Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.30% | — | Gingerplugins Sticky Chat WidgetAI | 11/9/2026 | 11/9/2026 | The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Gingerplugins Sticky Chat WidgetAI | 18/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. | |
| Aplazada | Media (6.4) | 0.33% | — | Flarum StickyAI | 20/5/2026 | 24/7/2026 | The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmoretext` attribute in versions up to and including 2.5.6. This is due to insufficient input sanitization and output escaping in the `cvmh_sticky_front_render()` function — the `readmoretext` attribute… | |
| Aplazada | Alta (8.7) | 0.28% | — | Sticky Notes WidgetAI | 16/5/2026 | 17/6/2026 | Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an application crash… | |
| Aplazada | Alta (8.7) | 0.28% | — | Sticky Notes AND Color WidgetsAI | 16/5/2026 | 17/6/2026 | Sticky Notes & Color Widgets 1.4.2 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can paste large payloads of repeated characters into note fields to trigger application crashes and make the application stop… | |
| Aplazada | Alta (7.5) | 0.56% | — | Premio MY Sticky BARAI | 12/3/2026 | 17/6/2026 | The My Sticky Bar plugin for WordPress is vulnerable to SQL injection via the `stickymenu_contact_lead_form` AJAX action in all versions up to, and including, 2.8.6. This is due to the handler using attacker-controlled POST parameter names directly as SQL column identifiers in `$wpdb->insert()`. While parameter values… | |
| Aplazada | Media (4.3) | 0.13% | — | Sticky Action ButtonsAI | 7/1/2026 | 17/6/2026 | The Sticky Action Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on the sabs_options_page_form_submit() function. This makes it possible for unauthenticated attackers to update plugin settings via… | |
| Aplazada | Media (4.3) | 0.30% | — | Premio MY Sticky ElementsAI | 1/1/2026 | 17/6/2026 | The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'my_sticky_elements_bulks' function in all versions up to, and including, 2.3.3. This makes it possible… | |
| Aplazada | Media (4.3) | 0.21% | — | Webbuilder143 Sticky Notes FOR WP DashboardAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in Web Builder 143 Sticky Notes for WP Dashboard wb-sticky-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Notes for WP Dashboard: from n/a through <= 1.2.4. | |
| Aplazada | Media (4.3) | 0.29% | — | Premio MY Sticky ElementsAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Premio My Sticky Elements mystickyelements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Sticky Elements: from n/a through <= 2.3.3. | |
| Aplazada | Media (4.3) | 0.24% | — | Posimyth Sticky Header Effects FOR ElementorAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in POSIMYTH Sticky Header Effects for Elementor sticky-header-effects-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Header Effects for Elementor: from n/a through <= 2.1.2. | |
| Analizada | Baja (3.3) | 0.21% | — | Maevelander Sticky Side Buttons | 3/9/2025 | 17/6/2026 | The Sticky Side Buttons WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Alta (7.1) | 0.21% | — | Lambertgroup Apollo Sticky Full Width Html5 Audio PlayerAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Apollo - Sticky Full Width HTML5 Audio Player lbg-audio5-html5-shoutcast-sticky allows Reflected XSS.This issue affects Apollo - Sticky Full Width HTML5 Audio Player: from n/a through <= 3.4. | |
| Aplazada | Media (4.3) | 0.15% | — | Blend Media CTA Easy Sticky SidebarAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Blend Media WordPress CTA easy-sticky-sidebar allows Cross Site Request Forgery.This issue affects WordPress CTA: from n/a through <= 1.7.0. | |
| Aplazada | Media (5.9) | 0.26% | — | Sandor Kovacs Simple Sticky FooterAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sandor Kovacs Simple Sticky Footer simple-sticky-footer allows Stored XSS.This issue affects Simple Sticky Footer : from n/a through <= 1.3.5. | |
| Aplazada | Media (6.1) | 0.13% | — | ZEN Sticky SocialAI | 14/6/2025 | 17/6/2026 | The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to missing or incorrect nonce validation on the 'zen-social-sticky/zen-sticky-social.php' page. This makes it possible for unauthenticated attackers to update settings and… | |
| Aplazada | Alta (7.1) | 0.28% | — | Lambertgroup Sticky Radio PlayerAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Sticky Radio Player lbg-audio5-html5-shoutcast_sticky allows Reflected XSS.This issue affects Sticky Radio Player: from n/a through <= 3.4. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Chimpstudio Foodbakery Sticky CartAI | 19/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart foodbakery-sticky-cart allows Object Injection.This issue affects Foodbakery Sticky Cart: from n/a through <= 3.2. | |
| Aplazada | Alta (8.5) | 0.32% | — | Lambertgroup Sticky Html5 Music PlayerAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky HTML5 Music Player lbg-audio3-html5 allows SQL Injection.This issue affects Sticky HTML5 Music Player: from n/a through <= 3.1.6. | |
| Aplazada | Alta (8.5) | 0.32% | — | Lambertgroup Sticky Radio PlayerAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky Radio Player lbg-audio5-html5-shoutcast_sticky allows SQL Injection.This issue affects Sticky Radio Player: from n/a through <= 3.4. | |
| Analizada | Media (4.8) | 0.34% | — | Premio MY Sticky BAR | 15/5/2025 | 17/6/2026 | The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html… | |
| Aplazada | Alta (7.1) | 0.15% | — | Mustafa Kucuk WP Sticky Side ButtonsAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mustafa KUCUK WP Sticky Side Buttons wp-sticky-side-buttons allows Stored XSS.This issue affects WP Sticky Side Buttons: from n/a through <= 2.1. | |
| Aplazada | Media (4.3) | 0.39% | — | Sharaz Shahid Simple Sticky ADD TO Cart FOR WoocommerceAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Sharaz Shahid Simple Sticky Add To Cart For WooCommerce sticky-add-to-cart-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Sticky Add To Cart For WooCommerce: from n/a through <= 1.4.9. | |
| Aplazada | Media (6.5) | 0.26% | — | Bplugins Sticky ContentAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Sticky Content sticky-menu-block allows Stored XSS.This issue affects Sticky Content: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.4) | 0.28% | — | Hardik Sticky Header ON ScrollAI | 24/2/2025 | 17/6/2026 | Missing Authorization vulnerability in Hardik Sticky Header On Scroll sticky-header-on-scroll allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Header On Scroll: from n/a through <= 1.0. |