Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-77001

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators. In the default case a session as the site's original administrator account is obtained without needing to know any account details at all.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
23/08/2026

CVE-2026-77002

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
23/08/2026

CVE-2026-19221

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/08/2026

CVE-2026-19222

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through it.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/08/2026

CVE-2026-76789

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript which will be executed in the context of an administrator viewing the Slider Hero with Video Background, Animation WordPress plugin before 9.1.3's admin area, as well as any visitor of a page embedding a slider.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/08/2026

CVE-2026-76793

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/08/2026

CVE-2026-16612

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product password. Two endpoints are affected: the autocomplete search endpoint (dgwt_wcas_ajax_search) and the Details Panel endpoint (dgwt_wcas_result_details) when queried for taxonomy details.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/08/2026

CVE-2026-16738

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/08/2026

CVE-2026-18052

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator.
Gravedad CVSS v3.1: ALTA
Última modificación:
23/08/2026

CVE-2026-19093

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, including files outside the web root.<br /> <br /> The readable files include the WordPress configuration file, which exposes the database credentials and the authentication keys and salts, so authentication cookies can be forged.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/08/2026

CVE-2026-16260

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Post Grid, Slider &amp; Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript that executes in the session of any administrator who opens the affected item.
Gravedad CVSS v3.1: MEDIA
Última modificación:
23/08/2026

CVE-2026-14187

Fecha de publicación:
22/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.
Gravedad CVSS v3.1: BAJA
Última modificación:
23/08/2026