Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades conocidas

Página 22 de 95. Los registros están ordenados por fecha oficial de publicación, del más reciente al más antiguo.

Registros 2101–2200 de 9.413

Alta

WordPress · SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments

CVE-2026-7655: CWE-640: vulnerabilidad de seguridad en SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments

El registro oficial identifica la vulnerabilidad «CWE-640: vulnerabilidad de seguridad» en SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments. SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments: 0 hasta 4.2.3

Leer análisis →
Media

WordPress · Affiliate Program & Referral Tracking for WooCommerce & WordPress – Affilia

CVE-2026-7559: CWE-862: Falta de autorización en Affiliate Program & Referral Tracking for WooCommerce & WordPress – Affilia

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Affiliate Program & Referral Tracking for WooCommerce & WordPress – Affilia. Affiliate Program & Referral Tracking for WooCommerce & WordPress – Affilia: 0 hasta 3.3.3

Leer análisis →
Alta

WordPress · CorvusPay WooCommerce Payment Gateway

CVE-2026-6939: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en CorvusPay WooCommerce Payment Gateway

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en CorvusPay WooCommerce Payment Gateway. CorvusPay WooCommerce Payment Gateway: 0 hasta 2.7.4

Leer análisis →
Alta

WordPress · WP CTA – Call Now Button, Sticky Button & Call to Action Builder

CVE-2026-4661: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en WP CTA – Call Now Button, Sticky Button & Call to Action Builder

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en WP CTA – Call Now Button, Sticky Button & Call to Action Builder. WP CTA – Call Now Button, Sticky Button & Call to Action Builder: 0 hasta 2.2.2

Leer análisis →
Media

WordPress · Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk

CVE-2026-1832: CWE-862: Falta de autorización en Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk. Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk: 0 hasta 2.1.7

Leer análisis →
Alta

WordPress · Essential Addons for Elementor – Popular Elementor Templates & Widgets

CVE-2026-15155: CWE-640: vulnerabilidad de seguridad en Essential Addons for Elementor – Popular Elementor Templates & Widgets

El registro oficial identifica la vulnerabilidad «CWE-640: vulnerabilidad de seguridad» en Essential Addons for Elementor – Popular Elementor Templates & Widgets. Essential Addons for Elementor – Popular Elementor Templates & Widgets: 0 hasta 6.6.10

Leer análisis →
Media

WordPress · KiviCare – Clinic & Patient Management System (EHR)

CVE-2026-15073: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en KiviCare – Clinic & Patient Management System (EHR)

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en KiviCare – Clinic & Patient Management System (EHR). KiviCare – Clinic & Patient Management System (EHR): 0 hasta 4.5.0

Leer análisis →
Media

WordPress · KiviCare – Clinic & Patient Management System (EHR)

CVE-2026-15072: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en KiviCare – Clinic & Patient Management System (EHR)

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en KiviCare – Clinic & Patient Management System (EHR). KiviCare – Clinic & Patient Management System (EHR): 0 hasta 4.5.0

Leer análisis →
Alta

WordPress · Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database

CVE-2026-13378: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database. Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database: 0 hasta 1.5.2

Leer análisis →
Alta

WordPress · WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

CVE-2026-13353: CWE-94: Control incorrecto de la generación de código (Code Injection) en WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel

El registro oficial identifica la vulnerabilidad «CWE-94: Control incorrecto de la generación de código (Code Injection)» en WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel. WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel: 0 hasta 8.0.1

Leer análisis →
Media

WordPress · Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin

CVE-2026-13262: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin. Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin: 0 hasta 1.1.9

Leer análisis →
Alta

WordPress · Motors – Car Dealership & Classified Listings Plugin

CVE-2026-13114: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Motors – Car Dealership & Classified Listings Plugin

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Motors – Car Dealership & Classified Listings Plugin. Motors – Car Dealership & Classified Listings Plugin: 0 hasta 1.4.112

Leer análisis →
Media

WordPress · Premium Addons for Elementor – Powerful Elementor Templates & Widgets

CVE-2026-12141: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Premium Addons for Elementor – Powerful Elementor Templates & Widgets

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Premium Addons for Elementor – Powerful Elementor Templates & Widgets. Premium Addons for Elementor – Powerful Elementor Templates & Widgets: 0 hasta 4.11.84

