Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74998] In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style S…
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-74800] SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when servin…
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link.
M Alto vulnerabilidad
16/08/2026
Vulnerabilidad XSS almacenado alta en plugin Infility Global para WordPress (CVE-2026-10734)
El plugin Infility Global para WordPress es vulnerable a Cross-Site Scripting (XSS) almacenado en el endpoint /cf7_record_log en versiones hasta 2.15.21. Atacantes no autenticados pueden inyectar scripts maliciosos que se ejecutan cuando usuarios acceden a páginas comprometidas, comprometiendo datos de formularios de contacto y sesiones de clientes. Afecta a sitios en WordPress que utilizan este complemento para gestionar registros de formularios Contact Form 7.
M Alto vulnerabilidad
16/08/2026
Vulnerabilidad XSS almacenado en plugin Bookly para WordPress afecta tiendas en línea
El plugin de reservas Bookly para WordPress (versiones hasta 27.7) permite a atacantes no autenticados inyectar scripts maliciosos mediante la acción AJAX bookly_speed_up_update_addons, aprovechando sanitización insuficiente. Afecta directamente a pequeñas y medianas empresas en LATAM que dependen de WordPress para gestión de citas y reservas. La ejecución del código malicioso ocurre en páginas visitadas por clientes y administradores.
M Alto vulnerabilidad
16/08/2026
Vulnerabilidad de Scripting Almacenado en plugin Platnosci Online Blue Media (Autopay) para WordPress
El plugin Platnosci Online Blue Media (Autopay) para WordPress, versiones hasta 5.0.0, es vulnerable a Cross-Site Scripting (XSS) almacenado a través del parámetro POST 'bm_woocommerce_css_editor_content'. La falla reside en el método Css_Editor::handle_save() que carece de validación de capacidades, verificación de nonce y sanitización de entrada, permitiendo a atacantes inyectar código malicioso sin autenticación. Este vector impacta tiendas de comercio electrónico en LATAM que dependen de WooCommerce para procesar pagos y gestionar inventario.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73052] SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them d…
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73053] SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji func…
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73042] SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing…
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins due to Electron's insecure configuration.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73043] SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculat…
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the …
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73044] SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored …
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of style attributes and inject event handlers on every table cell, executing arbitrary code in the Electron renderer with Node integration enabled.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73050] SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select op…
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select field.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73041] SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the se…
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.
M Alto vulnerabilidad
15/08/2026
Vulnerabilidad XSS almacenado en plugin WordPress 'Invisible Anti-Spam & CAPTCHA' (CVE-2026-16145)
El plugin 'Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms' para WordPress (versiones hasta 5.1) contiene una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en el parámetro 'action' por falta de sanitización. Atacantes no autenticados pueden inyectar scripts maliciosos que se ejecutan cuando usuarios acceden a páginas con formularios afectados. Este riesgo impacta directamente sitios web de empresas, tiendas en línea y portales institucionales en LATAM que usan este plugin.
M Alto vulnerabilidad
15/08/2026
Vulnerabilidad de Cross-Site Scripting en plugin WPLP Cookie Consent para WordPress (CVE-2026-13360)
El plugin 'Cookie Banner for GDPR / CCPA – WPLP Cookie Consent' en WordPress es vulnerable a inyección de scripts almacenados (Stored XSS) a través del parámetro 'regionArray' en versiones hasta la 4.3.5 debido a sanitización insuficiente. Atacantes no autenticados pueden inyectar código malicioso que se ejecuta cuando usuarios acceden a páginas con el plugin, afectando potencialmente datos de visitantes y credenciales en sitios de comercio electrónico, gobiernos digitales y financieras de la región.
M Alto vulnerabilidad
15/08/2026
Vulnerabilidad XSS almacenado en plugin vcita para WordPress afecta versiones hasta 4.6.0
El plugin 'Online Booking & Scheduling Calendar for WordPress by vcita' contiene una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en el parámetro 'business_id' debido a sanitización insuficiente. Atacantes no autenticados pueden inyectar scripts maliciosos que se ejecutan cuando usuarios acceden a páginas afectadas. Esto representa un riesgo alta para sitios de reservas y agendamiento en LATAM que confían en este plugin para capturar clientes.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19794] The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to…
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-18109] The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Aut…
The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.10.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability is only expl…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73650] SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG …
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove namespaced or prefixed script elements such as and, in versions 3 and …
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28154] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress Theme: from n/a through 2.5; M.Anh - Fashion WooCoommerce WordPress Theme: from n/a…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66697] Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCom…
Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce