WordPress · Blocksy Companion
CVE-2026-15158: CWE-434: vulnerabilidad de seguridad en Blocksy Companion
El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en Blocksy Companion. Blocksy Companion: 0 hasta 2.1.46
DIRECTORIO CVE · 2026
Página 92 de 163. Los registros están ordenados por fecha oficial de publicación, del más reciente al más antiguo.
Registros 9101–9200 de 16.277
WordPress · Blocksy Companion
El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en Blocksy Companion. Blocksy Companion: 0 hasta 2.1.46
WordPress · Connect Contact Form 7 and Mailchimp
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Connect Contact Form 7 and Mailchimp. Connect Contact Form 7 and Mailchimp: 0 hasta 0.9.78.06
WordPress · Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder. Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder: 0 hasta 3.1.1
WordPress · Download Manager
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Download Manager. Download Manager: 0 hasta 3.3.61
WordPress · Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails. Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails: 0 hasta 1.24.2
WordPress · miniOrange OTP Login, Verification and SMS Notifications
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en miniOrange OTP Login, Verification and SMS Notifications. miniOrange OTP Login, Verification and SMS Notifications: 0 hasta 5.5.1
WordPress · Customer Reviews for WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Customer Reviews for WooCommerce. Customer Reviews for WooCommerce: 0 hasta 5.113.0
WordPress · UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP. UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP: 0 hasta 1.2.65
WordPress · GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress. GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress: 0 hasta 7.9.4
WordPress · EventPrime – Events Calendar, Bookings and Tickets
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en EventPrime – Events Calendar, Bookings and Tickets. EventPrime – Events Calendar, Bookings and Tickets: 0 hasta 4.3.4.2
WordPress · Mang Board WP
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Mang Board WP. Mang Board WP: 0 hasta 2.3.4
WordPress · Post Grid Gutenberg Blocks – PostX
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Post Grid Gutenberg Blocks – PostX. Post Grid Gutenberg Blocks – PostX: 0 hasta 5.0.31
WordPress · WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
El registro oficial identifica la vulnerabilidad «CWE-98: vulnerabilidad de seguridad» en WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell. WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: 0 hasta 3.12.7
WordPress · ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce. ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce: 0 hasta 1.17.5
WordPress · LoginPress Pro
El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en LoginPress Pro. LoginPress Pro: 0 hasta 6.2.3
WordPress · LoginPress Pro
El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en LoginPress Pro. LoginPress Pro: 0 hasta 6.2.3
WordPress · LoginPress Pro
El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en LoginPress Pro. LoginPress Pro: 0 hasta 6.2.3
WordPress · Fediverse Embeds
El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en Fediverse Embeds. Fediverse Embeds: 0 hasta 1.5.8
WordPress · Fediverse Embeds
El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en Fediverse Embeds. Fediverse Embeds: 0 hasta 1.5.8
WordPress · Hydra Booking — Appointment Scheduling & Booking Calendar
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Hydra Booking — Appointment Scheduling & Booking Calendar. Hydra Booking — Appointment Scheduling & Booking Calendar: 0 hasta 1.2.1
WordPress · Blocks for ACF Fields — Display Custom Fields in the Block Editor
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Blocks for ACF Fields — Display Custom Fields in the Block Editor. Blocks for ACF Fields — Display Custom Fields in the Block Editor: 0 hasta 1.6.2
WordPress · User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration. User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration: 0 hasta 4.3.7
WordPress · User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration. User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration: 0 hasta 4.3.7
WordPress · Everest Forms
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Everest Forms. Everest Forms: 3.4.2 hasta 3.5.0
WordPress · AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress. AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress: 0 hasta 10.10.2
WordPress · WP Support Plus Responsive Ticket System
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en WP Support Plus Responsive Ticket System. WP Support Plus Responsive Ticket System: 0 hasta 9.1.2
WordPress · WP DSGVO Tools (GDPR)
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en WP DSGVO Tools (GDPR). WP DSGVO Tools (GDPR): 0 hasta 3.1.40
WordPress · Everest Forms
El registro oficial identifica la vulnerabilidad «CWE-200: vulnerabilidad de seguridad» en Everest Forms. Everest Forms: 0 hasta 3.5.0
WordPress · Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration. Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration: 0 hasta 3.4
WordPress · Backstage – Customizer Demo Access
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Backstage – Customizer Demo Access. Backstage – Customizer Demo Access: 0 hasta 1.4.2
WordPress · Wp Js Detect
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en Wp Js Detect. Wp Js Detect: 0 hasta 1.0.9
WordPress · Eventer
El registro oficial identifica la vulnerabilidad «CWE-289: vulnerabilidad de seguridad» en Eventer. Eventer: 0 hasta 4.4.2
WordPress · Eventer
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Eventer. Eventer: 0 hasta 4.4.2
WordPress · My Calendar – Accessible Event Manager
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en My Calendar – Accessible Event Manager. My Calendar – Accessible Event Manager: 0 hasta 3.7.8
WordPress · VikBooking Hotel Booking Engine & PMS
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en VikBooking Hotel Booking Engine & PMS. VikBooking Hotel Booking Engine & PMS: 0 hasta 1.8.8
WordPress · VikBooking Hotel Booking Engine & PMS
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en VikBooking Hotel Booking Engine & PMS. VikBooking Hotel Booking Engine & PMS: 0 hasta 1.8.8
WordPress · Advanced iFrame
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Advanced iFrame. Advanced iFrame: 0 hasta 2026.1
WordPress · Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder. Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder: 0 hasta 4.7.4
WordPress · Essential Addons for Elementor – Popular Elementor Templates & Widgets
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Essential Addons for Elementor – Popular Elementor Templates & Widgets. Essential Addons for Elementor – Popular Elementor Templates & Widgets: 0 hasta 6.6.2
WordPress · Tainacan
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Tainacan. Tainacan: 0 hasta 1.0.3
WordPress · Blocksy Companion
El registro oficial identifica la vulnerabilidad «Vulnerabilidad de seguridad» en Blocksy Companion. Blocksy Companion: 0 hasta 2.1.46, 2.1.47
NGINX · frigate
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en frigate. frigate: <= 0.17.1
WordPress · User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration. User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration: 0 hasta 4.3.1
WordPress · LatePoint – Calendar Booking Plugin for Appointments and Events
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en LatePoint – Calendar Booking Plugin for Appointments and Events. LatePoint – Calendar Booking Plugin for Appointments and Events: 0 hasta 5.4.0
WordPress · WCFM Membership – WooCommerce Memberships for Multivendor Marketplace
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en WCFM Membership – WooCommerce Memberships for Multivendor Marketplace. WCFM Membership – WooCommerce Memberships for Multivendor Marketplace: 0 hasta 2.11.10
WordPress · Bulk Order Update for WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Bulk Order Update for WooCommerce. Bulk Order Update for WooCommerce: 0 hasta 1.6
WordPress · DoLogin Security
El registro oficial identifica la vulnerabilidad «CWE-338: vulnerabilidad de seguridad» en DoLogin Security. DoLogin Security: 0 hasta 4.3
WordPress · WHMCS Bridge
