Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-18934

Publication date:
10/08/2026
The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowing users with author-level access and above to permanently delete the posts created by another user's import job, reset its deduplication and scheduling state, disable it, or clear its error log. One of the affected actions performs no object-type check either, so arbitrary posts and pages can also be unpublished regardless of who owns them.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-18960

Publication date:
10/08/2026
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-19049

Publication date:
10/08/2026
The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the ProSolution WP Client WordPress plugin before 2.0.9 stores.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-17541

Publication date:
10/08/2026
The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026

CVE-2026-17542

Publication date:
10/08/2026
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents which may contain sensitive data.
Severity CVSS v4.0: Pending analysis
Last modification:
10/08/2026

CVE-2026-18200

Publication date:
10/08/2026
The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including administrators.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-17023

Publication date:
10/08/2026
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-17540

Publication date:
10/08/2026
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-18030

Publication date:
10/08/2026
The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and take over their account.<br /> <br /> Exploitation requires the site to have a form using the BricksForge WordPress plugin before 3.1.8.8&amp;#39;s password reset action in its update mode. The server-side current-password verification option for that action is disabled by default, so the vulnerable state is the default one once the action is used.
Severity CVSS v4.0: Pending analysis
Last modification:
11/08/2026

CVE-2026-17020

Publication date:
10/08/2026
The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer&amp;#39;s booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2026

CVE-2026-17021

Publication date:
10/08/2026
The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2026

CVE-2026-17022

Publication date:
10/08/2026
The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking&amp;#39;s ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers&amp;#39; booking records, including personal information, by supplying a sequential booking identifier.
Severity CVSS v4.0: Pending analysis
Last modification:
13/08/2026