Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
02/10/2026
[CVE-2026-96871] The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type'…
The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable on any boa…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-97336] The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Typ…
The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'file_list' Field Type in all versions up to, and including, 2.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when an integ…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-93756] The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulne…
The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Facebook Comment Message via v-html in Admin Builder Preview in all versions up to, and including, 4.13.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that wil…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-95670] The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL …
The No External Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Log URL via /goto/{base64} Redirect in all versions up to, and including, 5.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only …
M Alto vulnerabilidad
02/10/2026
[CVE-2026-95817] The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comm…
The DoFollow Case by Case plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation delays but…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-102772] The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<textarea_code f…
The CMB2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ' (e.g. kl_code, kl_post_code)' parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an inject…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103426] The Relevanssi Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_r…
The Relevanssi Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_rt' parameter in all versions up to, and including, 2.31.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the click-tra…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/10/2026
[CVE-2026-100182] The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Ori…
The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This req…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-100107] The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …
The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-93029] There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts in…
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-93697] There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Account…
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-102565] The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bo…
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful …
M Alto vulnerabilidad
02/10/2026
[CVE-2026-90438] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to…
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a u…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-93367] The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated …
The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST['page_title'] with NO sanitization, keeping it raw in …
M Alto vulnerabilidad
01/10/2026
[CVE-2026-54049] Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and vers…
Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversa…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-55230] Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor…
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to version 1.0.8.6, Vvveb's HTML sanitizer fails to strip event-handler attributes when a tag carries a greater-than character inside a quoted attribute value. A low-privilege content author (default role author or contributor) can store a payload in post or product content that runs JavaS…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-97273] Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce
M Alto vulnerabilidad
01/10/2026
[CVE-2026-97260] Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions.
Unauthenticated Cross Site Scripting (XSS) in MaxGalleria
M Alto vulnerabilidad
01/10/2026
[CVE-2026-97268] Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce
M Alto vulnerabilidad
01/10/2026
[CVE-2026-56589] HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, whic…
HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page, enabling session hijacking and the theft of sensitive data.