El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en WHMCS Bridge. WHMCS Bridge: 0 hasta 6.9
WordPress · Simple Coherent Form
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Simple Coherent Form. Simple Coherent Form: 0 hasta 2.4.13
WordPress · 多说社会化评论框
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en 多说社会化评论框. 多说社会化评论框: 0 hasta 1.2
WordPress · TH Login Registration
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en TH Login Registration. TH Login Registration: 0 hasta 1.0.2
WordPress · Jssor Slider by jssor.com
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Jssor Slider by jssor.com. Jssor Slider by jssor.com: 0 hasta 3.1.24
WordPress · Widget Logic Visual
El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en Widget Logic Visual. Widget Logic Visual: 0 hasta 1.52
WordPress · Recurio – Ultimate Subscription for WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Recurio – Ultimate Subscription for WooCommerce. Recurio – Ultimate Subscription for WooCommerce: 0 hasta 1.1.3
WordPress · Appointment Booking Calendar Plugin and Scheduling Plugin
El registro oficial identifica la vulnerabilidad «CWE-502: Deserialización de datos no confiables» en Appointment Booking Calendar Plugin and Scheduling Plugin. Appointment Booking Calendar Plugin and Scheduling Plugin: 0 hasta 1.1.28
WordPress · WP Learn Manager
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en WP Learn Manager. WP Learn Manager: 0 hasta 1.1.8
WordPress · User Management
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en User Management. User Management: 0 hasta 1.2
WordPress · Chatra Live Chat + ChatBot + Cart Saver
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Chatra Live Chat + ChatBot + Cart Saver. Chatra Live Chat + ChatBot + Cart Saver: 0 hasta 1.0.12
WordPress · Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en Smash Balloon Social Photo Feed – Easy Social Feeds Plugin. Smash Balloon Social Photo Feed – Easy Social Feeds Plugin: 0 hasta 6.11.1
WordPress · Social Share, Social Login and Social Comments Plugin – Super Socializer
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Social Share, Social Login and Social Comments Plugin – Super Socializer. Social Share, Social Login and Social Comments Plugin – Super Socializer: 0 hasta 7.14.5
WordPress · Sympl Repeater for ACF and Elementor
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Sympl Repeater for ACF and Elementor. Sympl Repeater for ACF and Elementor: 0 hasta 2.3
WordPress · AMP for WP – Accelerated Mobile Pages
El registro oficial identifica la vulnerabilidad «CWE-73: vulnerabilidad de seguridad» en AMP for WP – Accelerated Mobile Pages. AMP for WP – Accelerated Mobile Pages: 0 hasta 1.1.12
Windows · Color Management Driver
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Color Management Driver. Color Management Driver: 0 hasta 1.0.7.6, 1.0.7.6
Microsoft Office · actual
El registro oficial identifica la vulnerabilidad «CWE-1236: vulnerabilidad de seguridad» en actual. actual: < 26.6.0
Joomla · Joomla! CMS
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en Joomla! CMS. Joomla! CMS: 4.0.0-5.4.6, 6.0.0-6.1.1
Joomla · Joomla! CMS
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en Joomla! CMS. Joomla! CMS: 4.0.0-5.4.6, 6.0.0-6.1.1
Joomla · Joomla! CMS
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en Joomla! CMS. Joomla! CMS: 4.0.0-5.4.6, 6.0.0-6.1.1
Joomla · Joomla! CMS
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en Joomla! CMS. Joomla! CMS: 6.0.0-6.1.1
Joomla · Joomla! CMS
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Joomla! CMS. Joomla! CMS: 3.0.0-5.4.6, 6.0.0-6.1.1
Joomla · Joomla! CMS
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Joomla! CMS. Joomla! CMS: 4.0.0-5.4.6, 6.0.0-6.1.1
Joomla · Joomla! CMS
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Joomla! CMS. Joomla! CMS: 4.0.0-5.4.6, 6.0.0-6.1.1
Joomla · Joomla! CMS
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Joomla! CMS. Joomla! CMS: 4.0.0-5.4.6, 6.0.0-6.1.1
Joomla · Joomla! CMS
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Joomla! CMS. Joomla! CMS: 4.0.0-5.4.6, 6.0.0-6.1.1
Joomla · Joomla! CMS
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Joomla! CMS. Joomla! CMS: 4.2.0-5.4.6, 6.0.0-6.1.1
