Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 74 respecto a la semana anterior
Críticas / altas1464▲ 358 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)89▼ 424 respecto a la semana anterior
99 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.19% | — | Viable URL Media UploaderAI | 30/9/2026 | 30/9/2026 | The Viable URL Media Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Multi Uploader FOR Gravity FormsAI | 17/9/2026 | 19/9/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload… | |
| Aplazada | Media (6.5) | 0.41% | — | Image Uploader FOR WelcartAI | 15/8/2026 | 20/8/2026 | The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.32% | — | Peprodev Woocommerce Receipt UploaderAI | 6/8/2026 | 26/8/2026 | The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they… | |
| Aplazada | Crítica (9.1) | 0.66% | — | Gravity Forms Multi Uploader Multi Uploader FOR Gravity FormsAI | 5/8/2026 | 12/8/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via `wp_ajax_nopriv_gfmu_delete_file`. The nonce… | |
| Aplazada | Media (4.3) | 0.41% | — | MUX Video UploaderAI | 11/7/2026 | 13/7/2026 | The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive data including Mux API… | |
| Aplazada | Alta (8.7) | 0.64% | — | PhpuploaderAI | 29/6/2026 | 14/7/2026 | phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result… | |
| Analizada | Media (5.1) | 0.24% | — | Avatar Uploader Project Avatar Uploader | 10/5/2026 | 24/7/2026 | Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Attackers can craft URLs with script payloads in the file parameter of avatar_uploader.pages.inc to execute arbitrary… | |
| Aplazada | Crítica (9.8) | 6.1% | — | Fohrloop Dash-uploaderAI | 8/5/2026 | 17/6/2026 | Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, BaseHttpRequestHandler.get_temp_root(), BaseHttpRequestHandler._post() components. | |
| Modificada | Alta (7.5) | 2.8% | — | Fohrloop Dash-uploader | 8/5/2026 | 17/6/2026 | Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-upload handler (dash_uploader/httprequesthandler.py, dash_uploader/upload.py) trusts unsanitized, attacker-controlled upload parameters (e.g. flowTotalChunks) and does not enforce the documented… | |
| Aplazada | Alta (7.5) | 0.43% | — | Snowray Software File Uploader FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader for WooCommerce: from n/a through <= 1.0.4. | |
| Aplazada | Crítica (9.8) | 0.73% | — | File Uploader FOR WoocommerceAI | 20/12/2025 | 17/6/2026 | The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback function for the 'add-image-data' REST API endpoint in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to upload arbitrary… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Multi Uploader FOR Gravity FormsAI | 12/12/2025 | 17/6/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'plupload_ajax_delete_file' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the… | |
| Aplazada | Media (4.3) | 0.23% | — | Apprhyme URL Media UploaderAI | 12/12/2025 | 17/6/2026 | The URL Media Uploader plugin for WordPress is vulnerable to unauthorized safe file uploads due to a missing capability check on the url_media_uploader_url_upload_ajax_handler() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Crítica (10) | 0.43% | — | Borisolhor Drop Uploader FOR CF7AI | 6/11/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in borisolhor Drop Uploader for CF7 - Drag&Drop File Uploader Addon drop-uploader-for-contact-form-7-dragdrop-file-uploader-addon allows Upload a Web Shell to a Web Server.This issue affects Drop Uploader for CF7 - Drag&Drop File Uploader Addon: from n/a… | |
| Aplazada | Alta (8.8) | 0.32% | — | Tagfree X-free UploaderAI | 7/8/2025 | 17/6/2026 | : External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This issue affects X-Free Uploader: from 1.0.1.0084 before 1.0.1.0085, from 2.0.1.0034 before 2.0.1.0035. | |
| Aplazada | Alta (8.7) | 0.42% | — | Tagfree X-free UploaderAI | 7/8/2025 | 17/6/2026 | : Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploader XFU allows Path Traversal.This issue affects X-Free Uploader: from 1.0.1.0084 before 1.0.1.0085, from 2.0.1.0034 before 2.0.1.0035. | |
| Analizada | Media (5.4) | 0.30% | — | Grandplugins Avif Uploader | 15/5/2025 | 17/6/2026 | The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |
| Modificada | Media (6.4) | 0.29% | — | Apprhyme URL Media Uploader | 28/2/2025 | 17/6/2026 | The URL Media Uploader plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.0 via the 'url_media_uploader_url_upload' action. This makes it possible for authenticated attackers, with author-level access and above, to make web requests to arbitrary locations… | |
| Aplazada | Media (6.5) | 0.30% | — | Rpldy UploaderAI | 5/2/2025 | 17/6/2026 | A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload. | |
| Analizada | Crítica (9.1) | 0.53% | — | Ivanm WP Image Uploader | 30/1/2025 | 17/6/2026 | The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the gky_image_uploader_main_function() function in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server,… | |
| Analizada | Alta (8.1) | 0.24% | — | Ivanm WP Image Uploader | 30/1/2025 | 17/6/2026 | The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the gky_image_uploader_main_function() function. This makes it possible for unauthenticated attackers to delete arbitrary files via… | |
| Aplazada | Media (6.1) | 0.29% | — | Ivanm WP Image UploaderAI | 30/1/2025 | 17/6/2026 | The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Crítica (9) | 0.53% | — | Sh1zen Multi Uploader FOR Gravity FormsAIGravityforms Gravity FormsAI | 22/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in sh1zen Multi Uploader for Gravity Forms gf-multi-uploader allows Upload a Web Shell to a Web Server.This issue affects Multi Uploader for Gravity Forms: from n/a through <= 1.1.3. | |
| Aplazada | Media (6.1) | 0.48% | — | Peprodev Woocommerce Receipt UploaderAI | 16/11/2024 | 17/6/2026 | The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.6.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… |