Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▲ 48 respecto a la semana anterior
Críticas / altas1479▲ 371 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.8)0.43%—WP Highlight BOXAI12/9/202614/9/2026
The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaMedia (4.4)0.34%—Highlighting Code BlockAI10/7/202610/7/2026
The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to…
AplazadaMedia (6.4)0.32%—Easy Prism Syntax HighlighterAI27/5/202617/6/2026
The Easy Prism Syntax Highlighter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'code' (and 'c') shortcode in versions up to, and including, 1.0.2. This is due to insufficient input sanitization and output escaping on user supplied shortcode attributes in the shortcode() function,…
AplazadaMedia (4.3)0.19%—OLD Posts HighlighterAI27/5/202617/6/2026
The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the OPH_options function. This makes it possible for unauthenticated attackers to update the plugin's configuration settings…
AplazadaAlta (7.1)0.21%—Agmorpheus Syntax Highlighter CompressAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agmorpheus Syntax Highlighter Compress syntax-highlighter-compress allows Reflected XSS.This issue affects Syntax Highlighter Compress: from n/a through <= 3.0.83.3.
AplazadaMedia (4.7)0.44%—Ronald Huereca Highlight AND ShareAI9/12/202517/6/2026
Missing Authorization vulnerability in Ronald Huereca Highlight and Share highlight-and-share allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Highlight and Share: from n/a through <= 5.2.0.
AplazadaMedia (4.4)0.22%—Just HighlightAI25/11/202517/6/2026
The Just Highlight plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Highlight Color' setting in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,…
AplazadaMedia (6.5)0.20%—Ronald Huereca Highlight AND ShareAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Highlight and Share highlight-and-share allows Stored XSS.This issue affects Highlight and Share: from n/a through <= 5.1.1.
AnalizadaMedia (6.5)0.46%—Jgehrcke Wp-geshi-highlight10/4/202517/6/2026
The WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages WordPress plugin through 1.4.3 processes user-supplied input as a regular expression via the wp_geshi_filter_replace_code() function, which could lead to Regular Expression Denial of Service (ReDoS) issue
AplazadaAlta (7.1)0.29%—E1tekoap42 Search Engine Keywords HighlighterAI3/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e1tekoap42 Search engine keywords highlighter keywords-highlight-tool allows Reflected XSS.This issue affects Search engine keywords highlighter: from n/a through <= 0.1.3.
AplazadaMedia (6.5)0.29%—Alex Mills Syntaxhighlighter EvolvedAI27/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Mills SyntaxHighlighter Evolved syntaxhighlighter allows DOM-Based XSS.This issue affects SyntaxHighlighter Evolved: from n/a through <= 3.7.1.
AplazadaMedia (5.9)0.31%—Quantumcloud HighlightAI7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Highlight highlight allows Stored XSS.This issue affects Highlight: from n/a through <= 2.0.2.
AplazadaMedia (4.3)0.18%—Extendthemes HighlightAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in extendthemes Highlight highlight allows Cross Site Request Forgery.This issue affects Highlight: from n/a through <= 1.0.29.
AplazadaAlta (7.1)0.20%—A328496647 CK AND SyntaxhighlighterAI16/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in a328496647 CK and SyntaxHighlighter ck-and-syntaxhighlighter allows Stored XSS.This issue affects CK and SyntaxHighlighter: from n/a through <= 3.4.2.
ModificadaAlta (8.8)0.21%—Urvanov Syntax Highlighter12/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Fedor Urvanov, Aram Kocharyan Urvanov Syntax Highlighter plugin <= 2.8.33 versions.
ModificadaMedia (5.4)0.39%—Aramk Crayon-syntax-highlighter12/9/202317/6/2026
The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Server Side Request Forgery via the 'crayon' shortcode in versions up to, and including, 2.8.4. This can allow authenticated attackers with contributor-level permissions or above to make web requests to arbitrary locations originating from the web…
ModificadaMedia (6.5)0.29%—Highlight26/5/202317/6/2026
Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when a password html input is switched to `type="text"` via a javascript "Show Password" button. This differs from the expected behavior which always obfuscates `type="password"` inputs. A customer may…
ModificadaAlta (8.8)0.26%—Crayon Syntax Highlighter Project Crayon Syntax Highlighter22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Aram Kocharyan Crayon Syntax Highlighter plugin <= 2.8.4 versions.
ModificadaMedia (4.8)0.56%—Highlight Focus Project Highlight Focus7/11/202217/6/2026
The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (5.4)0.62%—Dna88 Highlight6/9/202117/6/2026
The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaAlta (7.2)1.5%—Comment Highlighter Project Comment Highlighter6/9/202117/6/2026
A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.
ModificadaAlta (8.7)1.3%—Highlightjs Highlight.jsDebian LinuxOracle Mysql Enterprise Monitor24/11/202017/6/2026
Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype pollution of the base object's prototype during highlighting. If you allow users to insert custom…
ModificadaMedia (6.1)1.4%—Markdown-it-highlightjs Project Markdown-it-highlightjs16/11/202017/6/2026
—
ModificadaMedia (6.1)1.5%—Crayon Syntax Highlighter Project Crayon Syntax Highlighter20/8/201917/6/2026
The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
ModificadaAlta (8.8)1.3%—Wp-code-highlightjs Project Wp-code-highlightjs20/7/201917/6/2026
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.