Joomla · Joomla! CMS
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en Joomla! CMS. Joomla! CMS: 3.0.0-5.4.6, 6.0.0-6.1.1
Joomla · Joomla! CMS
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en Joomla! CMS. Joomla! CMS: 4.1.0-5.4.6, 6.0.0-6.1.1
Microsoft Office · actual
El registro oficial identifica la vulnerabilidad «CWE-1236: vulnerabilidad de seguridad» en actual. actual: < 26.6.0
WordPress · DoLeads Integrator / wp2epub
El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en DoLeads Integrator / wp2epub. DoLeads Integrator: 0 hasta 0.65; wp2epub: 0 hasta 0.65
WordPress · WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell
El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell. WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell: 0 hasta 3.12.7
WordPress · uncanny-automator-pro
El registro oficial identifica la vulnerabilidad «CWE-912: vulnerabilidad de seguridad» en uncanny-automator-pro. uncanny-automator-pro: 7.3.0.5 hasta 7.3.0.6
WordPress · Frontend File Manager Plugin
El registro oficial identifica la vulnerabilidad «CWE-73: vulnerabilidad de seguridad» en Frontend File Manager Plugin. Frontend File Manager Plugin: 0 hasta 23.6
WordPress · Exclusive Addons for Elementor
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Exclusive Addons for Elementor. Exclusive Addons for Elementor: 0 hasta 2.7.9.8
WordPress · WP Travel Engine
El registro oficial identifica la vulnerabilidad «CWE-73: vulnerabilidad de seguridad» en WP Travel Engine. WP Travel Engine: 0 hasta 6.8.1
WordPress · FileOrganizer / Advanced File Manager / File Manager Pro
El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en FileOrganizer / Advanced File Manager / File Manager Pro. FileOrganizer: 0 hasta 1.1.9; Advanced File Manager: 0 hasta 5.4.12; File Manager Pro: 0 hasta 2.1.1; File Manager: 0 hasta 8.0.4
Linux · optee_os
El registro oficial identifica la vulnerabilidad «CWE-190: vulnerabilidad de seguridad» en optee_os. optee_os: >= 3.0.0, < 4.11.0
NGINX · FOSSBilling
El registro oficial identifica la vulnerabilidad «CWE-640: vulnerabilidad de seguridad» en FOSSBilling. FOSSBilling: >= 0.5.6, < 0.8.0
Linux · optee_os
El registro oficial identifica la vulnerabilidad «CWE-285: vulnerabilidad de seguridad» en optee_os. optee_os: >= 3.20.0, < 4.11.0
Linux · optee_os
El registro oficial identifica la vulnerabilidad «CWE-770: vulnerabilidad de seguridad» en optee_os. optee_os: >= 3.3.0, < 4.11.0
Linux · optee_os
El registro oficial identifica la vulnerabilidad «CWE-208: vulnerabilidad de seguridad» en optee_os. optee_os: >= 4.5.0, < 4.11.0
Linux · optee_os
El registro oficial identifica la vulnerabilidad «CWE-208: vulnerabilidad de seguridad» en optee_os. optee_os: >= 3.9.0, < 4.11.0
Linux · optee_os
El registro oficial identifica la vulnerabilidad «CWE-208: vulnerabilidad de seguridad» en optee_os. optee_os: >= 4.5.0, < 4.11.0
Linux · optee_os
El registro oficial identifica la vulnerabilidad «CWE-121: vulnerabilidad de seguridad» en optee_os. optee_os: >= 3.10.0, < 4.11.0
Linux · optee_os
El registro oficial identifica la vulnerabilidad «CWE-787: vulnerabilidad de seguridad» en optee_os. optee_os: >= 3.21.0, < 4.11.0
WordPress · Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations. Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations: 0 hasta 2.7.3
WordPress · Admin and Site Enhancements (ASE) / admin-site-enhancements-pro
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Admin and Site Enhancements (ASE) / admin-site-enhancements-pro. Admin and Site Enhancements (ASE): 7.6.3 hasta 8.8.4; admin-site-enhancements-pro: 7.6.3 hasta 8.8.4
WordPress · FileOrganizer
El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en FileOrganizer. FileOrganizer: 0 hasta 1.2.0
WordPress · Simple Membership
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Simple Membership. Simple Membership: 0 hasta 4.7.5
WordPress · Ultimate Member
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Ultimate Member. Ultimate Member: 0 hasta 2.12.0
WordPress · AllCoach
El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en AllCoach. AllCoach: 0 hasta 1.0.2
WordPress · CrawlWP SEO
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en CrawlWP SEO. CrawlWP SEO: n/a hasta 3.0.16