Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.34% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body. | |
| Aplazada | Media (6.5) | 0.37% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users. | |
| Aplazada | Alta (7.5) | 0.41% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users'… | |
| Aplazada | Media (4.3) | 0.25% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site. | |
| Aplazada | Media (6.5) | 0.37% | — | Jshelpdesk JS Help DeskAI | 31/7/2026 | 26/8/2026 | The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets. | |
| Aplazada | Media (5.3) | 0.31% | — | Jshelpdesk JS Help DeskAI | 26/6/2026 | 26/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions. | |
| Aplazada | Alta (7.7) | 0.47% | — | Jshelpdesk JS Help DeskAI | 25/6/2026 | 25/6/2026 | Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Jshelpdesk JS Help DeskAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Jshelpdesk JS Help DeskAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions. | |
| Aplazada | Alta (7.5) | 0.30% | — | Jshelpdesk JS Help DeskAI | 26/3/2026 | 17/6/2026 | The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, and including, 3.0.4. This is due to the user-supplied `multiformid` value being passed to `esc_sql()` without enclosing… | |
| Aplazada | Media (6.5) | 0.27% | — | Joomsky JS Help DeskAI | 25/3/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through <= 3.0.3. | |
| Aplazada | Alta (8.5) | 0.36% | — | Joomsky JS Help DeskAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through <= 3.0.3. | |
| Aplazada | Alta (7.5) | 1.3% | — | Jshelpdesk JS Help DeskAI | 4/3/2026 | 17/6/2026 | The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in version 2.8.2 due to an incomplete fix for CVE-2023-50839 where a second sink was left with insufficient escaping on the user supplied values and lack of… | |
| Aplazada | Alta (8.5) | 0.22% | — | Joomsky JS Help DeskAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through <= 3.0.1. | |
| Modificada | Alta (8.1) | 0.85% | — | Joomsky JS Help Desk | 1/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Help Desk js-support-ticket allows PHP Local File Inclusion.This issue affects JS Help Desk: from n/a through <= 2.9.2. | |
| Modificada | Crítica (10) | 0.52% | — | Joomsky JS Help Desk | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows SQL Injection.This issue affects JS Help Desk: from n/a through <= 2.9.2. | |
| Modificada | Alta (7.5) | 0.59% | — | Joomsky JS Help Desk | 1/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-support-ticket allows Path Traversal.This issue affects JS Help Desk: from n/a through <= 2.9.1. | |
| Modificada | Alta (7.5) | 0.49% | — | Joomsky JS Help Desk | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through <= 2.9.2. | |
| Modificada | Crítica (9.1) | 0.62% | — | Joomsky JS Help Desk | 1/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk js-support-ticket allows Path Traversal.This issue affects JS Help Desk: from n/a through <= 2.9.2. | |
| Analizada | Alta (7.5) | 0.43% | — | Wiselyhub JS Help Desk | 13/2/2025 | 17/6/2026 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'jssupportticketdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the… | |
| Modificada | Media (5.4) | 0.45% | — | Joomsky JS Help Desk | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1. | |
| Modificada | Crítica (9.1) | 0.73% | — | Joomsky JS Help Desk | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1. | |
| Modificada | Media (4.8) | 0.26% | — | Joomsky JS Help Desk | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JoomSky JS Help Desk js-support-ticket allows Stored XSS.This issue affects JS Help Desk: from n/a through <= 2.8.7. | |
| Analizada | Crítica (9.8) | 0.44% | — | Joomsky JS Help Desk | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.6. | |
| Aplazada | Crítica (9.8) | 38% | — | Jshelpdesk JS Help DeskAI | 13/8/2024 | 17/6/2026 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the… |