Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades conocidas

Página 64 de 95. Los registros están ordenados por fecha oficial de publicación, del más reciente al más antiguo.

Registros 6301–6400 de 9.413

Alta

WordPress · Drag and Drop Multiple File Upload for Contact Form 7

CVE-2026-5710: CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) en Drag and Drop Multiple File Upload for Contact Form 7

El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Drag and Drop Multiple File Upload for Contact Form 7. Drag and Drop Multiple File Upload for Contact Form 7: 0 hasta 1.3.9.6

Leer análisis →
Media

WordPress · LatePoint – Calendar Booking Plugin for Appointments and Events

CVE-2026-5234: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en LatePoint – Calendar Booking Plugin for Appointments and Events

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en LatePoint – Calendar Booking Plugin for Appointments and Events. LatePoint – Calendar Booking Plugin for Appointments and Events: 0 hasta 5.3.2

Leer análisis →
Alta

WordPress · WP Statistics – Simple, privacy-friendly Google Analytics alternative

CVE-2026-5231: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WP Statistics – Simple, privacy-friendly Google Analytics alternative

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WP Statistics – Simple, privacy-friendly Google Analytics alternative. WP Statistics – Simple, privacy-friendly Google Analytics alternative: 0 hasta 14.16.4

Leer análisis →
Media

WordPress · Royal Addons for Elementor – Addons and Templates Kit for Elementor

CVE-2026-5162: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Royal Addons for Elementor – Addons and Templates Kit for Elementor

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Royal Addons for Elementor – Addons and Templates Kit for Elementor. Royal Addons for Elementor – Addons and Templates Kit for Elementor: 0 hasta 1.7.1056

Leer análisis →
Media

WordPress · MasterStudy LMS WordPress Plugin – for Online Courses and Education

CVE-2026-4817: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en MasterStudy LMS WordPress Plugin – for Online Courses and Education

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en MasterStudy LMS WordPress Plugin – for Online Courses and Education. MasterStudy LMS WordPress Plugin – for Online Courses and Education: 0 hasta 3.7.25

Leer análisis →
Media

WordPress · Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

CVE-2026-3330: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder. Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: 0 hasta 1.15.40

Leer análisis →
Media

WordPress · Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

CVE-2026-4160: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder. Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder: 6.1.21

Leer análisis →
Media

WordPress · WP Shortcodes Plugin — Shortcodes Ultimate

CVE-2026-3885: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WP Shortcodes Plugin — Shortcodes Ultimate

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WP Shortcodes Plugin — Shortcodes Ultimate. WP Shortcodes Plugin — Shortcodes Ultimate: 0 hasta 7.4.9

Leer análisis →
Media

WordPress · BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor

CVE-2026-3875: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor. BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor: 0 hasta 4.3.8

Leer análisis →
Alta

WordPress · AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

CVE-2026-3614: CWE-862: Falta de autorización en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress. AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress: 9.11.0 hasta 10.8.1

Leer análisis →
Alta

WordPress · DirectoryPress – Business Directory And Classified Ad Listing

CVE-2026-3489: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en DirectoryPress – Business Directory And Classified Ad Listing

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en DirectoryPress – Business Directory And Classified Ad Listing. DirectoryPress – Business Directory And Classified Ad Listing: 0 hasta 3.6.26

Leer análisis →
Media

WordPress · Better Find and Replace – AI-Powered Suggestions

CVE-2026-3369: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Better Find and Replace – AI-Powered Suggestions

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Better Find and Replace – AI-Powered Suggestions. Better Find and Replace – AI-Powered Suggestions: 0 hasta 1.7.9

Leer análisis →
Media

WordPress · Email Encoder – Protect Email Addresses and Phone Numbers

CVE-2026-2840: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Email Encoder – Protect Email Addresses and Phone Numbers

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Email Encoder – Protect Email Addresses and Phone Numbers. Email Encoder – Protect Email Addresses and Phone Numbers: 0 hasta 2.4.4

Leer análisis →
Alta

WordPress · Login as User – Switch User & WooCommerce Login as Customer

CVE-2026-5617: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Login as User – Switch User & WooCommerce Login as Customer

