Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad XSS almacenado alta en plugin Premium Packages para WordPress (CVE-2026-93654)
El plugin 'Premium Packages – Sell Digital Products Securely' para WordPress contiene una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en versiones hasta 7.2.1 que permite a atacantes no autenticados inyectar código malicioso a través del parámetro 'cart_items[][product_name]'. La falta de sanitización de entrada y escape de salida expone tiendas virtuales en LATAM a robo de credenciales, captura de datos de clientes y comprometimiento de transacciones. El riesgo es alto especialmente en comercios pequeños y medianos con bajo monitoreo de seguridad.
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad de XSS almacenado alta en plugin Fancy Product Designer para WordPress
El plugin Fancy Product Designer (versiones hasta 6.5.2) para WordPress permite a atacantes no autenticados inyectar scripts maliciosos mediante el parámetro 'elements[].title' en shortcodes, ejecutándose cuando usuarios acceden a páginas comprometidas. Afecta tiendas en línea y sitios comerciales en México y LATAM que utilicen este plugin sin actualizar. El CVSS 7.2 refleja alto riesgo de compromiso de datos de clientes y defacement.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-96039] The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_n…
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An unauthenticated attacke…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-84281] The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pr…
The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-93303] The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to S…
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'form_data' Rich Text Field via Draft Save/Resume in all versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will …
M Alto vulnerabilidad
25/09/2026
[CVE-2026-83591] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Sc…
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Regex Transformation in all versions up to, and including, 1.1.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-84279] The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the…
The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97735] ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php)…
ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-61823] code16 Sharp is a Laravel-based framework for building content-management and administrative interfa…
code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in the rich-text editor because the HTML sanitizer permits the `srcdoc` attribute on iframe elements. Although markup inside `srcdoc` is HTML-encoded during sanitization, browsers decode attribute entities before interpr…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-61825] code16 Sharp is a Laravel-based framework for building content-management and administrative interfa…
code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in `SharpEditorFormField`: attacker-controlled content bearing the `data-html-content` attribute can bypass HTML sanitization and preserve executable markup, which may execute when another user views the stored content. …
M Alto vulnerabilidad
24/09/2026
[CVE-2026-57440] The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and variou…
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute without sanitization. When given a malformed url or id, the src attribute can be escap…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-91122] Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0…
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attribute breakout and inject an attacker-controlled event handler. An authenticated user with default trust-level posting privileges could store the crafted placeholder in a post. When another user opened the post and clicked the vi…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-62368] Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.crea…
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens an asset-list page associated with the fieldset, the stored markup executes on page load in that user's Snipe-IT session.…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-63498] Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint G…
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with the inline=true parameter. The app/Http/Controllers/Api/UploadedFilesController.php show() path does not apply the safe-inline allowlist use…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-56736] phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in…
phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-privileged registered user) to inject arbitrary JavaScript that executes in an administrator's browser when they review or edit a user-submitted FAQ entry. This leads to admin account takeover via session theft. The vulnerability…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-84683] A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of j…
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal escape sequences before conversion to HTML. An ANSI OSC 8 hyperlink sequence in the output is expanded into an HTML anchor whose href is not scheme- filtered or esca…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95528] Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions…
Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95529] Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95515] Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94176] Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Mang Board WP