Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3040▲ 560 respecto a la semana anterior
Críticas / altas1452▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

74 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.28%—Realtyna Organic IDXAIRealtyna WPL Real EstateAI17/9/202618/9/2026
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link…
AplazadaAlta (7.1)0.25%—Realtyna Organic IDXAI27/8/202628/8/2026
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
AplazadaAlta (8.8)1.2%—Realtyna Organic IDXAI31/7/202612/8/2026
The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing…
AplazadaCrítica (9.8)4.0%—Realtyna Organic IDXAIRealtyna WPL Real EstateAI31/7/202612/8/2026
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, combined with a publicly accessible I/O endpoint authenticated solely by…
AplazadaCrítica (9.8)0.83%—Realtyna Organic IDXAIRealtyna WPL Real EstateAI27/7/202627/7/2026
The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and authenticated with hardcoded credentials shipped identically across all installations. This makes it…
AplazadaCrítica (10)0.56%—Realtyna Organic IDXAI13/7/202613/7/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through <= 5.2.0.
AplazadaCrítica (9.3)0.40%—Realtyna Organic IDXAI15/6/202617/6/2026
Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.
AnalizadaAlta (8.8)0.42%—Nextclickventures Realtyscript16/3/202617/6/2026
Next Click Ventures RealtyScript 4.0.2 contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting arbitrary SQL code through the GET parameter 'u_id' in /admin/users.php and the POST parameter 'agent[]' in /admin/mailer.php. Attackers can exploit time-based…
AnalizadaAlta (8.8)0.42%—Nextclickventures Realtyscript16/3/202617/6/2026
Next Click Ventures RealtyScript 4.0.2 contains multiple time-based blind SQL injection vulnerabilities that allow unauthenticated attackers to extract database information by injecting SQL code into application parameters. Attackers can craft requests with time-delay payloads to infer database contents character by…
AnalizadaMedia (5.1)0.21%—Nextclickventures Realtyscript16/3/202617/6/2026
Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious HTML and iframe elements through the text parameter in the pages.php admin interface. Attackers can submit POST requests to the add page action with crafted iframe…
AnalizadaMedia (5.1)0.32%—Nextclickventures Realtyscript16/3/202617/6/2026
Next Click Ventures RealtyScript 4.0.2 contains a stored cross-site scripting vulnerability in the location_name parameter of the admin locations interface. Attackers can submit POST requests to the locations.php endpoint with JavaScript payloads in the location_name field to execute arbitrary code in administrator…
AnalizadaMedia (6.9)0.19%—Nextclickventures Realtyscript16/3/202617/6/2026
Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create unauthorized user accounts and administrative users by crafting malicious forms. Attackers can submit hidden form data to /admin/addusers.php and /admin/editadmins.php endpoints to…
AnalizadaMedia (5.1)0.24%—Nextclickventures Realtyscript16/3/202617/6/2026
Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize CSV file uploads, allowing attackers to inject malicious scripts through filename parameters in multipart form data. Attackers can upload files with XSS payloads in the filename field to execute arbitrary JavaScript in users' browsers when the file is…
AnalizadaMedia (5.1)0.27%—Nextclickventures Realtyscript16/3/202617/6/2026
Next Click Ventures RealtyScript 4.0.2 fails to properly sanitize file uploads, allowing attackers to store malicious scripts through the file POST parameter in admin/tools.php. Attackers can upload files containing JavaScript code that executes in the context of admin/tools.php when accessed by other users.
AnalizadaMedia (5.1)0.27%—Nextclickventures Realtyscript16/3/202617/6/2026
Next Click Ventures RealtyScript 4.0.2 contains a cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and script code by injecting malicious input through multiple parameters that are not properly sanitized. Attackers can craft requests with injected script payloads in vulnerable…
AnalizadaMedia (6.9)0.18%—Nextclickventures Realtyscript16/3/202617/6/2026
Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabilities that allow attackers to perform administrative actions and inject malicious scripts. Attackers can craft malicious web pages that execute unauthorized actions when logged-in users visit them,…
AplazadaAlta (8.8)0.38%—Realty PortalAI21/11/202517/6/2026
The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'rp_save_property_settings' function in versions 0.1 to 0.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaAlta (7.5)0.21%—Realtyna Organic IDXAI20/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows PHP Local File Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through <= 5.0.0.
AplazadaAlta (8.1)0.40%—Simplerealtytheme Simple Login LOGAI20/8/202517/6/2026
Deserialization of Untrusted Data vulnerability in Max Chirkov Simple Login Log allows Object Injection. This issue affects Simple Login Log: from n/a through 1.1.3.
AplazadaAlta (8.8)0.46%—Realty PortalAI23/7/202517/6/2026
The Realty Portal – Agent plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within the rp_user_profile() AJAX handler in versions 0.1.0 through 0.3.9. The handler reads the client-supplied meta key and value pairs from $_POST and passes them directly to update_user_meta() without…
AplazadaAlta (8.1)0.58%—Real-web RealtyeliteAI27/6/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in real-web RealtyElite realtyelite allows PHP Local File Inclusion.This issue affects RealtyElite: from n/a through <= 1.0.0.
AplazadaAlta (7.1)0.32%—Realtyna ProvisioningAI3/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Realtyna Realtyna Provisioning realtyna-provisioning allows Reflected XSS.This issue affects Realtyna Provisioning: from n/a through <= 1.2.2.
AplazadaAlta (8.2)0.47%—Realtyworkstation Realty WorkstationAI21/1/202517/6/2026
Missing Authorization vulnerability in realtyworkstation Realty Workstation realty-workstation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Realty Workstation: from n/a through <= 1.0.45.
AplazadaAlta (7.1)0.17%—Realtycandy IDX Broker ExtendedAI2/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in RealtyCandy.com RealtyCandy IDX Broker Extended realtycandy-idx-broker-extended allows Stored XSS.This issue affects RealtyCandy IDX Broker Extended: from n/a through <= 1.5.1.
AplazadaMedia (6.5)0.25%—Bestwebsoft RealtyAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bestweblayout Realty by BestWebSoft realty allows Stored XSS.This issue affects Realty by BestWebSoft: from n/a through <= 1.1.5.