Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades conocidas

Página 95 de 163. Los registros están ordenados por fecha oficial de publicación, del más reciente al más antiguo.

Registros 9401–9500 de 16.277

Media

WordPress · Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

CVE-2026-12904: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Kadence Blocks — Page Builder Toolkit for Gutenberg Editor

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Kadence Blocks — Page Builder Toolkit for Gutenberg Editor. Kadence Blocks — Page Builder Toolkit for Gutenberg Editor: 0 hasta 3.7.7

Leer análisis
Media

WordPress · VikBooking Hotel Booking Engine & PMS

CVE-2026-12754: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en VikBooking Hotel Booking Engine & PMS

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en VikBooking Hotel Booking Engine & PMS. VikBooking Hotel Booking Engine & PMS: 0 hasta 1.8.12

Leer análisis
Media

WordPress · LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

CVE-2026-12732: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses. LearnPress – WordPress LMS Plugin for Create and Sell Online Courses: 0 hasta 4.4.0

Leer análisis
Media

WordPress · Slim SEO – A Fast & Automated SEO Plugin For WordPress

CVE-2026-12408: CWE-200: Exposición de información sensible a un actor no autorizado en Slim SEO – A Fast & Automated SEO Plugin For WordPress

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en Slim SEO – A Fast & Automated SEO Plugin For WordPress. Slim SEO – A Fast & Automated SEO Plugin For WordPress: 0 hasta 4.9.8

Leer análisis
Alta

WordPress · RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

CVE-2026-12158: CWE-352: vulnerabilidad de seguridad en RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login. RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: 0 hasta 6.0.9.1

Leer análisis
Alta

WordPress · NEX-Forms – Ultimate Forms Plugin for WordPress

CVE-2026-12142: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en NEX-Forms – Ultimate Forms Plugin for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en NEX-Forms – Ultimate Forms Plugin for WordPress. NEX-Forms – Ultimate Forms Plugin for WordPress: 0 hasta 9.2.2

Leer análisis
Media

WordPress · WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

CVE-2026-12127: CWE-93: vulnerabilidad de seguridad en WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

El registro oficial identifica la vulnerabilidad «CWE-93: vulnerabilidad de seguridad» en WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More. WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More: 0 hasta 1.10.2

Leer análisis
Media

WordPress · Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-12110: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Taskbuilder – Project Management & Task Management Tool With Kanban Board

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Taskbuilder – Project Management & Task Management Tool With Kanban Board. Taskbuilder – Project Management & Task Management Tool With Kanban Board: 0 hasta 5.0.8

Leer análisis
Media

WordPress · Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-12090: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Taskbuilder – Project Management & Task Management Tool With Kanban Board

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Taskbuilder – Project Management & Task Management Tool With Kanban Board. Taskbuilder – Project Management & Task Management Tool With Kanban Board: 0 hasta 5.0.8

Leer análisis
Media

WordPress · LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

CVE-2026-11988: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses. LearnPress – WordPress LMS Plugin for Create and Sell Online Courses: 0 hasta 4.3.9.1

Leer análisis
Crítica

WordPress · SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

CVE-2026-11387: CWE-287: Autenticación incorrecta en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery

El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery. SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery: 0 hasta 3.9.5

Leer análisis
Crítica

WordPress · EventON (Pro) - WordPress Virtual Event Calendar Plugin

CVE-2026-9711: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en EventON (Pro) - WordPress Virtual Event Calendar Plugin

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en EventON (Pro) - WordPress Virtual Event Calendar Plugin. EventON (Pro) - WordPress Virtual Event Calendar Plugin: 0 hasta 5.0.11

Leer análisis
Media

WordPress · Editorial Rating – Product Review & Rating System

CVE-2026-12560: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Editorial Rating – Product Review & Rating System

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Editorial Rating – Product Review & Rating System. Editorial Rating – Product Review & Rating System: 0 hasta 4.0.5

Leer análisis
Media

WordPress · Team Members – Multi Language Supported Team Plugin

CVE-2026-12114: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Team Members – Multi Language Supported Team Plugin

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Team Members – Multi Language Supported Team Plugin. Team Members – Multi Language Supported Team Plugin: 0 hasta 8.7

