Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
174 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | — | — | Radiustheme Review SchemaAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Schema: 3.1.0. | |
| Aplazada | Media (5.3) | 0.29% | — | Radiustheme Review SchemaAI | 30/9/2026 | 30/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Radiustheme Classified ListingAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Radiustheme THE Post GridAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. | |
| Aplazada | Alta (7.1) | 0.19% | — | Radiustheme Classified ListingAI | 4/9/2026 | 8/9/2026 | The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing… | |
| Aplazada | Media (5.4) | 0.29% | — | Radiustheme Classified ListingAI | 2/9/2026 | 23/9/2026 | Missing Authorization vulnerability in Mamunur Rashid Classified Listing classified-listing allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Classified Listing: from n/a through 6.1.3. | |
| Aplazada | Baja (2.7) | 0.30% | — | Radiustheme Classified ListingAI | 3/8/2026 | 26/8/2026 | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators and report managers. | |
| Aplazada | Baja (2.7) | 0.30% | — | Radiustheme Classified ListingAI | 3/8/2026 | 26/8/2026 | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private… | |
| Aplazada | Media (4.3) | 0.27% | — | Radiustheme Classified ListingAI | 21/7/2026 | 21/7/2026 | The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order. | |
| Aplazada | Media (6.5) | 0.30% | — | Radiustheme Classified ListingAI | 2/7/2026 | 2/7/2026 | Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Radiustheme Classified ListingAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions. | |
| Aplazada | Media (4.3) | 0.37% | — | Radiustheme Classified ListingAI | 19/6/2026 | 22/6/2026 | The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capability/ownership check on the gallery_image_update_as_feature AJAX handler (action:… | |
| Aplazada | Alta (7.1) | 0.25% | — | Radiustheme Classified ListingAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | Radiustheme Classified ListingAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions. | |
| Aplazada | Media (6.5) | 0.44% | — | Radiustheme Classified ListingAI | 1/6/2026 | 22/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: from n/a through 5.3.8. | |
| Aplazada | Media (4.3) | 0.27% | — | Radiustheme THE Post GridAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Post Grid: from n/a through 7.9.2. | |
| Aplazada | Media (4.3) | 0.45% | — | Radiustheme Classified ListingAI | 15/5/2026 | 17/6/2026 | The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Media (5.1) | 0.20% | — | Radiustheme Testimonial Slider AND ShowcaseAI | 10/5/2026 | 25/7/2026 | WordPress Plugin Testimonial Slider and Showcase 2.2.6 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malicious scripts by failing to sanitize the post_title parameter. Attackers with editor privileges can inject JavaScript payloads through the testimonial title field… | |
| Aplazada | Media (6.5) | 0.27% | — | Radiustheme Review SchemaAI | 25/3/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme Review Schema review-schema allows Retrieve Embedded Sensitive Data.This issue affects Review Schema: from n/a through <= 2.2.6. | |
| Aplazada | Alta (7.5) | 0.28% | — | Radiustheme Tlp-teamAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.11. | |
| Aplazada | Media (5.3) | 0.26% | — | Radiustheme Tlp-teamAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.13. | |
| Aplazada | Media (5.3) | 0.33% | — | Radiustheme ShopbuilderAI | 13/3/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder allows Retrieve Embedded Sensitive Data.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through <= 3.2.4. | |
| Aplazada | Alta (7.5) | 0.51% | — | Radiustheme Medilink-coreAI | 13/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Medilink-Core medilink-core allows PHP Local File Inclusion.This issue affects Medilink-Core: from n/a through < 2.0.7. | |
| Aplazada | Alta (8.1) | 0.56% | — | Radiustheme MetroAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Metro metro allows PHP Local File Inclusion.This issue affects Metro: from n/a through <= 2.13. | |
| Aplazada | Alta (7.1) | 0.25% | — | Radiustheme MetroAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Metro metro allows DOM-Based XSS.This issue affects Metro: from n/a through <= 2.13. |