Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.5) | 0.14% | — | ALL IN ONE Schemas Schema AND Structured Data FOR WP AND AMPAI | 30/9/2026 | 30/9/2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the… | |
| Aplazada | Baja (2.7) | 0.30% | — | WP AMP Schema AND Structured Data FOR WP AND AMPAI | 16/9/2026 | 17/9/2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the specific post they request schema generation for, allowing users with the contributor role and above to obtain the content of other users' draft, pending, private and password protected posts. | |
| Aplazada | Media (5.3) | 0.32% | — | Schema AND Structured Data FOR WP AND AMPAI | 16/9/2026 | 17/9/2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a comment before returning its content, allowing unauthenticated users to read the content of comments still awaiting moderation or marked as spam. | |
| Aplazada | Crítica (9.1) | 0.45% | 💥 PoC | Schema AND Structured Data FOR WP AND AMPAI | 10/6/2026 | 23/7/2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded files against the endpoint's intended media type, allowing unauthenticated users to upload any file type accepted by… | |
| Aplazada | Media (6.4) | 0.27% | — | Schema AND Structured Data FOR WP AND AMPAI | 23/1/2026 | 17/6/2026 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saswp_custom_schema_field' profile field in all versions up to, and including, 1.54 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.1) | 0.21% | — | Schema AND Structured Data FOR WP AND AMPAI | 1/10/2025 | 17/6/2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.50 does not properly handles HTML tag attribute modifications, making it possible for unauthenticated attackers to conduct Stored XSS attacks via post comments. | |
| Aplazada | Media (5.3) | 0.34% | — | Magazine3 Schema AND Structured Data FOR WP AND AMPAI | 24/10/2024 | 17/6/2026 | Missing Authorization vulnerability in Magazine3 Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Schema & Structured Data for WP & AMP: from n/a through <= 1.3.5. | |
| Aplazada | Media (6.4) | 0.33% | — | Schema AND Structured Data FOR WP AND AMPAI | 23/4/2024 | 17/6/2026 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's "How To" and "FAQ" Blocks in all versions up to, and including, 1.29 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… |