Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
351 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.8% | — | Craftcms Craft CMS | 19/5/2023 | 17/6/2026 | Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execution. If the name parameter value is not empty string('') in the View.php's doesTemplateExist() -> resolveTemplate() -> _resolveTemplateInternal() -> _resolveTemplate()… | |
| Modificada | Media (5.4) | 0.36% | — | Ncrafts Formcraft | 15/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in nCrafts FormCraft plugin <= 1.2.6 versions. | |
| Modificada | Alta (8.8) | 1.4% | — | Craftcms Craft CMS | 12/5/2023 | 17/6/2026 | An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter. | |
| Modificada | Media (6.1) | 0.41% | — | Craftcms Craft CMS | 9/5/2023 | 17/6/2026 | Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4. | |
| Modificada | Media (6.1) | 0.40% | — | Craftcms Craft CMS | 25/4/2023 | 17/6/2026 | CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name. | |
| Modificada | Crítica (9.8) | 1.7% | 💥 PoC | Bibliocraftmod Bibliocraft | 7/4/2023 | 17/6/2026 | BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution. | |
| Modificada | Media (5.4) | 0.80% | — | Craftcms Craft CMS | 3/3/2023 | 17/6/2026 | Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an entry type, an cross-site scripting (XSS) happens in the quick post widget on the admin dashboard. This issue has been fixed in version 4.3.7. | |
| Modificada | Alta (7.2) | 0.44% | — | Craftercms Crafter CMS | 17/2/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26. | |
| Modificada | Media (6.1) | 0.52% | — | Wordcraft Project Wordcraft | 29/1/2023 | 16/6/2026 | A vulnerability was found in capnsquarepants wordcraft up to 0.6. It has been classified as problematic. Affected is an unknown function of the file tag.php. The manipulation of the argument tag leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 0.7 is able to address… | |
| Modificada | Alta (7.5) | 1.1% | — | Craftcms Craft CMS | 5/12/2022 | 17/6/2026 | All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site Request Forgery attacks. The… | |
| Modificada | Media (5.4) | 0.51% | — | Craftcms Craft CMS | 21/9/2022 | 17/6/2026 | Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label. | |
| Modificada | Alta (7.5) | 1.0% | — | Mcwebserver Minecraft MOD FOR Fabric AND Quilt Project Mcwebserver Minecraft MOD FOR Fabric AND QuiltMcwebserver Minecraft MOD FOR Forge Project Mcwebserver Minecraft MOD FOR Forge | 21/9/2022 | 17/6/2026 | McWebserver mod runs a simple HTTP server alongside the Minecraft server in seperate threads. Path traversal in McWebserver Minecraft Mod for Fabric and Quilt up to and including 0.1.2.1 and McWebserver Minecraft Mod for Forge up to and including 0.1.1 allows all files, accessible by the program, to be read by anyone… | |
| Modificada | Media (5.4) | 0.50% | — | Craftcms Craft CMS | 16/9/2022 | 9/7/2026 | Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts. | |
| Modificada | Media (5.4) | 0.57% | — | Craftcms Craft CMS | 16/9/2022 | 17/6/2026 | Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page. | |
| Modificada | Media (5.4) | 0.66% | — | Craftcms Craft CMS | 16/9/2022 | 17/6/2026 | Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php. | |
| Modificada | Media (5.4) | 0.67% | — | Craftcms Craft CMS | 16/9/2022 | 17/6/2026 | Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount. | |
| Modificada | Alta (7.2) | 1.6% | 💥 PoC | Craftercms Crafter CMS | 13/9/2022 | 17/6/2026 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. | |
| Modificada | Alta (7.2) | 1.6% | 💥 PoC | Craftercms Crafter CMS | 13/9/2022 | 17/6/2026 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker SSTI. | |
| Modificada | Media (4.8) | 0.59% | — | Ncrafts Formcraft | 8/6/2022 | 17/6/2026 | The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8.8) | 0.93% | — | Craftercms Crafter CMS | 16/5/2022 | 17/6/2026 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static methods. | |
| Modificada | Media (4.3) | 0.56% | — | Craftercms Crafter CMS | 16/5/2022 | 17/6/2026 | An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator. | |
| Modificada | Media (4.3) | 0.60% | — | Craftercms Crafter CMS | 16/5/2022 | 17/6/2026 | A logged-in and authenticated user with a Reviewer Role may lock a content item. | |
| Modificada | Media (4.8) | 0.59% | — | Moecraft Tieba-cloud-sign | 12/5/2022 | 17/6/2026 | Tieba-Cloud-Sign v4.9 was discovered to contain a cross-site scripting (XSS) vulnerability via the function strip_tags. | |
| Modificada | Alta (8.8) | 4.6% | — | Craftcms Craft CMS | 9/5/2022 | 17/6/2026 | Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the password reset functionality. Specifically, the attacker must send X-Forwarded-Host… | |
| Modificada | Crítica (9.8) | 1.4% | — | Thedigitalcraft Atomcms | 12/4/2022 | 17/6/2026 | AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php |