Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-9767

Fecha de publicación:
16/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This vulnerability is replicated across seven or more AJAX handlers including wlsm-fetch-staff-classes, wlsm-fetch-notices, wlsm-fetch-subjects, wlsm-fetch-inquiries, wlsm-fetch-staff-employee, and wlsm-fetch-payments, and the missing nonce verification on several of these handlers also enables CSRF-chained exploitation.
Gravedad CVSS v3.1: MEDIA
Última modificación:
16/08/2026

CVE-2026-2283

Fecha de publicación:
16/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions up to, and including, 2.1.7. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is only exploitable on multisite installations.
Gravedad CVSS v3.1: MEDIA
Última modificación:
16/08/2026

CVE-2026-19613

Fecha de publicación:
16/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of its dynamic repeater data sources reads custom field values from a user-supplied post identifier, allowing users with a contributor-level account or above to read custom field values and post metadata from posts they do not own, including private and draft ones.
Gravedad: Pendiente de análisis
Última modificación:
16/08/2026

CVE-2026-19711

Fecha de publicación:
16/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against the requesting user's actual earned balance, allowing any authenticated user, including a subscriber with no sales at all, to submit a payout request for an arbitrary amount, which an administrator may then approve and pay out.
Gravedad: Pendiente de análisis
Última modificación:
16/08/2026

CVE-2026-19712

Fecha de publicación:
16/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before outputting it back in a page, and grants its instructor role the ability to store unfiltered HTML, allowing such users to perform Stored Cross-Site Scripting attacks against any visitor of the affected page, including administrators.<br /> This affects default single-site installations. Sites running multisite, or defining DISALLOW_UNFILTERED_HTML, are not affected as the capability is not granted there.
Gravedad: Pendiente de análisis
Última modificación:
16/08/2026

CVE-2026-19714

Fecha de publicación:
16/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated users to authenticate as any user whose email address such a token carries, up to and including an administrator. Every site with the Simple JWT Login WordPress plugin before 3.6.8&amp;#39;s Google sign-in enabled is affected.
Gravedad: Pendiente de análisis
Última modificación:
16/08/2026

CVE-2026-19717

Fecha de publicación:
16/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The CatFolders Document Gallery &amp; PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its REST API endpoints, allowing unauthenticated users to retrieve the title, type, size and URL of the media attachments assigned to any of its folders, including folders which are not published in any gallery on the site.
Gravedad: Pendiente de análisis
Última modificación:
16/08/2026

CVE-2026-19725

Fecha de publicación:
16/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WPvivid — Backup, Migration &amp; Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before using it to build a log file path, allowing an attacker holding a site to site transfer key to create a log file in any existing writable directory of the site, including the web root.<br /> <br /> The file name always carries a fixed suffix and the contents are always the WPvivid — Backup, Migration &amp; Staging WordPress plugin before 0.9.131&amp;#39;s own log header, so only the location of the file is attacker controlled.
Gravedad: Pendiente de análisis
Última modificación:
16/08/2026

CVE-2026-19726

Fecha de publicación:
16/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration of its charts, allowing users with the Contributor role and above to read the full configuration of any chart on the site, including charts the Visualizer WordPress plugin before 4.0.7&amp;#39;s own interface denies them, and to retrieve every chart&amp;#39;s configuration in a single request. The disclosed configuration can include the credentials of a remote data source a chart reads from.
Gravedad: Pendiente de análisis
Última modificación:
16/08/2026

CVE-2026-19728

Fecha de publicación:
16/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file&amp;#39;s stored name to retrieve it.<br /> <br /> The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 writes a deny-all rule into its upload directories, so the disclosure only crosses a boundary on web servers that honour it, such as Apache. Where it is ignored, as on a default nginx setup, the same files are already served at their direct URL and the endpoint exposes nothing further.
Gravedad: Pendiente de análisis
Última modificación:
16/08/2026

CVE-2026-19934

Fecha de publicación:
16/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. The manipulation of the argument delid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Gravedad CVSS v4.0: BAJA
Última modificación:
16/08/2026

CVE-2026-16758

Fecha de publicación:
16/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Gravedad CVSS v3.1: MEDIA
Última modificación:
16/08/2026