Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.25% | — | Wedevs WP Project ManagerAI | 1/10/2026 | 1/10/2026 | Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions. | |
| Aplazada | Media (6.5) | 0.38% | — | WP Project Manager PROAI | 25/8/2026 | 28/9/2026 | The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wedevs WP Project ManagerAI | 24/8/2026 | 27/8/2026 | Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | WP Project Manager PROAI | 24/8/2026 | 24/8/2026 | Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions. | |
| Aplazada | Media (6.5) | 0.26% | — | Wedevs WP Project ManagerAI | 29/12/2025 | 1/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 3.0.1. | |
| Aplazada | Media (6.5) | 0.28% | — | Wedevs WP Project ManagerAI | 15/11/2025 | 17/6/2026 | The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘completed_at_operator’ parameter in all versions up to, and including, 2.6.26 due to insufficient escaping on the user supplied… | |
| Aplazada | Media (5.3) | 0.29% | — | Wedevs WP Project ManagerAI | 22/9/2025 | 30/9/2026 | Use of Hard-coded Credentials vulnerability in weDevs WP Project Manager wedevs-project-manager allows Retrieve Embedded Sensitive Data.This issue affects WP Project Manager: from n/a through <= 2.6.25. | |
| Analizada | Media (5.4) | 0.31% | — | Wedevs WP Project Manager | 11/4/2025 | 17/6/2026 | The WP Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Analizada | Media (5.4) | 0.28% | — | Wedevs WP Project Manager | 9/4/2025 | 17/6/2026 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.22 due to insufficient input sanitization and output escaping in tasks discussion.… | |
| Modificada | Alta (8.8) | 0.17% | — | Wedevs WP Project Manager | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager wedevs-project-manager allows Cross Site Request Forgery.This issue affects WP Project Manager: from n/a through < 2.6.25. | |
| Modificada | Media (4.8) | 0.27% | — | Wedevs WP Project Manager | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager wedevs-project-manager allows Stored XSS.This issue affects WP Project Manager: from n/a through <= 2.6.22. | |
| Analizada | Media (6.5) | 0.43% | — | Wedevs WP Project Manager | 15/2/2025 | 17/6/2026 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.6.17 due to insufficient escaping on the user supplied parameter and lack of… | |
| Analizada | Media (6.5) | 0.52% | — | Wedevs WP Project Manager | 15/2/2025 | 17/6/2026 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check in the '/pm/v2/settings/notice' endpoint all versions up to, and including, 2.6.17. This makes it possible for… | |
| Analizada | Media (6.5) | 0.43% | — | Wedevs WP Project Manager | 4/1/2025 | 17/6/2026 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to SQL Injection via the 'project_id' parameter of the /wp-json/pm/v2/projects/2/task-lists REST API endpoint in all versions up to, and including, 2.6.16 due to insufficient… | |
| Analizada | Media (6.5) | 0.40% | — | Wedevs WP Project Manager | 19/12/2024 | 17/6/2026 | The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task List ('/wp-json/pm/v2/projects/1/task-lists') REST API endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Modificada | Crítica (9.8) | 0.50% | — | Wedevs WP Project Manager | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in weDevs WP Project Manager wedevs-project-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Project Manager: from n/a through <= 2.6.7. | |
| Analizada | Media (5.3) | 0.32% | — | Wedevs WP Project Manager | 20/11/2024 | 17/6/2026 | The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'check' method of the 'Create_Milestone', 'Create_Task_List', 'Create_Task', and 'Delete_Task' classes in version 2.6.14. This makes it possible for unauthenticated attackers to… | |
| Analizada | Alta (7.3) | 0.66% | — | Wedevs WP Project Manager | 13/11/2024 | 17/6/2026 | The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.13 via the 'Abstract_Permission' class due to missing validation on the 'user_id' user controlled… | |
| Modificada | Media (5.4) | 0.39% | — | Wedevs WP Project Manager | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts allows Stored XSS.This issue affects WP Project Manager – Task, team, and project management plugin… | |
| Modificada | Crítica (9.8) | 0.68% | — | Wedevs WP Project Manager | 3/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a through 2.6.0. | |
| Modificada | Alta (8.8) | 0.86% | — | Wedevs WP Project Manager | 31/8/2023 | 17/6/2026 | The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role… | |
| Modificada | Alta (8.8) | 0.44% | — | Wedevs WP Project Manager | 1/7/2023 | 17/6/2026 | The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missing or incorrect nonce validation on the do_updates() function. This makes it possible for unauthenticated attackers to trigger updates via a forged request granted they… | |
| Modificada | Media (5.4) | 0.62% | — | Wedevs WP Project Manager | 4/4/2022 | 17/6/2026 | Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerability in weDevs WP Project Manager plugin <= 2.4.13 versions. |