Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2757▲ 47 respecto a la semana anterior
Críticas / altas1482▲ 372 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.39% | — | Template KITAI | 30/9/2026 | 30/9/2026 | Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions. | |
| Pendiente de análisis | Crítica (9.1) | 0.30% | — | Wikimedia Template SandboxAI | 29/9/2026 | 1/10/2026 | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Pendiente de análisis | Media (6.9) | 0.39% | — | Marcos Camara01 Ecommerce TemplateAI | 28/9/2026 | 29/9/2026 | Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The… | |
| Pendiente de análisis | Media (4.8) | 0.29% | — | Wikimedia Mediawiki TemplatesandboxAI | 25/9/2026 | 28/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Aplazada | Media (4.3) | 0.21% | — | Wpgogo Custom Field TemplateAI | 22/9/2026 | 22/9/2026 | The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to delete… | |
| Aplazada | Media (6.5) | 0.58% | — | Wpgogo Custom Field TemplateAI | 19/9/2026 | 21/9/2026 | The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all versions up to, and including, 2.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.34% | — | Udecode PlateAI | 16/9/2026 | 16/9/2026 | Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strings in the active document. When an application passes untrusted or cross-user HTML to these APIs, certain HTML… | |
| Aplazada | Media (6.9) | 0.37% | — | Regularlabs Advanced Module ManagerAIRegularlabs Conditional ContentAIRegularlabs Content TemplaterAIRegularlabs RereplacerAI+1 | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla - The Conditions editor creates a default Condition Set name from the item to which the set is… | |
| Aplazada | Media (4.3) | 0.25% | — | Starter TemplatesAI | 11/9/2026 | 11/9/2026 | Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions. | |
| Aplazada | Media (4.3) | 0.28% | — | Arma Digital Media INC Website TemplateAI | 11/9/2026 | 11/9/2026 | Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Pendiente de análisis | Alta (7.7) | 0.38% | — | Hashicorp Consul-templateAI | 10/9/2026 | 10/9/2026 | The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task events. This vulnerability (CVE-2026-87993) is fixed in consul-template 0.43.0. | |
| Aplazada | Media (5.3) | 0.33% | — | Dernekplus Website TemplateAI | 10/9/2026 | 10/9/2026 | Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpkoi Templates FOR ElementorAI | 3/9/2026 | 7/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This issue affects WPKoi Templates for Elementor: from n/a through 3.7.2. | |
| Aplazada | Media (6.9) | 0.27% | — | Appwrite TemplatesAI | 20/8/2026 | 24/9/2026 | The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns "typeof signature !== 'string' || (await verify(...))", so when the X-Hub-Signature-256… | |
| Aplazada | Alta (8.2) | 0.52% | — | Platejs Docx IOAI | 20/8/2026 | 16/9/2026 | Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can make requests to internal network resources and include the fetched image bytes… | |
| Aplazada | Alta (7.5) | 0.46% | — | Kadencewp Starter TemplatesAI | 18/8/2026 | 20/8/2026 | Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | TemplatelyAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions. | |
| Aplazada | Alta (8.8) | 1.3% | — | TemplatelyAI | 15/8/2026 | 20/8/2026 | The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.1 via the fetch_remote_file function. This is due to a filename validation/destination mismatch in… | |
| Pendiente de análisis | Alta (8.8) | 0.32% | — | Anthropic Claude Code TemplatesAI | 11/8/2026 | 9/9/2026 | Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The POST /api/execute… | |
| Aplazada | Media (6.5) | 0.34% | — | TemplatelyAI | 7/8/2026 | 26/8/2026 | The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate administrator and redirecting the… | |
| Aplazada | Media (6.1) | 0.26% | — | Ember Dynamic Render TemplateAIEmber Template CompilationAI | 5/8/2026 | 26/8/2026 | The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property directly into Ember/Glimmer's compileTemplate (from @ember/template-compilation) with no sanitization, allow-listing, or validation of the input. | |
| Aplazada | Alta (7.5) | 0.56% | — | Art-templateAI | 5/8/2026 | 26/8/2026 | art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and extend template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that the result remains inside root. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Vps.org Zulip TemplateAIZulipAI | 31/7/2026 | 8/9/2026 | Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True. | |
| Aplazada | Media (6.1) | 0.25% | — | Polen Media Software AND Information Services Website TemplateAI | 24/7/2026 | 24/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue affects Website Template: before v2. | |
| Aplazada | Media (4.3) | 0.27% | — | TemplatespareAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions. |