Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 48 respecto a la semana anterior
Críticas / altas1479▲ 371 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.43% | — | WP Highlight BOXAI | 12/9/2026 | 14/9/2026 | The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (4.4) | 0.34% | — | Highlighting Code BlockAI | 10/7/2026 | 10/7/2026 | The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Media (6.4) | 0.32% | — | Easy Prism Syntax HighlighterAI | 27/5/2026 | 17/6/2026 | The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'code' (and 'c') shortcode in versions up to, and including, 1.0.2. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes in the shortcode() function,… | |
| Aplazada | Media (4.3) | 0.19% | — | OLD Posts HighlighterAI | 27/5/2026 | 17/6/2026 | The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the OPH_options function. This makes it possible for unauthenticated attackers to update the plugin's configuration settings… | |
| Aplazada | Alta (7.1) | 0.21% | — | Agmorpheus Syntax Highlighter CompressAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agmorpheus Syntax Highlighter Compress syntax-highlighter-compress allows Reflected XSS.This issue affects Syntax Highlighter Compress: from n/a through <= 3.0.83.3. | |
| Aplazada | Media (4.7) | 0.44% | — | Ronald Huereca Highlight AND ShareAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Ronald Huereca Highlight and Share highlight-and-share allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Highlight and Share: from n/a through <= 5.2.0. | |
| Aplazada | Media (4.4) | 0.22% | — | Just HighlightAI | 25/11/2025 | 17/6/2026 | The Just Highlight plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Highlight Color' setting in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,… | |
| Aplazada | Media (6.5) | 0.20% | — | Ronald Huereca Highlight AND ShareAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Highlight and Share highlight-and-share allows Stored XSS.This issue affects Highlight and Share: from n/a through <= 5.1.1. | |
| Analizada | Media (6.5) | 0.46% | — | Jgehrcke Wp-geshi-highlight | 10/4/2025 | 17/6/2026 | The WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages WordPress plugin through 1.4.3 processes user-supplied input as a regular expression via the wp_geshi_filter_replace_code() function, which could lead to Regular Expression Denial of Service (ReDoS) issue | |
| Aplazada | Alta (7.1) | 0.29% | — | E1tekoap42 Search Engine Keywords HighlighterAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e1tekoap42 Search engine keywords highlighter keywords-highlight-tool allows Reflected XSS.This issue affects Search engine keywords highlighter: from n/a through <= 0.1.3. | |
| Aplazada | Media (6.5) | 0.29% | — | Alex Mills Syntaxhighlighter EvolvedAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Mills SyntaxHighlighter Evolved syntaxhighlighter allows DOM-Based XSS.This issue affects SyntaxHighlighter Evolved: from n/a through <= 3.7.1. | |
| Aplazada | Media (5.9) | 0.31% | — | Quantumcloud HighlightAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Highlight highlight allows Stored XSS.This issue affects Highlight: from n/a through <= 2.0.2. | |
| Aplazada | Media (4.3) | 0.18% | — | Extendthemes HighlightAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in extendthemes Highlight highlight allows Cross Site Request Forgery.This issue affects Highlight: from n/a through <= 1.0.29. | |
| Aplazada | Alta (7.1) | 0.20% | — | A328496647 CK AND SyntaxhighlighterAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in a328496647 CK and SyntaxHighlighter ck-and-syntaxhighlighter allows Stored XSS.This issue affects CK and SyntaxHighlighter: from n/a through <= 3.4.2. | |
| Modificada | Alta (8.8) | 0.21% | — | Urvanov Syntax Highlighter | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fedor Urvanov, Aram Kocharyan Urvanov Syntax Highlighter plugin <= 2.8.33 versions. | |
| Modificada | Media (5.4) | 0.39% | — | Aramk Crayon-syntax-highlighter | 12/9/2023 | 17/6/2026 | The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortcode in versions up to, and including, 2.8.4. This can allow authenticated attackers with contributor-level permissions or above to make web requests to arbitrary locations originating from the web… | |
| Modificada | Media (6.5) | 0.29% | — | Highlight | 26/5/2023 | 17/6/2026 | Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when a password html input is switched to `type="text"` via a javascript "Show Password" button. This differs from the expected behavior which always obfuscates `type="password"` inputs. A customer may… | |
| Modificada | Alta (8.8) | 0.26% | — | Crayon Syntax Highlighter Project Crayon Syntax Highlighter | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Aram Kocharyan Crayon Syntax Highlighter plugin <= 2.8.4 versions. | |
| Modificada | Media (4.8) | 0.56% | — | Highlight Focus Project Highlight Focus | 7/11/2022 | 17/6/2026 | The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.62% | — | Dna88 Highlight | 6/9/2021 | 17/6/2026 | The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Alta (7.2) | 1.5% | — | Comment Highlighter Project Comment Highlighter | 6/9/2021 | 17/6/2026 | A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. | |
| Modificada | Alta (8.7) | 1.3% | — | Highlightjs Highlight.jsDebian LinuxOracle Mysql Enterprise Monitor | 24/11/2020 | 17/6/2026 | Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype pollution of the base object's prototype during highlighting. If you allow users to insert custom… | |
| Modificada | Media (6.1) | 1.4% | — | Markdown-it-highlightjs Project Markdown-it-highlightjs | 16/11/2020 | 17/6/2026 | — | |
| Modificada | Media (6.1) | 1.5% | — | Crayon Syntax Highlighter Project Crayon Syntax Highlighter | 20/8/2019 | 17/6/2026 | The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests. | |
| Modificada | Alta (8.8) | 1.3% | — | Wp-code-highlightjs Project Wp-code-highlightjs | 20/7/2019 | 17/6/2026 | An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter. |