Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-18037

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.
Gravedad CVSS v3.1: MEDIA
Última modificación:
11/08/2026

CVE-2026-18032

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does not cover them, allowing unauthenticated attackers to read arbitrary columns of the database table the affected front-end form is bound to, including user password hashes where that table is the users table.
Gravedad CVSS v3.1: ALTA
Última modificación:
10/08/2026

CVE-2026-17044

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.
Gravedad CVSS v3.1: ALTA
Última modificación:
11/08/2026

CVE-2026-17017

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does not include a capability check on that action, allowing users with Subscriber-level access and above to perform SQL injection attacks.
Gravedad CVSS v3.1: ALTA
Última modificación:
10/08/2026

CVE-2026-17014

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.
Gravedad CVSS v3.1: MEDIA
Última modificación:
11/08/2026

CVE-2026-16992

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publishes the requested content as a side effect, allowing unauthenticated attackers to read unpublished content and to make it publicly available.
Gravedad CVSS v3.1: MEDIA
Última modificación:
11/08/2026

CVE-2026-17011

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing.
Gravedad CVSS v3.1: BAJA
Última modificación:
11/08/2026

CVE-2026-16988

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings.
Gravedad CVSS v3.1: ALTA
Última modificación:
10/08/2026

CVE-2026-16957

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users with the Contributor role to read arbitrary post meta, including protected and private keys, of published posts they do not own, including password-protected posts and posts of non-public post types.
Gravedad CVSS v3.1: BAJA
Última modificación:
11/08/2026

CVE-2026-16965

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.
Gravedad CVSS v3.1: MEDIA
Última modificación:
11/08/2026

CVE-2026-16032

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it in an administrative dashboard, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the affected dashboard page.
Gravedad CVSS v3.1: MEDIA
Última modificación:
10/08/2026

CVE-2026-15038

Fecha de publicación:
09/08/2026
Idioma:
Inglés
*** Pendiente de traducción *** The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the entire network, leading to remote code execution.
Gravedad CVSS v3.1: CRÍTICA
Última modificación:
10/08/2026