Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.24% | — | Restaurant Menu AND Food OrderingAI | 25/9/2026 | 25/9/2026 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.16% | — | Restaurant Menu AND Food OrderingAI | 4/9/2026 | 8/9/2026 | The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers to forge a payment notification and mark their own order as paid and completed without making any payment. | |
| Aplazada | Alta (8.1) | 0.47% | — | Motopress Restaurant MenuAI | 18/8/2026 | 20/8/2026 | Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Motopress Restaurant MenuAI | 26/6/2026 | 26/6/2026 | Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Fivestarplugins Five Star Restaurant MenuAI | 26/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Motopress Restaurant MenuAI | 26/6/2026 | 5/10/2026 | Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Motopress Mp-restaurant-menuAI | 18/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Retrieve Embedded Sensitive Data.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.7. | |
| Analizada | Baja (2.1) | 0.35% | — | Phpjabbers Restaurant Menu Maker | 23/9/2025 | 17/6/2026 | A weakness has been identified in PHPJabbers Restaurant Menu Maker up to 1.1. Affected by this issue is some unknown functionality of the file /preview.php. This manipulation of the argument theme causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and… | |
| Aplazada | Media (5.9) | 0.22% | — | Will.i.am Simple Restaurant MenuAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Will.I.am Simple Restaurant Menu simple-restaurant-menu allows Stored XSS.This issue affects Simple Restaurant Menu: from n/a through <= 1.2. | |
| Aplazada | Media (6.5) | 0.21% | — | Best Restaurant Menu BY PricelistoAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PriceListo Best Restaurant Menu by PriceListo best-restaurant-menu-by-pricelisto allows Stored XSS.This issue affects Best Restaurant Menu by PriceListo: from n/a through <= 1.4.3. | |
| Aplazada | Media (4.3) | 0.16% | — | Easy Restaurant Menu ManagerAI | 13/8/2025 | 17/6/2026 | The Easy restaurant menu manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing or incorrect nonce validation on the nsc_eprm_save_menu() function. This makes it possible for unauthenticated attackers to upload a menu file via a… | |
| Aplazada | Media (5.4) | 0.14% | — | Motopress Mp-restaurant-menuAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Cross Site Request Forgery.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.6. | |
| Aplazada | Media (6.4) | 0.26% | — | Easy Restaurant Menu ManagerAI | 4/7/2025 | 17/6/2026 | The Easy restaurant menu manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's nsc_eprm_menu_link shortcode in versions up to, and including 2.0.1, due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.1) | 1.1% | — | Exthemes WP Food Ordering AND Restaurant MenuAI | 11/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Exthemes WP Food ordering and Restaurant Menu wp-food allows PHP Local File Inclusion.This issue affects WP Food ordering and Restaurant Menu: from n/a through <= 2.7. | |
| Aplazada | Alta (8.8) | 0.75% | — | Motopress Mp-restaurant-menuAIPHPAI | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows PHP Local File Inclusion.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.4. | |
| Aplazada | Media (4.3) | 0.35% | — | Best Restaurant Menu BY PricelistoAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in PriceListo Best Restaurant Menu by PriceListo best-restaurant-menu-by-pricelisto.This issue affects Best Restaurant Menu by PriceListo: from n/a through <= 1.4.2. | |
| Analizada | Media (6.1) | 0.32% | — | Oracle Restaurant Menu - Food Ordering System - Table Reservation | 20/11/2024 | 17/6/2026 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.5) | 0.39% | — | Marco Piarulli MY Restaurant MenuAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Piarulli My Restaurant Menu my-restaurant-menu allows Stored XSS.This issue affects My Restaurant Menu: from n/a through <= 0.2.0. | |
| Aplazada | Media (6.5) | 0.39% | — | Shahjahan Jewel Trendy Restaurant MenuAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjahan Jewel Trendy Restaurant Menu trendy-restaurant-menu allows DOM-Based XSS.This issue affects Trendy Restaurant Menu: from n/a through <= 1.0.0. | |
| Analizada | Alta (8.8) | 1.2% | — | Pricelisto Great Restaurant Menu WP | 29/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PriceListo Best Restaurant Menu by PriceListo allows SQL Injection.This issue affects Best Restaurant Menu by PriceListo: from n/a through 1.4.1. | |
| Aplazada | Media (6.4) | 0.27% | — | Restaurant Menu Food Ordering System Table ReservationAI | 15/6/2024 | 17/6/2026 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (4.3) | 0.36% | — | Fivestarplugins Five Star Restaurant Menu | 5/6/2024 | 17/6/2026 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_item', and 'add_menu_page' functions in all versions up to, and including, 2.4.16. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.32% | — | Gloriafood Restaurant Menu Food Ordering System Table ReservationAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GloriaFood Restaurant Menu – Food Ordering System – Table Reservation allows Stored XSS.This issue affects Restaurant Menu – Food Ordering System – Table Reservation: from n/a through 2.4.1. | |
| Aplazada | Media (6.5) | 0.32% | — | Fivestarplugins Five Star Restaurant MenuAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Menu allows Stored XSS.This issue affects Five Star Restaurant Menu: from n/a through 2.4.14. | |
| Modificada | Media (5.4) | 0.31% | — | Fivestarplugins Five Star Restaurant Menu | 5/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue affects Five Star Restaurant Reviews: from n/a through 2.3.5. |