Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3037▲ 502 respecto a la semana anterior
Críticas / altas1448▲ 249 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 158 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.41% | — | Smashballoon Custom Twitter FeedsAI | 18/9/2026 | 18/9/2026 | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute in all versions up to, and including, 2.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.7) | 0.29% | — | Twitter Secure HeadersAI | 17/7/2026 | 23/7/2026 | secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_directive, build_media_type_list_directive, and build_report_to_directive interpolate caller-supplied… | |
| Aplazada | Media (5.1) | 0.15% | — | Easy Twitter FeedsAI | 10/6/2026 | 23/7/2026 | Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated user into visiting a crafted link that duplicates any post regardless of post type. | |
| Aplazada | Alta (8.8) | 0.34% | — | Twitter-cloneAI | 25/5/2026 | 23/7/2026 | Twitter-Clone 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the name parameter. Attackers can submit crafted payloads to the search.php endpoint to extract database information including usernames, credentials, and… | |
| Aplazada | Media (5.3) | 0.20% | — | Twitter-cloneAI | 25/5/2026 | 23/7/2026 | Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to delete posts by crafting malicious HTML forms. Attackers can create hidden forms targeting tweetdel.php with tweet IDs and automatically submit them to delete arbitrary posts from authenticated user… | |
| Aplazada | Alta (8.8) | 0.31% | — | Twitter-clone Twitter CloneAI | 25/5/2026 | 23/7/2026 | Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code through the userid parameter. Attackers can submit union-based or time-based blind SQL injection payloads to extract sensitive database information including usernames,… | |
| Aplazada | Alta (7.2) | 0.51% | — | Smashballoon Custom Twitter FeedsAI | 13/5/2026 | 17/6/2026 | The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elements::get_post_text() function when rendering cached tweet text. The plugin's ctf_get_more_posts AJAX action is available… | |
| Aplazada | Media (6.4) | 0.19% | — | Twitter FeedsAI | 21/3/2026 | 17/6/2026 | The Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tweet_title' parameter in the 'TwitterFeeds' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.52% | — | Nextscripts Social-networks-auto-poster-facebook-twitter-gAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7. | |
| Aplazada | Media (5.4) | 0.22% | — | 10up Autoshare FOR TwitterAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in 10up Autoshare for Twitter autoshare-for-twitter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoshare for Twitter: from n/a through <= 2.3.1. | |
| Aplazada | Media (6.5) | 0.30% | — | Twitter Posts TO BlogAI | 11/2/2026 | 17/6/2026 | The Twitter posts to Blog plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dg_tw_options' function in all versions up to, and including, 1.11.25. This makes it possible for unauthenticated attackers to update plugin settings including Twitter API… | |
| Aplazada | Alta (7.1) | 0.18% | — | Zckevin Zhina Twitter WidgetAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zckevin ZhinaTwitterWidget zhina-twitter-widget allows Reflected XSS.This issue affects ZhinaTwitterWidget: from n/a through <= 1.0. | |
| Aplazada | Media (6.1) | 0.25% | — | WP Twitter Auto PublishAI | 18/11/2025 | 17/6/2026 | The WP Twitter Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.4) | 0.18% | — | Devbuddy Twitter FeedAI | 11/11/2025 | 17/6/2026 | The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ottwitter_feed' shortcode in all versions up to, and including, 1.3.1. This is due to the plugin not properly sanitizing user input and output of the 'width' and 'height' parameters. This makes it possible for authenticated… | |
| Aplazada | Media (5.9) | 0.22% | — | Khashabawy Tli.tl Auto Twitter PosterAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in khashabawy tli.tl auto Twitter poster tlitl-auto-twitter-poster allows Stored XSS.This issue affects tli.tl auto Twitter poster: from n/a through <= 3.4. | |
| Aplazada | Alta (7.1) | 0.13% | — | Ultimate Twitter Profile WidgetAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in dyiosah Ultimate twitter profile widget ultimate-twitter-profile-widget allows Stored XSS.This issue affects Ultimate twitter profile widget: from n/a through <= 1.0. | |
| Analizada | Media (5.4) | 0.31% | — | Mohsinrasool Twitter Bootstrap Collapse AKA Accordian Shortcode | 15/5/2025 | 17/6/2026 | The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting… | |
| Modificada | Baja (3.5) | 0.19% | — | Reneade Twitterposts | 15/5/2025 | 17/6/2026 | The TwitterPosts WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Alta (7.1) | 0.16% | — | Corbyboy Marketing Twitter BOT | 15/5/2025 | 17/6/2026 | The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Aplazada | Media (6.5) | 0.20% | — | Edward Caissie BNS Twitter Follow ButtonAI | 12/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edward Caissie BNS Twitter Follow Button bns-twitter-follow-button allows DOM-Based XSS.This issue affects BNS Twitter Follow Button: from n/a through <= 0.3.8. | |
| Aplazada | Alta (7.1) | 0.14% | — | Silencecm Twitter Card GeneratorAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in silencecm Twitter Card Generator twitter-card-generator allows Stored XSS.This issue affects Twitter Card Generator: from n/a through <= 1.0.5. | |
| Aplazada | Media (6.5) | 0.26% | — | Oniswap Mini Twitter FeedAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oniswap Mini twitter feed mini-twitter-feed allows Stored XSS.This issue affects Mini twitter feed: from n/a through <= 3.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | Ruudkok WP Twitter ButtonAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ruudkok WP Twitter Button wp-twitter-button allows Stored XSS.This issue affects WP Twitter Button: from n/a through <= 1.4.1. | |
| Aplazada | Media (6.5) | 0.22% | — | Arrowplugins Arrow Custom Feed FOR TwitterAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arrow Plugins Arrow Custom Feed for Twitter arrow-twitter-feed allows Stored XSS.This issue affects Arrow Custom Feed for Twitter: from n/a through <= 1.5.3. | |
| Aplazada | Media (4.3) | 0.20% | — | Smashballoon Custom Twitter FeedsAI | 20/3/2025 | 17/6/2026 | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.5. This is due to missing or incorrect nonce validation on the ctf_clear_cache_admin() function. This makes it possible for unauthenticated attackers to… |