« Volver al listado

Flextype

Flextype CMS: vulnerabilidades y CVE

Flextype CMS tiene 4 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE4
Últimos 12 meses4
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-91751Alta (7.2)0.54%—15 sept 2026
Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can…
CVE-2026-89145Baja (2.4)0.18%—11 sept 2026
Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory…
CVE-2026-88897Alta (8.2)0.56%—10 sept 2026
Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API…
CVE-2026-77939Alta (7.1)0.61%—28 ago 2026
Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System2
  2. T1210 Exploitation of Remote Services2
  3. T1190 Exploit Public-Facing Application1
  4. T1212 Exploitation for Credential Access1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.