Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
28/09/2026
[CVE-2026-88804] An unauthenticated update of public UI settings could be used by remote attackers to execute a store…
An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.14.6, 2.13 before 2.13.10, 2.12 before 2.12.14 and 2.11 before 2.11.18.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-86609] The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted throu…
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects the commercial Pro edition only; the free Download Manager WordPress plugin befor…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100720] Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowe…
Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certificates API add()/update() methods parse it with openssl_x509_parse() and store the issuer organization (issuer['O']) value verbatim without sanitization. Froxlor's table-listing renderer then emits s…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100673] The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render s…
The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('') call that PHP's strip_tags() bypasses by preserving allowed tags together with their attributes. An unauthenticated visitor wh…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100641] SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it int…
SiYuan before v3.8.4 does not HTML-escape stored flashcard block content before interpolating it into the card-manager list markup. Block content returned by /api/riff/getRiffCards is inserted into a card item template in app/src/card/viewCards.ts and assigned to listElement.innerHTML, so content such as becomes an executable event-handler attribute. Because the SiYua…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100643] SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea …
SiYuan versions before v3.8.4 fail to properly escape four stored Attribute View values in textarea elements, allowing authenticated attackers to inject JavaScript by modifying field descriptions, template sources, select option descriptions, or footer calculation templates. Attackers can execute stored JavaScript when other users open affected database menus, and in the Electron desktop app with …
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100645] SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery an…
SiYuan versions 3.7.0 before 3.8.4 contain a stored cross-site scripting vulnerability in gallery and kanban database renderers where field descriptions are not escaped in aria-label attributes. In the Electron desktop app with nodeIntegration enabled, attackers can inject JavaScript that calls Node.js child_process APIs to execute arbitrary commands with user privileges.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100639] SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (…
SiYuan v3.8.3 fails to HTML-escape the data-subtype attribute when generating gutter-button markup (app/src/protyle/gutter/button.ts, assigned via innerHTML in app/src/protyle/gutter/index.ts) from content pasted as plain-text Markdown containing a Kramdown inline attribute list (IAL). Because the shared Lute renderer parses Kramdown IAL from text/plain input, an attacker-supplied Markdown snippet…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-84095] The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one …
The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to store arbitrary review content which is later output without escaping on public pages, leading to Stored Cross-Site Scripting.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-84096] The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the …
The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that saves its review submission forms, and the nonce protecting it is generated for every visitor, allowing any authenticated user, such as a subscriber, to overwrite a live form with field values that are output without escaping on public pages, leading to Stored Cross-Site Scripting.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-85081] The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File M…
The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the site's own address, which allows an unauthenticated attacker to run arbitrary J…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-16591] The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category…
The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page attributes, allowing users with a WP Directory Kit WordPress plugin before 1.5.8-specific listing-management role (and without the unfiltered_html capability) to perform Stored Cross-Site Scripting attacks that execute for any visitor of the affect…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93641] An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Z…
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93642] An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Z…
An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-93647] An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. …
An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad XSS almacenado en plugin Repeater Fields para Elementor Forms (CVE-2026-94573)
El plugin Repeater Fields for Elementor Forms en WordPress (versiones hasta 2.2.7) contiene una falla de validación que permite a atacantes sin autenticación inyectar scripts maliciosos en formularios. Los scripts ejecutados afectan a todos los usuarios que accedan a páginas con formularios comprometidos, comprometiendo datos sensibles en sitios empresariales y de e-commerce. Este riesgo es alta para organizaciones en LATAM que usan Elementor como constructor de sitios.
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad XSD alta en Themify Builder para WordPress afecta sitios sin autenticación
El plugin Themify Builder para WordPress (versiones hasta 7.8.1) es vulnerable a inyección de scripts almacenados (Stored XSS) a través del parámetro 'css[fonts]' sin validación adecuada. Atacantes no autenticados pueden inyectar código malicioso que se ejecuta cuando usuarios acceden a páginas comprometidas, comprometiendo datos de administradores y visitantes en sitios empresariales de México y LATAM que usen este plugin.
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad XLS almacenado en User Profile Builder para WordPress (CVE-2026-95866)
El plugin User Profile Builder para WordPress es vulnerable a inyección de scripts entre sitios (XLS) a través del campo de avatar en versiones hasta 4.0.2. Atacantes no autenticados pueden ejecutar código malicioso en páginas del sitio afectando a todos los visitantes. El riesgo es alta en sitios con registro público de usuarios.
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad XSS almacenado en plugin Restaurant Menu and Food Ordering para WordPress (CVE-2026-96568)
El plugin Restaurant Menu and Food Ordering para WordPress presenta una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en el parámetro 'phone_number' hasta la versión 2.4.14, permitiendo a atacantes no autenticados inyectar scripts maliciosos que se ejecutan cuando usuarios visitan páginas comprometidas. Afecta principalmente a restaurantes, bares y negocios de comida en línea en LATAM que usan este plugin, exponiendo datos de clientes y comprometiendo la integridad de transacciones. Con CVSS 7.2, representa un riesgo considerable para plataformas de pedidos online.
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad XSS almacenado en plugin Zero Spam para WordPress (CVE-2026-96752)
El plugin Zero Spam para WordPress es vulnerable a inyección de scripts maliciosos (XSS almacenado) en versiones hasta 5.7.10 mediante arrays POST anidados en integración con Contact Form 7. Atacantes no autenticados pueden ejecutar código JavaScript en páginas públicas cuando usuarios acceden a formularios comprometidos, afectando sitios empresariales, tiendas en línea y portales de atención al cliente en México y LATAM que usen este plugin.