Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-17542

Publication date:
10/08/2026
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026

CVE-2026-18200

Publication date:
10/08/2026
The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-17023

Publication date:
10/08/2026
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-17540

Publication date:
10/08/2026
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-18030

Publication date:
10/08/2026
The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and take over their account.<br /> <br /> Exploitation requires the site to have a form using the BricksForge WordPress plugin before 3.1.8.8&amp;#39;s password reset action in its update mode. The server-side current-password verification option for that action is disabled by default, so the vulnerable state is the default one once the action is used.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-17020

Publication date:
10/08/2026
The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer&amp;#39;s booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2026

CVE-2026-17021

Publication date:
10/08/2026
The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2026

CVE-2026-17022

Publication date:
10/08/2026
The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking&amp;#39;s ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers&amp;#39; booking records, including personal information, by supplying a sequential booking identifier.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2026

CVE-2026-17010

Publication date:
10/08/2026
The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a higher-privileged user who reviews the content.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026

CVE-2026-17019

Publication date:
10/08/2026
The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored Cross-Site Scripting).
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026

CVE-2026-16298

Publication date:
10/08/2026
The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-16299

Publication date:
10/08/2026
The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026