Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
632 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.28% | — | Ultimatemember Ultimate MemberAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects Ultimate Member: from n/a through 2.13.1. | |
| Aplazada | Media (5.3) | 0.20% | — | Smackcoders WP Ultimate CSV ImporterAI | 1/10/2026 | 1/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate CSV Importer: from n/a through 9.1. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Ultimate MultisiteAI | 1/10/2026 | 1/10/2026 | The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible… | |
| Aplazada | Media (6.5) | 0.16% | — | Supsystic Ultimate MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. | |
| Aplazada | Alta (7.2) | 0.40% | — | Themefic Ultimate Addons FOR Contact Form 7AI | 30/9/2026 | 30/9/2026 | Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Supsystic Ultimate MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions. | |
| Aplazada | Media (6.5) | 0.16% | — | Contact Form 7AIThemefic Ultimate Addons FOR Contact Form 7AI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Etoilewebdesign Ultimate FAQAI | 23/9/2026 | 23/9/2026 | Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions. | |
| Aplazada | Alta (8.1) | 0.36% | — | Wpmet WP Ultimate ReviewAI | 22/9/2026 | 22/9/2026 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 0.51% | — | Ultimatemember Ultimate MemberAI | 19/9/2026 | 21/9/2026 | The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, and decodes HTML entities in it after its own sanitisation has already run, allowing unauthenticated attackers who register an account to store JavaScript that… | |
| Aplazada | Alta (7.5) | 0.26% | — | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not have any authorisation check when displaying gift card details, allowing unauthenticated users to retrieve the gift cards attached to arbitrary orders and disclose customer personal data, balances, dates and, in 3.2.9, the live redemption… | |
| Aplazada | Alta (7.5) | 0.21% | — | Ultimate Gift CardsAI | 10/9/2026 | 10/9/2026 | The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not reconcile the value of the gift card coupon it issues against the amount actually collected at checkout, allowing unauthenticated users to obtain store credit worth more than they paid. | |
| Aplazada | Media (6.5) | 0.30% | — | Ultimate Gift CardsAI | 9/9/2026 | 9/9/2026 | The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not verify that the user redeeming a gift card is its intended recipient, allowing any authenticated user, such as a subscriber, to redeem gift cards belonging to other users, zeroing their balance and crediting the value to themselves. In… | |
| Aplazada | Media (5.3) | 0.29% | — | Supsystic Ultimate MapsAI | 3/9/2026 | 5/9/2026 | Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3. | |
| Aplazada | Media (5.3) | 0.31% | — | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 2/9/2026 | 2/9/2026 | Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions. | |
| Aplazada | Media (5.3) | 0.23% | — | Ultimatemember Ultimate MemberAI | 2/9/2026 | 3/9/2026 | The Ultimate Member WordPress plugin before 2.13.0 does not check whether a comment has been approved, or whether the profile it belongs to is private, before returning profile activity to unauthenticated visitors, allowing them to read the content of comments still awaiting moderation. | |
| Aplazada | Media (6.8) | 0.29% | — | Codeinwp Ultimate Before After Image Slider AND GalleryAI | 2/9/2026 | 3/9/2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including… | |
| Aplazada | Media (6.8) | 0.29% | — | Ultimate Before After Image Slider GalleryAI | 2/9/2026 | 3/9/2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an… | |
| Aplazada | Media (5.3) | 0.41% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal. | |
| Aplazada | Alta (8.9) | 0.43% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict MIME verification and GD binary raster… | |
| Aplazada | Alta (8.6) | 0.42% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual escaping, allowing injection of malicious… | |
| Aplazada | Media (5.1) | 0.39% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or core.admin). An authenticated user could submit… | |
| Aplazada | Media (5.1) | 0.39% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized to edit the article ID passed in the request, but did not verify whether the specified image path (src) belonged to that article. On… | |
| Aplazada | Media (4.1) | 0.31% | — | Smackcoders WP Ultimate CSV ImporterAI | 29/8/2026 | 31/8/2026 | The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. | |
| Aplazada | Alta (8.1) | 0.23% | — | Ultimatemember Ultimate MemberAI | 28/8/2026 | 28/8/2026 | The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register… |