Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
866 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.33% | — | Mojoomla WpamsAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS apartment-management allows SQL Injection.This issue affects WPAMS: from n/a through <= 44.0 (17-08-2023). | |
| Aplazada | Crítica (9.3) | 0.45% | — | Mojoomla WpgymAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPGYM allows Blind SQL Injection. This issue affects WPGYM: from n/a through 65.0. | |
| Analizada | Media (6.5) | 0.22% | — | Joomlaserviceprovider JSP Store Locator | 15/5/2025 | 17/6/2026 | The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. | |
| Analizada | Alta (8.8) | 0.56% | — | Joomlaserviceprovider JSP Store Locator | 15/5/2025 | 17/6/2026 | The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks. | |
| Analizada | Alta (7.5) | 0.40% | 💥 PoC | Joomla! | 8/4/2025 | 17/6/2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | |
| Analizada | Crítica (9.8) | 0.47% | — | Joomla! | 8/4/2025 | 17/6/2026 | Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database package. Please note: the affected method is a protected method. It has no usages in the original packages in neither the 2.x nor 3.x branch and therefore the vulnerability in question can not be exploited… | |
| Analizada | Media (5.3) | 0.47% | — | Joomlaux JUX Real Estate | 24/3/2025 | 17/6/2026 | A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /extensions/realestate/index.php/agents/agent-register/addagent. The manipulation of the argument plan_id leads to cross site scripting. The attack may be… | |
| Analizada | Media (5.3) | 0.98% | 💥 Exploit | Joomlaux JUX Real Estate | 9/3/2025 | 17/6/2026 | A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties. The manipulation of the argument Itemid/jp_yearbuilt leads to cross site scripting. It… | |
| Analizada | Media (5.3) | 11% | 💥 Exploit | Joomlaux JUX Real Estate | 9/3/2025 | 17/6/2026 | A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties of the component GET Parameter Handler. The manipulation of the argument title leads to… | |
| Analizada | Alta (7.2) | 0.68% | — | Misterpah Mambo Joomla Importer | 22/2/2025 | 17/6/2026 | The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input via the $data parameter in the fImportMenu function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a… | |
| Aplazada | Media (6.7) | 0.45% | — | Joomla SchedulerAI | 18/2/2025 | 17/6/2026 | Improperly built order clauses lead to a SQL injection vulnerability in the backend task list of com_scheduler. | |
| Analizada | Alta (7.5) | 0.38% | — | Joomla! | 7/1/2025 | 17/6/2026 | Improper Access Controls allows access to protected views. | |
| Analizada | Alta (7.5) | 0.42% | — | Joomla! | 7/1/2025 | 17/6/2026 | Lack of output escaping in the id attribute of menu lists. | |
| Analizada | Media (6.1) | 0.25% | — | Joomla! | 7/1/2025 | 17/6/2026 | Various module chromes didn't properly process inputs, leading to XSS vectors. | |
| Analizada | Crítica (9.8) | 1.2% | — | Mojoomla Wordpress GYM Management System | 23/11/2024 | 17/6/2026 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on… | |
| Analizada | Alta (8.8) | 0.60% | — | Mojoomla Wordpress GYM Management System | 23/11/2024 | 17/6/2026 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Analizada | Media (6.1) | 0.27% | — | Joomla! | 20/8/2024 | 17/6/2026 | The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors. | |
| Analizada | Alta (7.5) | 0.35% | — | Joomla! | 20/8/2024 | 17/6/2026 | Improper Access Controls allows backend users to overwrite their username when disallowed. | |
| Analizada | Media (6.1) | 0.27% | — | Joomla! | 20/8/2024 | 17/6/2026 | The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. | |
| Analizada | Crítica (9.1) | 0.44% | — | Joomla! | 20/8/2024 | 17/6/2026 | The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors. | |
| Analizada | Media (6.1) | 0.25% | — | Joomla! | 20/8/2024 | 17/6/2026 | Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.. | |
| Modificada | Media (6.1) | 0.46% | — | Joomla! | 9/7/2024 | 17/6/2026 | The wrapper extensions do not correctly validate inputs, leading to XSS vectors. | |
| Modificada | Media (6.1) | 0.45% | — | Joomla! | 9/7/2024 | 17/6/2026 | The Custom Fields component not correctly filter inputs, leading to a XSS vector. | |
| Modificada | Media (6.1) | 0.44% | — | Joomla! | 9/7/2024 | 17/6/2026 | Improper handling of input could lead to an XSS vector in the StringHelper::truncate method. | |
| Modificada | Media (5.4) | 0.42% | — | Joomla! | 9/7/2024 | 17/6/2026 | The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector. |