Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

866 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.44%—Joomla!9/7/202417/6/2026
Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.
AplazadaMedia (5.3)0.55%—Fredericgilles FG Joomla TO WordpressAI24/4/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Joomla to WordPress.This issue affects FG Joomla to WordPress: from n/a through 4.20.2.
AnalizadaMedia (6.5)49%—Joomla!29/2/202417/6/2026
Inadequate content filtering leads to XSS vulnerabilities in various components.
AnalizadaMedia (6.1)32%—Joomla!29/2/202417/6/2026
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
ModificadaMedia (6.1)0.51%—Joomla!29/2/202417/6/2026
Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.
AnalizadaMedia (4.3)0.54%—Joomla!29/2/202417/6/2026
Inadequate parsing of URLs could result into an open redirect.
AnalizadaMedia (6.3)0.51%—Joomla!29/2/202417/6/2026
The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.
AplazadaMedia (4.3)0.28%—Fredericgilles FG Prestashop TO WoocommerceAIFredericgilles FG Drupal TO WordpressAIFredericgilles FG Joomla TO WordpressAI21/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joomla to WordPress.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.44.3; FG Drupal to WordPress: from n/a through 3.67.0; FG Joomla to…
ModificadaCrítica (9.8)0.83%—Joomlart S5 Register14/12/202317/6/2026
SQLi vulnerability in S5 Register module for Joomla.
ModificadaAlta (7.5)0.81%💥 PoCJoomla!29/11/202317/6/2026
The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information.
ModificadaMedia (5.4)0.38%—2joomla 2J Slideshow2/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team Slideshow, Image Slider by 2J plugin <= 1.3.54 versions.
ModificadaMedia (4.8)0.37%—Joomlaserviceprovider Wsecure4/9/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay Lulia wSecure Lite plugin <= 2.5 versions.
ModificadaMedia (4.3)0.71%—2joomla 2J Slideshow7/6/202317/6/2026
The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'twoj_slideshow_setup' function called via the wp_ajax_twoj_slideshow_setup AJAX action in versions up to, and including, 1.3.31. This makes it possible for authenticated attackers (Subscriber, or above…
ModificadaAlta (7.5)0.56%—Joomla!30/5/202317/6/2026
An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods.
ModificadaMedia (6.1)0.41%—Joomla!30/5/202317/6/2026
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.
AnalizadaMedia (5.3)100%⚠ Explotación activa💥 ExploitJoomla!16/2/202317/6/2026
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
ModificadaMedia (4.3)0.44%—Joomla!1/2/202317/6/2026
An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_actionlogs.
ModificadaMedia (6.3)0.23%—Joomla!1/2/202317/6/2026
An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.
ModificadaCrítica (9.8)0.66%—Joomla MOD Einsatz Stats Project Joomla MOD Einsatz Stats8/1/202317/6/2026
A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2. It has been classified as critical. This affects the function getStatsByType of the file helper.php. The manipulation of the argument year leads to sql injection. Upgrading to version 0.3 is able to address this issue. The identifier of the…
AnalizadaCrítica (9.8)0.52%—Rsjoomla Rsfirewall!15/12/202217/6/2026
RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented.
ModificadaMedia (6.1)0.48%—Joomla!8/11/202217/6/2026
An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media.
ModificadaMedia (6.1)0.40%💥 PoCJoomla!25/10/202217/6/2026
An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components.
ModificadaMedia (5.3)0.56%—Joomla!25/10/202217/6/2026
An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests.
ModificadaMedia (5.3)0.59%—Joomla!31/8/202217/6/2026
An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes.
ModificadaMedia (6.1)0.54%—Joomlatools Docman10/7/202217/6/2026
In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Site Scripting (XSS) in an image upload function
Orbitaley — Vulnerabilidades