Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-63229

Publication date:
29/07/2026
A pre-authentication blind SQL injection<br /> vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via<br /> the SSO OAuth endpoint to read sensitive database contents, including<br /> personally identifiable information, credentials, and valid JWT tokens that may<br /> enable account takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63230

Publication date:
29/07/2026
A pre-authentication error-based SQL injection<br /> vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database<br /> contents, including personally identifiable information, credentials, and valid<br /> JWT tokens that may enable account takeover, via the SCORM report endpoint.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63231

Publication date:
29/07/2026
A post-authentication SQL injection<br /> vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via<br /> the face-to-face runs update endpoint to read the entire application database<br /> and obtain valid JWT tokens for account takeover.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63232

Publication date:
29/07/2026
A SQL injection and unsafe deserialisation<br /> vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment<br /> reinforcement endpoint, control data passed to unserialize(), write a webshell<br /> to a publicly accessible location, and execute arbitrary code on the server.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63233

Publication date:
29/07/2026
A SQL injection and unsafe deserialisation<br /> vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment<br /> overall answer endpoint, control data passed to unserialize(), write a webshell<br /> to a publicly accessible location, and execute arbitrary code on the server.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63234

Publication date:
29/07/2026
A SQL injection and unsafe deserialisation<br /> vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark<br /> assessment endpoint, control data passed to unserialize(), write a webshell to<br /> a publicly accessible location, and execute arbitrary code on the server.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-63235

Publication date:
29/07/2026
An improper access control vulnerability in Koollab LMS<br /> allowed an<br /> unauthenticated attacker to forcibly terminate the session of any user given<br /> their email address via the login kickout endpoint, resulting in a denial of<br /> service.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-11974

Publication date:
29/07/2026
The wp-media-folder-addon WordPress plugin through 4.1.6 does not validate a user-supplied parameter before using it in a file read operation in two AJAX actions available to unauthenticated users, leading to Arbitrary File Disclosure and Server-Side Request Forgery on sites where a cloud storage connection has been configured. This is an incomplete fix of CVE-2026-9690, whose patch hardened only one of the affected cloud-storage handlers and left the others unpatched.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-13423

Publication date:
29/07/2026
The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied PHP function with an attacker-supplied argument array, allowing unauthenticated attackers to call arbitrary functions (for example to create an administrator account), leading to privilege escalation and remote code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-13605

Publication date:
29/07/2026
The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into the page DOM without escaping. Because the title attribute survives the post-content sanitization applied to users who lack the unfiltered_html capability, an authenticated user with Author-level access can store a JavaScript payload that executes in the browser of any visitor, including an administrator, who clicks the link.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-13690

Publication date:
29/07/2026
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attacker who already knows a user&amp;#39;s credentials to bypass the second authentication factor and log in as that user.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026

CVE-2026-13692

Publication date:
29/07/2026
The PayU CommercePro Plugin WordPress plugin through 3.8.9 does not verify the payment-gateway signature before applying order modifications, allowing unauthenticated attackers to tamper with the totals, shipping and metadata of arbitrary WooCommerce orders.
Severity CVSS v4.0: Pending analysis
Last modification:
30/07/2026