Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2026-81338

Publication date:
23/09/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts and above to perform stored HTML injection, such as embedding iframes, that can be leveraged for phishing and content spoofing against other users viewing the content.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-81339

Publication date:
23/09/2026
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated user with a minimal (subscriber) role to read other students' quiz grades, pass/fail status and attempt timestamps by referencing an attempt identifier belonging to another user.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-83555

Publication date:
23/09/2026
The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users to force-unsubscribe or force-confirm an arbitrary subscriber whose email address they know.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-84026

Publication date:
23/09/2026
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, allowing unauthenticated attackers to read registered users' private contact details.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-84027

Publication date:
23/09/2026
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to create paid order and payment records with arbitrary amounts and attribute them to other users.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-84046

Publication date:
23/09/2026
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users with the subscriber role and above to make the server issue requests to internal addresses.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-19438

Publication date:
23/09/2026
Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;) vulnerability in ABB Mint Workbench I.<br /> <br /> This issue affects Mint Workbench I: through 5876.
Severity CVSS v4.0: HIGH
Last modification:
23/09/2026

CVE-2026-18364

Publication date:
23/09/2026
The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions, allowing users with a subscriber-level account to modify the zportals WordPress plugin before 6.4.2&amp;#39;s stored integration settings.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-18365

Publication date:
23/09/2026
The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, allowing users with a subscriber-level account to disclose the display name and email address of every registered user, including administrators.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-75799

Publication date:
23/09/2026
The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-77765

Publication date:
23/09/2026
The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant&amp;#39;s configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbitrary reduced amount for a fixed-price item.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026

CVE-2026-77766

Publication date:
23/09/2026
The Directorist: AI-Powered Business Directory, Listings &amp; Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read every customer&amp;#39;s order and payment records.<br /> <br /> Versions 8.8.1 to 8.9 are not affected. The endpoint was scoped correctly in 8.8.1 and the unscoped behaviour was reintroduced in 8.9.1.
Severity CVSS v4.0: Pending analysis
Last modification:
23/09/2026