Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-6286

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication bypass where the AddBookingCommand explicitly skips nonce verification (Command.php line 186), allowing unauthenticated users to submit booking data. While the plugin applies sanitize_text_field() to customer firstName and lastName fields (BookingApplicationService.php lines 302-308), this function only removes HTML tags and preserves special characters including double quotes. The vulnerability manifests in the administrative Calendar view where a FullCalendar eventContent callback interpolates customer names directly into JavaScript template literals (redesign/dist/index.js line 199) and renders them via innerHTML without proper HTML entity encoding. Because double quotes are preserved, an attacker can inject payloads like '" onmouseover="alert(document.cookie)"' to break out of the title attribute and inject malicious event handlers. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute when an administrator accesses the Calendar page and hovers over the malicious appointment.
Gravedad CVSS v3.1: ALTA
Última modificación:
28/08/2026

CVE-2026-73827

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to the product.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026

CVE-2026-76581

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 verifies an unseparated concatenation that omits the domain field. This makes it possible for unauthenticated attackers, on sites connected to WPMU DEV with Hub SSO enabled and mapped to an administrator, to obtain a valid HMAC from step 1 and replay it to step 2 by moving the domain value into the redirect field, resulting in an authenticated administrator session.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
28/08/2026

CVE-2026-77701

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create refund requests against any guest checkout order on the site.
Gravedad: Pendiente de análisis
Última modificación:
28/08/2026

CVE-2026-77838

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to the product.
Gravedad CVSS v4.0: MEDIA
Última modificación:
28/08/2026

CVE-2026-78032

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
Gravedad CVSS v4.0: CRÍTICA
Última modificación:
28/08/2026

CVE-2026-12513

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission and their single-pass traversal filter is bypassable, allowing unauthenticated users to store a path that points outside the uploads directory. When the corresponding file entry is later permanently deleted, an arbitrary file on the server (such as wp-config.php) is deleted, leading to denial of service and potential site takeover.
Gravedad: Pendiente de análisis
Última modificación:
28/08/2026

CVE-2026-12514

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered for unauthenticated users and protected only by a nonce that is output on public pages, so an unauthenticated visitor can upload files to a publicly accessible directory and read the server's absolute path from the response. Uploads are limited to WordPress's allowed MIME types, so executable PHP cannot be uploaded.
Gravedad: Pendiente de análisis
Última modificación:
28/08/2026

CVE-2026-14558

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.
Gravedad: Pendiente de análisis
Última modificación:
28/08/2026

CVE-2026-14567

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address and phone number of every registered user, including administrators.
Gravedad: Pendiente de análisis
Última modificación:
28/08/2026

CVE-2026-19084

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.
Gravedad: Pendiente de análisis
Última modificación:
28/08/2026

CVE-2026-19423

Fecha de publicación:
28/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register through the Ultimate Member WordPress plugin before 2.13.0's own form to grant themselves arbitrary capabilities and reach administrator-equivalent access.
Gravedad: Pendiente de análisis
Última modificación:
28/08/2026