Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-22482

Publication date:
22/01/2026
Server-Side Request Forgery (SSRF) vulnerability in wbolt.com IMGspider imgspider allows Server Side Request Forgery.This issue affects IMGspider: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2026

CVE-2026-22483

Publication date:
22/01/2026
Cross-Site Request Forgery (CSRF) vulnerability in winkm89 teachPress teachpress allows Cross Site Request Forgery.This issue affects teachPress: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2026

CVE-2026-22462

Publication date:
22/01/2026
Cross-Site Request Forgery (CSRF) vulnerability in richardevcom Add Polylang support for Customizer add-polylang-support-for-customizer allows Cross Site Request Forgery.This issue affects Add Polylang support for Customizer: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2026

CVE-2026-22463

Publication date:
22/01/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Micro.company Form to Chat App form-to-chat allows Stored XSS.This issue affects Form to Chat App: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2026

CVE-2026-22464

Publication date:
22/01/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows PHP Local File Inclusion.This issue affects My auctions allegro: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2026

CVE-2026-22466

Publication date:
22/01/2026
Missing Authorization vulnerability in Chandni Patel WP MapIt wp-mapit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP MapIt: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2026

CVE-2026-22468

Publication date:
22/01/2026
Missing Authorization vulnerability in AbsolutePlugins Absolute Addons For Elementor absolute-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Absolute Addons For Elementor: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2026

CVE-2026-22469

Publication date:
22/01/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in mwtemplates DeepDigital deepdigital allows Code Injection.This issue affects DeepDigital: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2026

CVE-2026-22470

Publication date:
22/01/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FireStorm Plugins FireStorm Professional Real Estate fs-real-estate-plugin allows Blind SQL Injection.This issue affects FireStorm Professional Real Estate: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2026

CVE-2026-22472

Publication date:
22/01/2026
Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2026

CVE-2026-22411

Publication date:
22/01/2026
Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Dolcino dolcino allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dolcino: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2026

CVE-2026-22426

Publication date:
22/01/2026
Authorization Bypass Through User-Controlled Key vulnerability in Elated-Themes Sweet Jane sweetjane allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sweet Jane: from n/a through
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2026