Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.44%—Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI14/9/202616/9/2026
Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context in which the tag is used. Joomla's string…
AplazadaAlta (7.5)0.42%—Regularlabs Articles AnywhereAIJoomlaAI14/9/202616/9/2026
Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover. In affected versions, those options become real HTML event attributes without checking the article author's trust…
AplazadaMedia (6)0.21%—Aotuman Grab Wechat ArticlesAI18/8/202620/8/2026
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
AplazadaAlta (7.5)0.42%—Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI23/7/202628/7/2026
Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it…
AplazadaAlta (7.5)0.43%—Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI23/7/202627/7/2026
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF,…
AplazadaMedia (6.5)0.42%—Regularlabs Users AnywhereAIRegularlabs Articles AnywhereAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.
AplazadaCrítica (9.1)0.43%—Regularlabs Articles AnywhereAIRegularlabs Modules AnywhereAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the…
AplazadaAlta (8.2)0.50%💥 PoCDate Menu OF News ArticlesAI19/5/202617/6/2026
The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the…
AplazadaCrítica (9.8)0.39%—Joomla Articles CalendarAIJoomlaAI18/7/202517/6/2026
A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.
AplazadaCrítica (9.8)0.39%—Joomla Articles Good SearchAI18/7/202517/6/2026
A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.
AplazadaMedia (5.4)0.18%—Wikimedia Mediawiki Related Articles ExtensionAI7/7/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RelatedArticles Extension allows Stored XSS.This issue affects Mediawiki - RelatedArticles Extension: from 1.43.X before 1.43.2.
AplazadaMedia (6.5)0.32%—Erik Saulnier News ArticlesAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erik Saulnier News Articles news-articles allows Stored XSS.This issue affects News Articles: from n/a through <= 1.0.0.
ModificadaMedia (6.1)0.33%—Dj-extensions Dj-helpfularticles9/7/202417/6/2026
XSS vulnerability in DJ-HelpfulArticles component for Joomla.
ModificadaMedia (6.5)0.53%—Pdf24 Articles TO PDF Project Pdf24 Articles TO PDF20/6/202217/6/2026
The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaMedia (6.5)0.53%—Pdf24 Articles TO PDF Project Pdf24 Articles TO PDF20/6/202217/6/2026
The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaAlta (7.5)1.4%—News-articles Project News-articles26/6/201817/6/2026
ventrian News-Articles version NewsArticles.00.09.11 contains a XML External Entity (XXE) vulnerability in News-Articles/API/MetaWebLog/Handler.ashx.vb that can result in Attacker can read any file in the server or use smbrelay attack to access to server..
ModificadaCrítica (9.8)2.1%💥 ExploitYourarticlesdirectory Article Directory Script29/10/201717/6/2026
Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.
ModificadaCrítica (9.8)1.2%—Smart Related Articles Project Smart Related Articles13/4/201717/6/2026
The "Smart related articles" extension 1.1 for Joomla! has SQL injection in dialog.php (attacker must use search_cats variable in POST method to exploit this vulnerability).
ModificadaMedia (5.3)0.72%—Smart Related Articles Project Smart Related Articles13/4/201717/6/2026
The "Smart related articles" extension 1.1 for Joomla! does not prevent direct requests to dialog.php (there is a missing _JEXEC check).
ModificadaMedia (6.1)0.85%—Smart Related Articles Project Smart Related Articles13/4/201717/6/2026
The "Smart related articles" extension 1.1 for Joomla! has XSS in dialog.php (n_art,type in GET Method).
ModificadaMedia (6.5)3.4%💥 ExploitKalptaru Infotech Stararticles25/8/200916/6/2026
Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile photo, then accessing it via a direct request to the file in authorphoto/.
ModificadaAlta (7.5)2.0%💥 ExploitKalptaru Infotech Stararticles25/8/200916/6/2026
Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbitrary SQL commands via (1) the subcatid parameter to article.list.php; or the artid parameter to (2) article.print.php, (3) article.comments.php, (4) article.publisher.php, or (5)…
ModificadaMedia (4.3)1.5%💥 ExploitEdgephp Ezarticles24/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in articles.php in EDGEPHP EZArticles allows remote attackers to inject arbitrary web script or HTML via the title parameter.
ModificadaAlta (7.5)0.97%💥 ExploitYourarticlesdirectory Your Articles Directory27/6/200916/6/2026
SQL injection vulnerability in yad-admin/login.php in Your Article Directory allows remote attackers to execute arbitrary SQL commands via the txtAdminEmail parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.96%💥 ExploitYourarticlesdirectory Your Articles Directory27/6/200916/6/2026
SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.