Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
717 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.27% | — | Smashballoon Social Post FeedAI | 2/10/2026 | 2/10/2026 | The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message via v-html in Admin Builder Preview in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Alta (7.6) | 0.30% | — | Social BoostAI | 1/10/2026 | 1/10/2026 | Subscriber Broken Access Control in Social Boost <= 3.6.2 versions. | |
| Aplazada | Media (6.1) | 0.29% | — | Social Media Share Buttons Social Sharing IconsAI | 1/10/2026 | 1/10/2026 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (5.9) | 0.19% | — | Nextscripts Social Networks Auto PosterAI | 27/9/2026 | 28/9/2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials,… | |
| Aplazada | Media (4.3) | 0.32% | — | Adenion Blog2socialAI | 25/9/2026 | 25/9/2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Pendiente de análisis | Media (4.2) | 0.16% | — | Python Social AuthAI | 24/9/2026 | 30/9/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it. Applications using resumable partial pipeline steps could allow an attacker to… | |
| Pendiente de análisis | Alta (7.4) | 0.16% | — | Python Social AuthAI | 24/9/2026 | 28/9/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. Applications using this backend could treat unsigned attacker-controlled data as a… | |
| Pendiente de análisis | Media (4.3) | 0.11% | — | Python Social AuthAI | 24/9/2026 | 25/9/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login CSRF. An attacker could cause a victim's browser session to complete authentication… | |
| Pendiente de análisis | Media (6.8) | 0.22% | — | Python Social AuthAI | 24/9/2026 | 29/9/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same application, users from different shops with the same internal Vend user ID could… | |
| Pendiente de análisis | Media (6.4) | 0.23% | — | Python Social AuthAI | 24/9/2026 | 25/9/2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `AuthnRequest`. Applications using SAML account association could allow an attacker… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Moodle SocialwallAI | 23/9/2026 | 24/9/2026 | SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests | |
| Aplazada | Media (5.3) | 0.18% | — | Social Commerce FOR WoocommerceAI | 23/9/2026 | 23/9/2026 | The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to update Social Commerce for WooCommerce WordPress plugin through 2.5.4 configuration and product synchronisation state. | |
| Aplazada | Media (4.4) | 0.21% | — | Wp2social Auto PublishAI | 19/9/2026 | 21/9/2026 | The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Media (5.3) | 0.30% | — | Adenion Blog2socialAI | 16/9/2026 | 24/9/2026 | Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_posts table using only the attacker-supplied b2s_id primary key with no blog_user_id… | |
| Aplazada | Media (5.3) | 0.28% | — | Adenion Blog2socialAI | 16/9/2026 | 24/9/2026 | Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php invokes B2S_Tools::searchUser() in includes/Tools.php, which returns the email address of every matching user without… | |
| Aplazada | Media (5.3) | 0.28% | — | Adenion Blog2socialAI | 16/9/2026 | 24/9/2026 | Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs supplied in the owner parameter to display names without verifying that the caller is authorized to… | |
| Aplazada | Media (5.1) | 0.34% | — | Yamap - Social Trekking GPS APPAI | 14/9/2026 | 16/9/2026 | The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. The in-app browser may cause information leakage from the app or redirect users to unintended websites. | |
| Aplazada | Alta (7.1) | 0.35% | — | Avideo SocialmediapublisherAIWwbn AvideoAI | 8/9/2026 | 8/9/2026 | AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to overwrite another user's stored… | |
| Aplazada | Media (6.4) | 0.20% | — | Social Chat Click TO Chat APP ButtonAI | 5/9/2026 | 8/9/2026 | The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.18% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button.… | |
| Aplazada | Media (6.8) | 0.29% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wordpress Social Login AND RegisterAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Social Media AND Share IconsAI | 24/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions. | |
| Aplazada | Crítica (9.8) | 0.63% | — | Soclever Social Login Sharing Buttons With AnalyticsAI | 22/8/2026 | 26/8/2026 | The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators.… | |
| Aplazada | Crítica (9.8) | 0.50% | — | WP Social Media LoginAI | 22/8/2026 | 26/8/2026 | The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by supplying that user's email address. |