Leer análisis →
Media

WordPress · WCFM Marketplace – Multivendor Marketplace for WooCommerce

CVE-2026-12126: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WCFM Marketplace – Multivendor Marketplace for WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WCFM Marketplace – Multivendor Marketplace for WooCommerce. WCFM Marketplace – Multivendor Marketplace for WooCommerce: 0 hasta 3.7.3

Leer análisis →
Media

WordPress · GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference

CVE-2026-6440: CWE-352: vulnerabilidad de seguridad en GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference

El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference. GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference: 0 hasta 1.1.8

Leer análisis →
Crítica

Linux · Linux

CVE-2026-53363: vulnerabilidad de seguridad en Linux

El registro oficial identifica la vulnerabilidad «vulnerabilidad de seguridad» en Linux. Linux: b96ba312e21c9b7ac1526829b9640ddc06695c0b hasta dd66f7f6e360ee82cd905517726f8e9091265de5, b96ba312e21c9b7ac1526829b9640ddc06695c0b hasta c885d111ed9f5a0a1f3cc4e87a50db6518abaa6c, b96ba312e21c9b7ac1526829b9640ddc06695c0b hasta e9096a5a170e7ecd6467bc2e08668ec39897cda7; Linux: 6.14, 0 hasta 6.14, 6.18.36 hasta 6.18.*, 7.0.13 hasta 7.0.*, 7.1 hasta *

Leer análisis →
Media

WordPress · Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

CVE-2026-5069: CWE-863: vulnerabilidad de seguridad en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

El registro oficial identifica la vulnerabilidad «CWE-863: vulnerabilidad de seguridad» en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder. Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder: 0 hasta 6.2.1

Leer análisis →
Media

WordPress · ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

CVE-2026-15302: CWE-36: Absolute Path Traversal en ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

El registro oficial identifica la vulnerabilidad «CWE-36: Absolute Path Traversal» en ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup. ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup: 0 hasta 4.0.27

Leer análisis →
Media

WordPress · Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates

CVE-2026-15299: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates. Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates: 0 hasta 2.6.3

Leer análisis →
Alta

WordPress · TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot

CVE-2026-15298: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot. TelSender – Сontact form 7, Events, Wpforms, ninja forms and woocommerce to telegram bot: 0 hasta 1.14.14

Leer análisis →
Media

WordPress · Brevo – Email, SMS, Web Push, Chat, and more.

CVE-2026-15297: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Brevo – Email, SMS, Web Push, Chat, and more.

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Brevo – Email, SMS, Web Push, Chat, and more.. Brevo – Email, SMS, Web Push, Chat, and more.: 0 hasta 3.1.77

Leer análisis →
Media

WordPress · affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

CVE-2026-15296: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display. affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display: 0 hasta 3.7.0

Leer análisis →
Alta

WordPress · ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form

CVE-2026-15291: CWE-862: Falta de autorización en ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form. ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form: 0 hasta 3.1.3

Leer análisis →
Alta

WordPress · Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

CVE-2026-15290: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin. Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin: 0 hasta 2.10.1

Leer análisis →
Alta

WordPress · SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

CVE-2026-15288: CWE-20: vulnerabilidad de seguridad en SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator

El registro oficial identifica la vulnerabilidad «CWE-20: vulnerabilidad de seguridad» en SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator. SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator: 0 hasta 2.2.1

Leer análisis →
Media

WordPress · rtMedia for WordPress, BuddyPress and bbPress

CVE-2026-15287: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en rtMedia for WordPress, BuddyPress and bbPress

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en rtMedia for WordPress, BuddyPress and bbPress. rtMedia for WordPress, BuddyPress and bbPress: 0 hasta 4.6.18

Leer análisis →
Media

WordPress · The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

CVE-2026-15285: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce. The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce: 0 hasta 6.4.11

Leer análisis →
Media

WordPress · King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

CVE-2026-15284: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder. King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder: 0 hasta 51.1.62

Leer análisis →
Media

WordPress · BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

CVE-2026-15104: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot. BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot: 0 hasta 4.6.0

Leer análisis →
Media

WordPress · Cookie Banner for GDPR / CCPA – WPLP Cookie Consent

CVE-2026-14475: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Cookie Banner for GDPR / CCPA – WPLP Cookie Consent

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Cookie Banner for GDPR / CCPA – WPLP Cookie Consent. Cookie Banner for GDPR / CCPA – WPLP Cookie Consent: 0 hasta 4.3.6

Leer análisis →
Media

WordPress · Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

CVE-2026-13710: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress. Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress: 0 hasta 3.2.6

Leer análisis →