Leer análisis
Crítica

WordPress · ProfileGrid – User Profiles, Groups and Communities

CVE-2026-12073: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en ProfileGrid – User Profiles, Groups and Communities

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en ProfileGrid – User Profiles, Groups and Communities. ProfileGrid – User Profiles, Groups and Communities: 0 hasta 5.9.9.5

Leer análisis
Media

WordPress · Colissimo Officiel : Méthodes de livraison pour WooCommerce

CVE-2026-57341: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Colissimo Officiel : Méthodes de livraison pour WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Colissimo Officiel : Méthodes de livraison pour WooCommerce. Colissimo Officiel : Méthodes de livraison pour WooCommerce: n/a hasta 2.9.0

Leer análisis
Sin clasificar

Linux · Linux

CVE-2026-53325: vulnerabilidad de seguridad en Linux

El registro oficial identifica la vulnerabilidad «vulnerabilidad de seguridad» en Linux. Linux: a32073bffc656ca4bde6002b6cf7c1a8e0e22712 hasta ce800993af477fc24187349c6a20d3073140b759, a32073bffc656ca4bde6002b6cf7c1a8e0e22712 hasta 1d7d45050e14083c1de1460c93f4063c1f0bca7b, a32073bffc656ca4bde6002b6cf7c1a8e0e22712 hasta 3e844a63668d1c3d10a9d347d7ebf161b2f91c84, a32073bffc656ca4bde6002b6cf7c1a8e0e22712 hasta eb045714bc6a2bbb0befb7a31b996a196e188869, a32073bffc656ca4bde6002b6cf7c1a8e0e22712 hasta 564b3b3f6565313eb6fa5355ffd037d6fb27897f, a32073bffc656ca4bde6002b6cf7c1a8e0e22712 hasta 53483a9f4ee9eeb18aa866ec16cce79e136987e1; Linux: 2.6.18, 0 hasta 2.6.18, 5.10.260 hasta 5.10.*, 5.15.211 hasta 5.15.*, 6.1.177 hasta 6.1.*, 6.6.144 hasta 6.6.*

Leer análisis
Media

WordPress · RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

CVE-2026-9242: CWE-345: vulnerabilidad de seguridad en RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

El registro oficial identifica la vulnerabilidad «CWE-345: vulnerabilidad de seguridad» en RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login. RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: 0 hasta 6.0.8.6

Leer análisis
Media

WordPress · Groundhogg — CRM, Newsletters, and Marketing Automation

CVE-2026-13333: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Groundhogg — CRM, Newsletters, and Marketing Automation

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Groundhogg — CRM, Newsletters, and Marketing Automation. Groundhogg — CRM, Newsletters, and Marketing Automation: 0 hasta 4.5.5

Leer análisis
Media

WordPress · Groundhogg — CRM, Newsletters, and Marketing Automation

CVE-2026-13331: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Groundhogg — CRM, Newsletters, and Marketing Automation

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Groundhogg — CRM, Newsletters, and Marketing Automation. Groundhogg — CRM, Newsletters, and Marketing Automation: 0 hasta 4.5.5

Leer análisis
Media

WordPress · Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions

CVE-2026-12432: CWE-862: Falta de autorización en Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions. Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions: 0 hasta 8.4.3

Leer análisis
Media

WordPress · Gutenverse – WordPress Blocks, Page Builder & Site Editor

CVE-2026-12399: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Gutenverse – WordPress Blocks, Page Builder & Site Editor

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Gutenverse – WordPress Blocks, Page Builder & Site Editor. Gutenverse – WordPress Blocks, Page Builder & Site Editor: 0 hasta 3.8.0

Leer análisis
Media

WordPress · Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

CVE-2026-11987: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy. Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: 0 hasta 5.0.4

Leer análisis
Media

WordPress · Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

CVE-2026-11783: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy. Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy: 0 hasta 5.0.4

Leer análisis
Media

WordPress · Ivory Search – WordPress Search Plugin

CVE-2026-11356: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Ivory Search – WordPress Search Plugin

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Ivory Search – WordPress Search Plugin. Ivory Search – WordPress Search Plugin: 0 hasta 5.5.15

Leer análisis
Alta

WordPress · Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content

CVE-2026-10820: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content. Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content: 0 hasta 4.16.17

Leer análisis