Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-100311

Fecha de publicación:
26/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The affected element is an unknown function of the file managevideos2.php of the component Faculty Video Management. Such manipulation of the argument V_Title/V_Url/V_Remarks leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure but did not respond in any way.
Gravedad CVSS v4.0: BAJA
Última modificación:
26/09/2026

CVE-2026-92411

Fecha de publicación:
26/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Delicious WordPress plugin before 1.10.8 does not validate or escape the HTML tag name taken from user-supplied recipe block data before rendering it on the front end, allowing users with the Contributor role and above to inject arbitrary HTML tags, including script tags, which execute when the recipe page is viewed.
Gravedad: Pendiente de análisis
Última modificación:
26/09/2026

CVE-2026-96524

Fecha de publicación:
26/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for cookie-authenticated requests when a condition an attacker can influence is present, allowing unauthenticated attackers to perform administrator-only actions, including creating a new administrator account, by tricking a logged-in administrator into visiting a crafted page.
Gravedad: Pendiente de análisis
Última modificación:
26/09/2026

CVE-2026-96525

Fecha de publicación:
26/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check on its workflow create, update and delete REST routes, allowing users with the Contributor role to modify, delete and create site-wide workflow configuration, including workflows created by administrators.
Gravedad: Pendiente de análisis
Última modificación:
26/09/2026

CVE-2026-96526

Fecha de publicación:
26/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one of its workflow REST routes, allowing users with the Contributor role to disclose the title and publication status of any post, page or custom post type, including other users' private, draft, pending and scheduled content.
Gravedad: Pendiente de análisis
Última modificación:
26/09/2026

CVE-2026-96531

Fecha de publicación:
26/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before rendering them onto the block's wrapper element, allowing users with the Author role and above to store an event-handler attribute that executes scripts in the browser of any user, such as an administrator, who views the post.
Gravedad: Pendiente de análisis
Última modificación:
26/09/2026

CVE-2026-96532

Fecha de publicación:
26/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.
Gravedad: Pendiente de análisis
Última modificación:
26/09/2026

CVE-2026-96533

Fecha de publicación:
26/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.
Gravedad: Pendiente de análisis
Última modificación:
26/09/2026

CVE-2026-18143

Fecha de publicación:
26/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME type validation in the popup upload handler, which uses the raw attacker-supplied filename directly as the destination for `move_uploaded_file()`. This makes it possible for unauthenticated attackers to upload executable files, such as PHP files, to a web-accessible temporary RFQ upload directory when a public quote rule with the multi-page popup flow is enabled.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
26/09/2026

CVE-2026-19708

Fecha de publicación:
26/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on servers that do not apply the directory's .htaccess file.
Gravedad: Pendiente de análisis
Última modificación:
26/09/2026

CVE-2026-84095

Fecha de publicación:
26/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public pages, leading to Stored Cross-Site Scripting.
Gravedad: Pendiente de análisis
Última modificación:
26/09/2026

CVE-2026-84096

Fecha de publicación:
26/09/2026
Idioma:
Inglés
*** Pendiente de traducción *** The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to overwrite a live form with field values that are output without escaping on public pages, leading to Stored Cross-Site Scripting.
Gravedad: Pendiente de análisis
Última modificación:
26/09/2026