Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81290] Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.
Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82653] SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where u…
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the name field that execute in users' browsers when uninstalling packages or unlocking encrypted notebooks.
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82654] SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, …
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82642] Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter H…
Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the tag (FORBID_TAGS: ['script']) in apps/readest-app/src/services/transformers/sanitizer.ts. DOMPurify does not parse the contents of the srcdoc attribute on elements, treating it as an opaque string attribute…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-81760] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-6176] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti…
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review comment text. The plugin accepts review submissions from unauthenticated users through the 'cr_local_forms_submit' AJAX act…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-5934] The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a…
The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input sanitization and output escaping of user-supplied data via the rocket_beacon AJAX endpoint. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected p…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
28/08/2026
[CVE-2026-6286] The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stor…
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication bypass where the AddBookingCommand explicitly skips nonce verification (Command.php line 186), allowing unauthenticated users to submit booking data. While the plugin applies saniti…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-76053] The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner…
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-77365] The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin f…
The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a' (above_fold_images) parameter in all versions up to, and including, 4.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18324] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a use…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18978] The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Co…
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A comment payload crafted exclusive…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-66155] A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-n…
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loa…
M Alto vulnerabilidad
27/08/2026
Vulnerabilidad XSS sin autenticación en CozyStay versiones ≤ 1.10.0 (CVSS 7.1)
CozyStay versiones 1.10.0 y anteriores contienen una vulnerabilidad de Cross Site Scripting (XSS) sin requerimiento de autenticación que permite a atacantes inyectar código malicioso. Esta falla afecta directamente sistemas de reservas y gestión hotelera ampliamente desplegados en México y Latinoamérica, poniendo en riesgo datos de clientes y sesiones administrativas.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78293] Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78261] Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78281] Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
Unauthenticated Cross Site Scripting (XSS) in CP Media Player
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78283] Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78333] The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submit…
The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-47665] Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Pe…
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerHTML without any sanitization. Because the backend applies only a length check and the frontend writes comment content directly through innerHTML, any tea…