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Login as User – Switch User & WooCommerce Login as Customer. Login as User – Switch User & WooCommerce Login as Customer: 0 hasta 1.0.1

Leer análisis →
Media

WordPress · Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

CVE-2026-4949: CWE-862: Falta de autorización en Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress. Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress: 0 hasta 4.16.12

Leer análisis →
Crítica

WordPress · Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

CVE-2026-4880: CWE-269: Gestión incorrecta de privilegios en Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale)

El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale). Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale): 0 hasta 1.11.0

Leer análisis →
Alta

Windows · HP DeskJet 2800e All-in-One Printer series / HP DeskJet 4200 All-in-One Printer series / HP DeskJet Ink Advantage 4200 All-in-One Printer series

CVE-2026-4682: CWE-121: vulnerabilidad de seguridad en HP DeskJet 2800e All-in-One Printer series / HP DeskJet 4200 All-in-One Printer series / HP DeskJet Ink Advantage 4200 All-in-One Printer series

El registro oficial identifica la vulnerabilidad «CWE-121: vulnerabilidad de seguridad» en HP DeskJet 2800e All-in-One Printer series / HP DeskJet 4200 All-in-One Printer series / HP DeskJet Ink Advantage 4200 All-in-One Printer series. HP DeskJet 2800e All-in-One Printer series: 0 hasta <2612A; HP DeskJet 4200 All-in-One Printer series: 0 hasta <2612A; HP DeskJet Ink Advantage 4200 All-in-One Printer series: 0 hasta <2612A; HP DeskJet 4200e All-in-One Printer series: 0 hasta <2612A; HP DeskJet Ink Advantage Ultra 4900 series: 0 hasta <2612A; HP DeskJet Ink Advantage 2800 All-in-One Printer series: 0 hasta <2612A

Leer análisis →
Media

WordPress · Power Charts – Responsive Beautiful Charts & Graphs

CVE-2026-4011: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Power Charts – Responsive Beautiful Charts & Graphs

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Power Charts – Responsive Beautiful Charts & Graphs. Power Charts – Responsive Beautiful Charts & Graphs: 0 hasta 0.1.0

Leer análisis →
Alta

WordPress · Accessibly – WordPress Website Accessibility

CVE-2026-3643: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Accessibly – WordPress Website Accessibility

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Accessibly – WordPress Website Accessibility. Accessibly – WordPress Website Accessibility: 0 hasta 3.0.3

Leer análisis →
Alta

WordPress · Age Verification & Identity Verification by Token of Trust

CVE-2026-2834: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Age Verification & Identity Verification by Token of Trust

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Age Verification & Identity Verification by Token of Trust. Age Verification & Identity Verification by Token of Trust: 0 hasta 3.32.3

Leer análisis →
Media

WordPress · WholeSale Products Dynamic Pricing Management WooCommerce

CVE-2026-4479: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en WholeSale Products Dynamic Pricing Management WooCommerce

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WholeSale Products Dynamic Pricing Management WooCommerce. WholeSale Products Dynamic Pricing Management WooCommerce: 0 hasta 1.2

Leer análisis →
Alta

WordPress · Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

CVE-2026-4388: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder. Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: 0 hasta 1.15.40

Leer análisis →
Media

WordPress · Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

CVE-2026-4109: CWE-862: Falta de autorización en Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered). Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered): 0 hasta 4.1.8

Leer análisis →
Media

WordPress · ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

CVE-2026-4059: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin. ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin: 0 hasta 3.3.5

Leer análisis →
Media

Windows Server · Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2

CVE-2026-33829: CWE-200: Exposición de información sensible a un actor no autorizado en Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2. Windows 10 Version 1607: 10.0.14393.0 hasta 10.0.14393.9060; Windows 10 Version 1809: 10.0.17763.0 hasta 10.0.17763.8644; Windows 10 Version 21H2: 10.0.19044.0 hasta 10.0.19044.7184; Windows 10 Version 22H2: 10.0.19045.0 hasta 10.0.19045.7184; Windows 11 version 22H3: 10.0.22631.0 hasta 10.0.22631.6936; Windows 11 Version 23H2: 10.0.22631.0 hasta 10.0.22631.6936; Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8246; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8246

Leer análisis →