Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.18%—WPS Limit LoginAI23/9/202623/9/2026
Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.
AplazadaBaja (3.7)0.26%—Limitloginattempts Limit Login Attempts ReloadedAI21/8/202626/8/2026
The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's email address, allowing an account an administrator intended to block from logging in to authenticate anyway.
AplazadaCrítica (9.3)0.54%—Limitloginattempts Limit Login AttemptsAI13/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wp-buy Limit Login Attempts wp-limit-failed-login-attempts allows SQL Injection.This issue affects Limit Login Attempts: from n/a through <= 5.5.
AplazadaMedia (5.3)0.34%—Limit Login Attempts Spam ProtectionAI8/10/202417/6/2026
The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.3. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the…
AnalizadaMedia (5.3)0.22%—Devfelixmoira Limit Login Attempts Plus19/9/202417/6/2026
The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header…
ModificadaMedia (5.4)0.43%—Limitloginattempts Limit Login Attempts Reloaded11/1/202417/6/2026
The Limit Login Attempts Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.25.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaMedia (4.3)0.45%—Limitloginattempts Limit Login Attempts Reloaded27/11/202317/6/2026
The Limit Login Attempts Reloaded WordPress plugin before 2.25.26 is missing authorization on the `toggle_auto_update` AJAX action, allowing any user with a valid nonce to toggle the auto-update status of the plugin.
ModificadaMedia (5.4)29%—Limit Login Attempts Project Limit Login Attempts2/5/202317/6/2026
The Limit Login Attempts WordPress plugin through 1.7.2 does not sanitize and escape usernames when outputting them back in the logs dashboard, which could allow any authenticated users, such as subscriber to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.1)0.79%—Limit Login Attempts Project Limit Login Attempts6/4/202317/6/2026
The Limit Login Attempts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging feature in versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
ModificadaAlta (7.5)0.70%—Ciphercoin WP Limit Login Attempts23/1/202317/6/2026
The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based restrictions on login forms.
ModificadaMedia (4.8)0.89%—Miniorange Limit Login Attempts27/6/202217/6/2026
The Limit Login Attempts WordPress plugin before 4.0.72 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
ModificadaCrítica (9.8)8.6%—Limit Login Attempts Project Limit Login Attempts28/3/202217/6/2026
The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections
ModificadaMedia (6.1)1.6%—Limit Login Attempts Project Limit Login Attempts20/9/202117/6/2026
The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by attacker via headers such as X-Forwarded-For) of attempted logins before outputting them in the reports table, leading to an Unauthenticated Stored Cross-Site Scripting issue.
ModificadaCrítica (9.8)2.5%—Limit Login Attempts Project Limit Login Attempts6/1/202116/6/2026
The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.
ModificadaCrítica (9.8)4.3%—Limitloginattempts Limit Login Attempts Reloaded21/12/202017/6/2026
LimitLoginAttempts.php in the limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows a bypass of (per IP address) rate limits because the X-Forwarded-For header can be forged. When the plugin is configured to accept an arbitrary header for the client source IP address, a malicious user is not limited…
ModificadaMedia (5.4)0.78%—Limitloginattempts Limit Login Attempts Reloaded21/12/202017/6/2026
The limit-login-attempts-reloaded plugin before 2.17.4 for WordPress allows wp-admin/options-general.php?page=limit-login-attempts&tab= XSS. A malicious user can cause an administrator user to supply dangerous content to the vulnerable page, which is then reflected back to the user and executed by the web browser. The…
ModificadaAlta (7.5)2.4%—Ciphercoin WP Limit Login Attempts16/9/201517/6/2026
Multiple SQL injection vulnerabilities in the getip function in wp-limit-login-attempts.php in the WP Limit Login Attempts plugin before 2.0.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) X-Forwarded-For or (2) Client-IP HTTP header.