Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2598▼ 321 respecto a la semana anterior
Críticas / altas1342▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
485 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.1) | 0.22% | — | Wpfront Notification BARAI | 3/10/2026 | 3/10/2026 | The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.1. This is due to the debug-log output path (write_debug_logs) reflecting the raw value of $_SERVER['REQUEST_URI'] through vprintf() directly inside a <script> block emitted on… | |
| Aplazada | Media (4.3) | 0.18% | — | Wedevs WP User FrontendAI | 2/10/2026 | 2/10/2026 | The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level access and above to create and, depending on the form's configuration, immediately publish posts through forms restricted… | |
| Aplazada | Media (5.3) | 0.22% | — | User FrontendAI | 30/9/2026 | 30/9/2026 | The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled. The created account receives the site's default role. | |
| Aplazada | Alta (7.4) | 0.25% | — | Wedevs User FrontendAI | 30/9/2026 | 30/9/2026 | The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a… | |
| Aplazada | Alta (7.2) | 0.25% | — | Frontend Post Submission Manager LiteAI | 30/9/2026 | 30/9/2026 | The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Media (6.5) | 0.47% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Media (5.3) | 0.25% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Wedevs WP User FrontendAI | 23/9/2026 | 23/9/2026 | Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. | |
| Aplazada | Crítica (9.8) | 0.44% | — | Metabox Meta BOX AIOAIMetabox Meta BOX Frontend SubmissionAIMetabox Meta BOX User ProfileAI | 22/9/2026 | 22/9/2026 | The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission component unconditionally overrides the form's target object_id from the GET… | |
| Aplazada | Alta (8.5) | 0.39% | — | FrontmcpAIFrontmcp Mcp-from-openapiAI@frontmcp/adaptersAI | 15/9/2026 | 30/9/2026 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISpec() forwards untrusted OpenAPI url and spec inputs and loadOptions.refResolution… | |
| Aplazada | Alta (8.3) | 0.36% | — | Zabbix FrontendAI | 13/9/2026 | 24/9/2026 | Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing… | |
| Aplazada | Crítica (9.8) | 0.63% | — | Frontegg Saml SSOAI | 12/9/2026 | 14/9/2026 | The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts. | |
| Aplazada | Crítica (9.8) | 0.91% | — | Dynamiapps Frontend AdminAI | 6/9/2026 | 8/9/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its… | |
| Aplazada | Media (5.9) | 0.38% | — | Dynamiapps Frontend AdminAI | 4/9/2026 | 8/9/2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including the WordPress root, which can render the… | |
| Aplazada | Media (5.3) | 0.22% | — | User FrontendAI | 2/9/2026 | 3/9/2026 | The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately publish posts through forms restricted to… | |
| Aplazada | Alta (8.8) | 0.52% | — | Wedevs WP User FrontendAI | 2/9/2026 | 2/9/2026 | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions. | |
| Aplazada | Alta (8.8) | 0.41% | — | User FrontendAI | 2/9/2026 | 3/9/2026 | The User Frontend WordPress plugin before 4.3.11 does not prevent user-supplied field values from being deserialized when a submitted post is reopened in its frontend editing form, allowing authenticated users with subscriber-level access and above to perform PHP Object Injection, which may lead to remote code… | |
| Aplazada | Alta (7.5) | 0.96% | — | Dynamiapps Frontend AdminAI | 1/9/2026 | 1/9/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all versions up to, and including, 3.29.12. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can… | |
| Aplazada | Media (6.4) | 0.20% | — | Dynamiapps Frontend AdminAI | 1/9/2026 | 1/9/2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Media (4.3) | 0.25% | — | Dynamiapps Frontend AdminAI | 29/8/2026 | 31/8/2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans. | |
| Aplazada | Media (5.3) | 0.25% | — | User FrontendAI | 28/8/2026 | 28/8/2026 | The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators. | |
| Aplazada | Alta (7.2) | 0.52% | — | User FrontendAI | 28/8/2026 | 28/8/2026 | The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable… | |
| Aplazada | Alta (8.2) | 0.31% | — | FrontaccountingAI | 27/8/2026 | 23/9/2026 | FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_POST['password']) to add_user() and update_user_password(), admin/change_current_user_password.php does the same when a user changes their own password, the forgotten-password path in… | |
| Aplazada | Alta (7.1) | 0.22% | — | FrontaccountingAI | 27/8/2026 | 23/9/2026 | FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden field in every form it renders, but only admin/users.php and admin/change_current_user_password.php call check_csrf_token() to validate it. No financial transaction handler validates… | |
| Aplazada | Media (6.5) | 0.22% | — | Dynamiapps Frontend AdminAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. |