Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
–

174 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)——Radiustheme Review SchemaAI1/10/20261/10/2026
Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Schema: 3.1.0.
AplazadaMedia (5.3)0.29%—Radiustheme Review SchemaAI30/9/202630/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in Review Schema <= 3.1.0 versions.
AplazadaAlta (7.1)0.25%—Radiustheme Classified ListingAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions.
AplazadaMedia (6.5)0.17%—Radiustheme THE Post GridAI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.
AplazadaAlta (7.1)0.19%—Radiustheme Classified ListingAI4/9/20268/9/2026
The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing…
AplazadaMedia (5.4)0.29%—Radiustheme Classified ListingAI2/9/202623/9/2026
Missing Authorization vulnerability in Mamunur Rashid Classified Listing classified-listing allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Classified Listing: from n/a through 6.1.3.
AplazadaBaja (2.7)0.30%—Radiustheme Classified ListingAI3/8/202626/8/2026
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users with contributor-level access and above to read daily revenue figures normally restricted to administrators and report managers.
AplazadaBaja (2.7)0.30%—Radiustheme Classified ListingAI3/8/202626/8/2026
The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing users with contributor-level access and above to read the content of any post, page, or custom post type on the site — including drafts, pending, and private…
AplazadaMedia (4.3)0.27%—Radiustheme Classified ListingAI21/7/202621/7/2026
The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt handler belongs to the requesting user, allowing authenticated users with subscriber-level access to read the payment receipt details of any other user's order.
AplazadaMedia (6.5)0.30%—Radiustheme Classified ListingAI2/7/20262/7/2026
Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.
AplazadaAlta (7.1)0.25%—Radiustheme Classified ListingAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.
AplazadaMedia (4.3)0.37%—Radiustheme Classified ListingAI19/6/202622/6/2026
The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capability/ownership check on the gallery_image_update_as_feature AJAX handler (action:…
AplazadaAlta (7.1)0.25%—Radiustheme Classified ListingAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions.
AplazadaMedia (6.5)0.27%—Radiustheme Classified ListingAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.
AplazadaMedia (6.5)0.44%—Radiustheme Classified ListingAI1/6/202622/7/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: from n/a through 5.3.8.
AplazadaMedia (4.3)0.27%—Radiustheme THE Post GridAI27/5/202617/6/2026
Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Post Grid: from n/a through 7.9.2.
AplazadaMedia (4.3)0.45%—Radiustheme Classified ListingAI15/5/202617/6/2026
The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 5.3.10. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…
AplazadaMedia (5.1)0.20%—Radiustheme Testimonial Slider AND ShowcaseAI10/5/202625/7/2026
WordPress Plugin Testimonial Slider and Showcase 2.2.6 contains a stored cross-site scripting vulnerability that allows authenticated editors to inject malicious scripts by failing to sanitize the post_title parameter. Attackers with editor privileges can inject JavaScript payloads through the testimonial title field…
AplazadaMedia (6.5)0.27%—Radiustheme Review SchemaAI25/3/202617/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme Review Schema review-schema allows Retrieve Embedded Sensitive Data.This issue affects Review Schema: from n/a through <= 2.2.6.
AplazadaAlta (7.5)0.28%—Radiustheme Tlp-teamAI25/3/202617/6/2026
Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.11.
AplazadaMedia (5.3)0.26%—Radiustheme Tlp-teamAI13/3/202617/6/2026
Missing Authorization vulnerability in RadiusTheme Team tlp-team allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team: from n/a through <= 5.0.13.
AplazadaMedia (5.3)0.33%—Radiustheme ShopbuilderAI13/3/202617/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder allows Retrieve Embedded Sensitive Data.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through <= 3.2.4.
AplazadaAlta (7.5)0.51%—Radiustheme Medilink-coreAI13/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Medilink-Core medilink-core allows PHP Local File Inclusion.This issue affects Medilink-Core: from n/a through < 2.0.7.
AplazadaAlta (8.1)0.56%—Radiustheme MetroAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Metro metro allows PHP Local File Inclusion.This issue affects Metro: from n/a through <= 2.13.
AplazadaAlta (7.1)0.25%—Radiustheme MetroAI5/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Metro metro allows DOM-Based XSS.This issue affects Metro: from n/a through <= 2.13.