Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
565 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.54% | — | Responsive Slider GalleryAI | 30/9/2026 | 30/9/2026 | Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions. | |
| Aplazada | Media (6.4) | 0.16% | — | Nextendweb Smart Slider 3AI | 30/9/2026 | 30/9/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (6.5) | 0.21% | — | WP Review Slider PRO Wp-review-slider-proAI | 26/9/2026 | 28/9/2026 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not sanitize a value stored through one of its AJAX handlers, which lacks a capability check, before using it in a SQL statement, allowing any authenticated user, such as a subscriber, to perform SQL injection attacks whose results are then returned to… | |
| Aplazada | Alta (8) | 0.23% | — | WP Review Slider PRO Wp-review-slider-proAI | 26/9/2026 | 28/9/2026 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to overwrite a live form with field values that are… | |
| Aplazada | Alta (8) | 0.23% | — | WP Review Slider PRO Wp-review-slider-proAI | 26/9/2026 | 28/9/2026 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public… | |
| Aplazada | Alta (7.2) | 0.43% | — | Ljapps WP Yelp Review SliderAI | 22/9/2026 | 22/9/2026 | The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) in all versions up to, and including, 9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Baja (3.1) | 0.21% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options capability before saving image sizing settings, allowing users granted only its gallery-management capability by an administrator to change settings that apply across the whole site. | |
| Aplazada | Media (4.2) | 0.19% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an image owns the gallery it belongs to, allowing users granted its gallery-management capability by an administrator to delete, copy and re-tag any image on the site, including images in galleries belonging… | |
| Aplazada | Baja (2.7) | 0.30% | — | Photo Gallery Sliders Proofing ANDAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is entitled to a given image record before returning it, allowing users with the Contributor role and above to read the stored metadata of any image on the site, including images in galleries belonging to… | |
| Aplazada | Baja (3.1) | 0.21% | — | Photo Gallery Sliders Proofing AND WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery owns it, allowing any user granted its gallery-management capability by an administrator to overwrite the stored settings of any gallery on the site, including its filesystem path, and including… | |
| Aplazada | Alta (7.2) | 0.50% | — | Photo Gallery Sliders Proofing WordpressAI | 20/9/2026 | 21/9/2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to a variable being reused as a loop counter so that the check always passes, allowing users granted its gallery-management capability by an administrator… | |
| Aplazada | Media (6.8) | 0.24% | — | Masterstickies Master SliderAI | 20/9/2026 | 21/9/2026 | The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before outputting them in an inline script context, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when the affected post is viewed.… | |
| Aplazada | Media (6.8) | 0.29% | — | Codeinwp Ultimate Before After Image Slider AND GalleryAI | 2/9/2026 | 3/9/2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including… | |
| Aplazada | Media (6.8) | 0.29% | — | Ultimate Before After Image Slider GalleryAI | 2/9/2026 | 3/9/2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an… | |
| Aplazada | Media (6.4) | 0.32% | — | Nextendweb Smart Slider 3AI | 28/8/2026 | 28/8/2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in all versions up to, and including, 3.5.1.38 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Alta (8.8) | 0.51% | — | Slider Hero With Video Background AnimationAI | 22/8/2026 | 26/8/2026 | The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an… | |
| Aplazada | Media (6.8) | 0.43% | — | Post Grid Slider Carousel UltimateAI | 22/8/2026 | 26/8/2026 | The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any… | |
| Aplazada | Alta (7.4) | 0.17% | — | 10web SliderAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Depicter SliderAI | 18/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. | |
| Aplazada | Media (4.9) | 0.48% | — | Quantumcloud Slider HeroAI | 16/8/2026 | 20/8/2026 | The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7 via the qcld_sliderhero_duplicate() function. Slide data (description, title, btn, btn2, image_link, custom, etc.) is stored safely via $wpdb->update() with %s placeholders in the qchero_save_image… | |
| Aplazada | Media (6.4) | 0.35% | — | Cryoutcreations Serious SliderAI | 16/8/2026 | 20/8/2026 | The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (6.4) | 0.43% | — | MetasliderAI | 6/8/2026 | 12/8/2026 | The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'delay' Post Meta Setting in all versions up to, and including, 3.111.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.4) | 0.23% | — | Slick SliderAI | 6/8/2026 | 26/8/2026 | The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute when a user views the affected post. | |
| Aplazada | Media (4.9) | 0.51% | — | Ljapps WP Tripadvisor Review SliderAI | 5/8/2026 | 12/8/2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.36% | — | WP Responsive Thumbnail SliderAI | 1/8/2026 | 12/8/2026 | The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management() function, which echoes $_GET['id']… |