Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
250 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.33% | — | Kylephillips Nested PagesAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Core WEB Vitals AND Pagespeed BoosterAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions. | |
| Aplazada | Alta (8) | 0.34% | — | Unbounce Landing PagesAI | 19/9/2026 | 21/9/2026 | The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any authenticated user, such as a subscriber, to point that proxy at a host they control and have arbitrary content served from the site's own origin. | |
| Aplazada | Alta (7.1) | 0.32% | — | Unbounce Landing PagesAI | 8/9/2026 | 8/9/2026 | Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a through 1.1.4. | |
| Aplazada | Media (6.8) | 0.23% | — | Sogo ADD Script TO Individual Pages Header FooterAI | 30/8/2026 | 31/8/2026 | The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contributor-level access and above to store… | |
| Aplazada | Alta (7.3) | 0.38% | — | Wplegalpages WP Legal PagesAI | 24/8/2026 | 26/8/2026 | Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions. | |
| Pendiente de análisis | Alta (8.8) | 0.68% | — | Cloudflare Pages-actionAICloudflare Wrangler-actionAI | 12/8/2026 | 28/8/2026 | Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN… | |
| Aplazada | Media (5.8) | 0.35% | — | Term PagesAI | 10/8/2026 | 26/8/2026 | The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks. | |
| Aplazada | Media (5.4) | 0.23% | — | Child Pages CardAI | 6/8/2026 | 26/8/2026 | The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page, allowing users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (4.8) | 0.24% | — | Kylephillips Nested PagesAI | 4/8/2026 | 26/8/2026 | The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowing users with the Editor role (or Contributor/Author when the Nested Pages WordPress plugin before 3.2.15 is enabled for the post type) to inject… | |
| Aplazada | Media (6.4) | 0.36% | — | Insert PagesAI | 2/7/2026 | 2/7/2026 | The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key names) in all versions up to, and including, 3.11.4. This is due to insufficient output escaping in the the_meta() function: while the custom field VALUE is sanitized with wp_kses_post(), the custom… | |
| Aplazada | Baja (2.1) | 0.43% | — | Pretix-pagesAI | 25/6/2026 | 25/6/2026 | Malicious HTML content could be injected into the content of a page in the pretix-pages plugin. | |
| Aplazada | Media (5.3) | 0.25% | — | Avirtum Ipages FlipbookAI | 17/6/2026 | 1/10/2026 | Missing Authorization vulnerability in Avirtum iPages Flipbook allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iPages Flipbook: from n/a through 1.5.1. | |
| Analizada | Crítica (9.8) | 0.58% | — | Microsoft Power Pages | 22/5/2026 | 23/7/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (6.4) | 0.26% | — | Caterhamcomputing CC Child PagesAI | 14/5/2026 | 17/6/2026 | The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'more' parameter in all versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (4.3) | 0.23% | — | Inquiry Form TO Posts OR PagesAI | 15/4/2026 | 17/6/2026 | The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in version 1.0. This is due to missing nonce validation on the plugin settings update handler, combined with insufficient input sanitization on all user-supplied fields and missing… | |
| Aplazada | Media (4.4) | 0.33% | — | Inquiry Form TO Posts OR PagesAI | 8/4/2026 | 24/7/2026 | The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Form Header' field in versions up to and including 1.0. This is due to insufficient input sanitization when saving via update_option() and lack of output escaping when displaying the stored value. The… | |
| Aplazada | Media (4.3) | 0.13% | — | Font Pairing Preview FOR Landing PagesAI | 7/3/2026 | 17/6/2026 | The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify the plugin's font pairing… | |
| Aplazada | Media (6.5) | 0.24% | — | LeadpagesAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Leadpages Leadpages leadpages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leadpages: from n/a through <= 1.1.3. | |
| Aplazada | Alta (7.5) | 0.29% | — | WplegalpagesAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Legal Pages WPLegalPages wplegalpages allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLegalPages: from n/a through <= 3.5.4. | |
| Analizada | Media (6.1) | 0.18% | — | SAP Business Server Pages | 10/2/2026 | 17/6/2026 | SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and… | |
| Modificada | Media (4.3) | 0.32% | — | Apple PagesApple IpadosApple Iphone OSApple Macos | 28/1/2026 | 17/6/2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in Pages 15.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. Processing a maliciously crafted Pages document may result in unexpected termination or disclosure of process memory. | |
| Modificada | Alta (8.6) | 1.3% | — | 4homepages 4images | 13/1/2026 | 17/6/2026 | 4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted… | |
| Aplazada | Media (4.3) | 0.22% | — | SAP Product Designer WEB UIAISAP Business Server PagesAI | 13/1/2026 | 17/6/2026 | SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application. | |
| Aplazada | Media (6.4) | 0.27% | — | WP JS List Pages ShortcodesAI | 7/1/2026 | 17/6/2026 | The WP Js List Pages Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to, and including, 1.21 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… |