Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Baja (3.1) | — | — | Themeisle Otter BlocksAI | 2/10/2026 | 2/10/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.6 via the 'otter_form_widget_filter' parameter. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Media (5.3) | 0.39% | — | Themeisle Otter BlocksAI | 7/9/2026 | 8/9/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.7 via the 'watch_checkout' function due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.32% | — | Woocommerce LotteryAI | 26/8/2026 | 26/8/2026 | The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Alta (7.5) | 0.52% | — | Themeisle Otter BlocksAI | 30/4/2026 | 17/6/2026 | The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the 'get_customer_data' method relying on an unsigned 'o_stripe_data' cookie to determine Stripe product ownership for unauthenticated users. The 'check_purchase' method… | |
| Aplazada | Media (5.3) | 0.24% | — | Doruk Communication AND Automation Industry AND Trade INC WispotterAI | 18/2/2026 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication and Automation Industry and Trade Inc. Wispotter allows Password Brute Forcing, Brute Force. This issue affects Wispotter: from 1.0 before v2025.10.08.1. | |
| Aplazada | Media (6.4) | 0.28% | — | Thai Lottery WidgetAI | 5/12/2025 | 25/9/2026 | The Thai Lottery Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `thailottery` shortcode in all versions up to, and including, 2.5. This is due to insufficient input sanitization and output escaping on the user supplied `width` and `height` shortcode attributes. This makes it possible… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Antabot White-jotterAI | 24/10/2025 | 17/6/2026 | Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the component /api/aaa;/../register. | |
| Aplazada | Alta (7.5) | 0.37% | — | Themeisle Otter - Gutenberg BlockAI | 20/8/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows Retrieve Embedded Sensitive Data.This issue affects Otter - Gutenberg Block: from n/a through <= 3.1.0. | |
| Analizada | Baja (1.3) | 0.40% | — | Antabot White-jotter | 8/8/2025 | 17/6/2026 | A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeManager of the file ShiroConfiguration.java of the component com.gm.wj.config.ShiroConfiguration. The manipulation with the input EVANNIGHTLY_WAOU leads to deserialization.… | |
| Analizada | Alta (7.6) | 0.53% | — | Antabot White-jotter | 21/2/2025 | 17/6/2026 | An issue in the shiroFilter function of White-Jotter project v0.2.2 allows attackers to execute a directory traversal and access sensitive endpoints via a crafted URL. | |
| Analizada | Media (5.4) | 0.17% | — | Magayo Lottery Results | 18/2/2025 | 17/6/2026 | The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.12. This is due to missing or incorrect nonce validation on the 'magayo-lottery-results' page. This makes it possible for unauthenticated attackers to update settings and inject… | |
| Analizada | Media (5.1) | 0.53% | — | Antabot White-jotter | 30/12/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Antabot White-Jotter up to 0.2.2. Affected by this vulnerability is an unknown functionality of the file /admin/content/editor of the component Article Editor. The manipulation of the argument articleCover leads to server-side request forgery. The attack can be… | |
| Analizada | Media (5.1) | 0.38% | — | Antabot White-jotter | 30/12/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Antabot White-Jotter up to 0.2.2. Affected is an unknown function of the file /admin/content/editor of the component Article Content Editor. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.52% | — | Antabot White-jotter | 30/12/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Antabot White-Jotter up to 0.2.2. Affected is an unknown function of the file /admin/content/book of the component Edit Book Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (6.3) | 0.75% | — | Antabot White-jotter | 29/12/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Antabot White-Jotter up to 0.2.2. This issue affects some unknown processing of the file /login. The manipulation of the argument username leads to observable response discrepancy. The attack may be initiated remotely. The complexity of an attack… | |
| Analizada | Alta (7.5) | 0.51% | — | Themeisle Otter Blocks | 27/11/2024 | 17/6/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.0.6 via the get_image function. This makes it possible for unauthenticated attackers to view arbitrary images on the server, which can contain… | |
| Aplazada | Baja (2.7) | 0.48% | — | Themeisle OtterAI | 19/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Otter - Gutenberg Block: from n/a through <= 3.0.3. | |
| Aplazada | Media (6.4) | 0.36% | — | Themeisle Otter BlocksAI | 1/11/2024 | 17/6/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Crítica (10) | 0.51% | — | Shafiq Digital Digital-lotteryAI | 16/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery digital-lottery allows Upload a Web Shell to a Web Server.This issue affects Digital Lottery: from n/a through <= 3.0.5. | |
| Modificada | Media (5.3) | 0.34% | — | Themeisle Otter Blocks | 8/6/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Themeisle Otter Blocks PRO.This issue affects Otter Blocks PRO: from n/a through 2.6.11. | |
| Modificada | Media (5.4) | 0.42% | — | Themeisle Otter Blocks | 2/5/2024 | 17/6/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Grid widget in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes such as… | |
| Analizada | Media (6.1) | 0.42% | — | Themeisle Otter Blocks | 18/4/2024 | 17/6/2026 | The Otter Blocks WordPress plugin before 2.6.6 does not properly escape its mainHeadings blocks' attribute before appending it to the final rendered block, allowing contributors to conduct Stored XSS attacks. | |
| Modificada | Media (5.4) | 0.32% | — | Themeisle Otter Blocks | 11/4/2024 | 17/6/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file upload in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Modificada | Media (5.4) | 0.34% | — | Themeisle Otter Blocks | 11/4/2024 | 17/6/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block attributes in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Modificada | Media (5.4) | 0.36% | — | Themeisle Otter Blocks | 9/4/2024 | 17/6/2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the id parameter in the google-map block in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping. This makes it possible for… |