Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 6 min
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
996
Esta semana
RSS
M Alto vulnerabilidad
01/10/2026
[CVE-2026-102378] Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Parallax Section block
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad alta en Ghost: inyección XLS afecta versiones 0.5.3 a 6.49.x
Ghost (plataforma de blogging y CMS) contiene una falla de sanitización en la etiqueta JSON-LD del helper {{ghost_head}} que permite a usuarios autenticados con permisos limitados inyectar código malicioso. El script se ejecuta en páginas publicadas, poniendo en riesgo las sesiones administrativas de staff cuando visualizan contenido comprometido. Afecta versiones desde 0.5.3 hasta anteriores a 6.50.0.
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad alta en Ghost: ejecución de scripts no confiables en oEmbed (CVE-2026-103277)
Las versiones de Ghost desde 2.5.0 hasta 6.34.0 contienen una vulnerabilidad de ejecución de scripts no confiables en la función de vista previa oEmbed, que no sandbox adecuadamente scripts externos. Atacantes pueden inyectar contenido oEmbed malicioso para ejecutar código en la sesión administrativa de usuarios autenticados, comprometiendo el acceso administrativo de plataformas de blogs y contenido. Este riesgo es alta para empresas medianas en LATAM que utilizan Ghost para portales corporativos, landing pages y sitios de marketing.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103249] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stor…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown link handling. Workflow authors can inject malicious script URLs that execute arbitrary JavaScript in the editor origin when other users open the node dropdown and click the external-link icon, with the payload persisti…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-92144] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103493] In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
M Alto vulnerabilidad
01/10/2026
[CVE-2026-97661] The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site S…
The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploit…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-92244] The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-…
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user …
M Alto vulnerabilidad
01/10/2026
[CVE-2026-96573] The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Bas…
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that w…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-96813] The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is v…
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields in all versions up to, and including, 1.15.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-85235] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user …
M Alto vulnerabilidad
01/10/2026
[CVE-2026-14995] The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Pa…
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Critical …
M Alto vulnerabilidad
01/10/2026
[CVE-2026-92412] The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supp…
The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-85679] The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' …
The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because r…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-81739] The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores …
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts that will run in the session of a store administrator.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-96561] The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to …
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.0 This is due to a chain of missing input neutralization and output escaping across the /mwai-ui/v1/chats/submit REST endpoint, the PHP error-log parser (MeowKit_MWAI_Helpers::php_error_logs), the Advisor task (Meow_MWAI_Modules_Advis…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-102147] A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attack…
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative control, including the creation of a new administrative account.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102126] A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding …
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have permitted the lower-privileged administrator to escalate to full administrative co…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102100] Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-sit…
Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be used to perform actions on the victim's behalf and may have permitted account ta…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102092] Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could al…
Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. This could potentially lead to session compromise and account takeover.