8/202620/8/2026
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.