Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-15136

Publication date:
28/07/2026
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3.7. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to permanently delete or forcibly resolve arbitrary GDPR data request records stored in the wpl_data_req table via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-16585

Publication date:
28/07/2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. This makes it possible for authenticated attackers, with administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The prefix check intended to restrict deletion to the uploads directory can be bypassed by crafting a URL that begins with the legitimate uploads base URL but embeds ../ traversal sequences in the path portion, as the normalize_sticker function only applies esc_url_raw(), which does not strip ../ sequences, allowing the traversal payload to be stored verbatim in WordPress options.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-12124

Publication date:
28/07/2026
The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the serveTemplatePdfAjax() function and the serveTemplatePdf() REST route (which is registered with `permission_callback => '__return_true'`) in versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to download stored template PDFs — which may contain customer PII, invoice, order, and certificate data — by requesting the publicly registered admin-ajax action `pdfdraft_embed_pdf` or the REST endpoint `/wp-json/pdfdraft/v1/embed-pdf/templates/{slug}/pdf` with a known or guessable design slug, bypassing the plugin's own .
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-14490

Publication date:
28/07/2026
The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as dotfiles inside a publicly accessible subdirectory of the WordPress uploads folder — without any `.htaccess` or index file protection — and the `demi_restore_step` AJAX handler, registered for unauthenticated callers, explicitly accepts possession of the on-disk signing key as a standalone alternative to WordPress capability and nonce checks; an unauthenticated attacker who retrieves the exposed key can forge a valid signed state envelope to invoke `CleanDir::execute()` with a caller-supplied absolute path that is subject to no allow-list or path-canonicalization check. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server.
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-17524

Publication date:
28/07/2026
Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. An attacker can bypass security checks designed to prevent directory traversal. The intended security function, isOutsideTargetFolder, only checks and caches the path status when the initial directory symlink is created during the first extraction.
Severity CVSS v4.0: HIGH
Last modification:
30/07/2026

CVE-2026-17528

Publication date:
28/07/2026
Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a victim’s browser when they view or interact with the affected page.
Severity CVSS v4.0: MEDIUM
Last modification:
30/07/2026

CVE-2026-65442

Publication date:
27/07/2026
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-65443

Publication date:
27/07/2026
Unauthenticated Cross Site Scripting (XSS) in BackWPup
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-65445

Publication date:
27/07/2026
Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP)
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-65447

Publication date:
27/07/2026
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-66473

Publication date:
27/07/2026
Unauthenticated Broken Access Control in Xendit Payment
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026

CVE-2026-65441

Publication date:
27/07/2026
Unauthenticated Cross Site Scripting (XSS) in GiveWP
Severity CVSS v4.0: Pending analysis
Last modification:
28/07/2026