Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18324] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a use…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18978] The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Co…
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A comment payload crafted exclusive…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-66155] A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-n…
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loa…
M Alto vulnerabilidad
27/08/2026
Vulnerabilidad XSS sin autenticación en CozyStay versiones ≤ 1.10.0 (CVSS 7.1)
CozyStay versiones 1.10.0 y anteriores contienen una vulnerabilidad de Cross Site Scripting (XSS) sin requerimiento de autenticación que permite a atacantes inyectar código malicioso. Esta falla afecta directamente sistemas de reservas y gestión hotelera ampliamente desplegados en México y Latinoamérica, poniendo en riesgo datos de clientes y sesiones administrativas.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78293] Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78261] Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78281] Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
Unauthenticated Cross Site Scripting (XSS) in CP Media Player

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78283] Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78333] The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submit…
The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-47665] Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Pe…
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerHTML without any sanitization. Because the backend applies only a length check and the frontend writes comment content directly through innerHTML, any tea…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-47666] Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Pe…
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and injected into the page as HTML without sanitization. Because the backend accepts an arbitrary font-family string and the frontend writes the resulting style throu…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-32257] Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Pr…
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the LESS parser and rendered without sanitization on every backend page, allowing stored cross-site scripting against backend users. This issue is f…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-32258] Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Fr…
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LESS parser and rendered without sanitization on every backend page, allowing stored cross-site scripting. This issue is fixed in version 1.2.13.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80426] FiftyOne renders a dataset field's description as markup. The sidebar field-information component at…
FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/src/components/FieldLabelAndInfo/index.tsx passes the description string to React's dangerouslySetInnerHTML, and no layer between storage and render escapes or sanitises it; the neighbouring info values in the same component are rendered as React children and are escaped, so the d…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-18331] The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin …
The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frm_user_id' parameter in all versions up to, and including, 6.33.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-19760] The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Sit…
The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP Host Header in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This req…
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta en hbs (Express Handlebars): bypass de escaping HTML en helpers asincronos
hbs, motor de vistas para Express que envuelve Handlebars, presenta una vulnerabilidad de inyección HTML (CVE-2026-16231, CVSS 8.1) en su API registerAsyncHelper. El fallo permite a atacantes bypass del escaping automático de HTML, ya que los helpers asincronos retornan placeholders durante el primer renderizado que no son escapados correctamente, exponiendo aplicaciones web a XSS. Afecta aplicaciones Node.js en producción que usan templates dinámicos con helpers asincronos.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78563] The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versi…
The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-18323] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) in all versions up to, and including, 1.57.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute w…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-18328] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 1.57.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex…