Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-48969

Publication date:
15/06/2026
Subscriber Broken Access Control in Really Simple SSL
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-49062

Publication date:
15/06/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation.<br /> <br /> This issue affects Faust.Js: from n/a through 1.8.7.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-49064

Publication date:
15/06/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data.<br /> <br /> This issue affects GetPaid: from n/a through 2.8.49.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2026-49111

Publication date:
15/06/2026
Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation.<br /> <br /> This issue affects Masteriyo - LMS: from n/a through 2.2.0.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2016-20084

Publication date:
15/06/2026
WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify calendar settings and inject persistent cross-site scripting payloads through the admin.php page parameters. Attackers can inject malicious JavaScript into the &amp;#39;ict&amp;#39; and &amp;#39;ics&amp;#39; options or the calendar &amp;#39;name&amp;#39; parameter via GET requests to execute arbitrary scripts when the calendar is displayed or accessed in the administration interface.
Severity CVSS v4.0: MEDIUM
Last modification:
15/06/2026

CVE-2018-25436

Publication date:
15/06/2026
WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files by exploiting the upload-package.php endpoint. Attackers can submit POST requests with malicious file extensions to the upload handler, which moves files without validation to the plugin upload directory, enabling remote code execution.
Severity CVSS v4.0: CRITICAL
Last modification:
15/06/2026

CVE-2018-25437

Publication date:
15/06/2026
WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated attackers to download sensitive backup files by accessing the download_backup.php endpoint. Attackers can directly access the download_backup.php script in the admin/data_management directory to obtain ZIP archives containing the entire wp-content/themes directory contents.
Severity CVSS v4.0: HIGH
Last modification:
15/06/2026

CVE-2019-25746

Publication date:
15/06/2026
WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the &amp;#39;post&amp;#39; parameter. Attackers can send requests to the admin.php endpoint with action=duplicate_quote_invoice and malicious &amp;#39;post&amp;#39; values to extract sensitive database information or modify data.
Severity CVSS v4.0: HIGH
Last modification:
15/06/2026

CVE-2025-64215

Publication date:
15/06/2026
Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Constrained by ACLs.<br /> <br /> This issue affects MasterStudy LMS Pro: from n/a before 4.7.16.
Severity CVSS v4.0: Pending analysis
Last modification:
15/06/2026

CVE-2016-20082

Publication date:
15/06/2026
WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the action parameter. Attackers can send GET requests to abtest_admin.php with malicious action values to include files from the admin directory and execute arbitrary code.
Severity CVSS v4.0: MEDIUM
Last modification:
15/06/2026

CVE-2016-20083

Publication date:
15/06/2026
WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validation. Attackers can craft malicious web pages that trick logged-in administrators into adding or deleting custom fields and boxes on the Write/Edit page via POST and GET requests to the options-general.php endpoint.
Severity CVSS v4.0: MEDIUM
Last modification:
15/06/2026

CVE-2016-20070

Publication date:
15/06/2026
WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious scripts by failing to verify user privileges and sanitize input parameters. Attackers with subscriber-level accounts can inject XSS payloads through parameters like price, name, calendar_language, and email_confirmation_to_user via admin-ajax.php and admin.php endpoints to execute arbitrary JavaScript in administrator browsers.
Severity CVSS v4.0: MEDIUM
Last modification:
15/06/2026