Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.73% | — | Mylittleforum MY Little Forum | 9/2/2026 | 17/6/2026 | my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to 20260208.1, the application fails to filter the phar:// protocol in URL validation, allowing attackers to upload a malicious Phar Polyglot file (disguised as JPEG) via the image upload feature,… | |
| Modificada | Alta (8.5) | 0.76% | — | Beehiveforum Beehive Forum | 13/1/2026 | 17/6/2026 | Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset tokens and change victim account passwords without direct authentication. | |
| Aplazada | Alta (8.8) | 0.40% | — | Mylittleforum MY Little ForumAI | 22/10/2025 | 30/9/2026 | my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to version 2.5.12, an authenticated SQL injection vulnerability in the bookmark reordering feature allows any logged-in user to execute arbitrary SQL commands. This can lead to a full compromise of the… | |
| Modificada | Media (6.5) | 0.60% | — | Mylittleforum MY Little Forum | 21/5/2019 | 17/6/2026 | my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting. | |
| Modificada | Media (6.5) | 0.41% | — | Mylittleforum MY Little Forum | 20/8/2018 | 17/6/2026 | my little forum 2.4.12 allows CSRF for deletion of users. | |
| Modificada | Media (4.8) | 0.91% | — | Mylittleforum MY Little Forum | 5/8/2018 | 17/6/2026 | The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field. | |
| Modificada | Media (4.8) | 0.91% | — | Mylittleforum MY Little Forum | 5/8/2018 | 17/6/2026 | The Add page option in my little forum 2.4.12 allows XSS via the Title field. | |
| Modificada | Media (4.3) | 2.4% | — | Mylittleforum MY Little Forum | 16/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in my little forum before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the back parameter to index.php. | |
| Modificada | Media (6.5) | 1.8% | — | Mylittleforum MY Little Forum | 16/2/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in my little forum before 2.3.4 allow remote administrators to execute arbitrary SQL commands via the (1) letter parameter in a user action or (2) edit_category parameter to index.php. | |
| Modificada | Media (4.3) | 1.9% | — | Mylittleforum MY Little Forum | 4/2/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in my little forum 2.3.3, 2.2, and 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) category parameter to forum.php or the (3) page or (4) order parameter to (a) board_entry.php or (b) forum_entry.php. | |
| Modificada | Media (4.3) | 0.92% | — | Courseforum Projectforum | 3/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CourseForum ProjectForum 7.0.1.3038 allows remote attackers to inject arbitrary web script or HTML via a crafted name of an object within a more object on a wiki page. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Mylittleforum MY Little Forum | 2/6/2010 | 16/6/2026 | SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Lukas Waldauf Phpfreeforum | 6/3/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to part/menu.php. | |
| Modificada | Media (5) | 6.2% | 💥 Exploit | Codeavalanche Freeforum | 21/1/2009 | 16/6/2026 | CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for _private/CAForum.mdb. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Zoneo-soft Freeforum | 10/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter to (1) the default URI or (2) index.php, or (3) the PATH_INFO to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Media (4.3) | 1.1% | — | Jcorporate Eforum | 24/3/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in busca.php in eForum 0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) busca and (2) link parameters. | |
| Modificada | Media (4.3) | 1.1% | — | Simpleforum | 3/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in simpleforum.cgi in SimpleForum 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchkey parameter in a search action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 3.3% | — | Xeforum | 29/6/2007 | 16/6/2026 | Xeweb XEForum allows remote attackers to gain privileges via a modified xeforum cookie. | |
| Modificada | Alta (7.5) | 1.4% | — | Zoneo-soft Freeforum | 25/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue has been disputed by third party researchers, stating that fpath variable is initialized before being used | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Freeforum | 11/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in forum.php in FreeForum 0.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Xfairguy Codeavalanche Freeforum | 9/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in post.asp in CodeAvalanche FreeForum (aka CAForum) 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_subject and (2) msg_body parameters. NOTE: The provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Alta (7.5) | 1.3% | — | Xfairguy Codeavalanche Freeforum | 5/6/2006 | 16/6/2026 | SQL injection vulnerability in admin/default.asp in Dusan Drobac CodeAvalanche FreeForum (aka CAForum) 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Battleaxe Software Bttlxeforum | 3/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Zoneo-soft Freeforum | 2/3/2006 | 16/6/2026 | Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php. | |
| Modificada | Media (4.3) | 1.4% | — | Zoneo-soft Freeforum | 2/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) subject parameters. |