Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
866 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.44% | — | Joomla! | 9/7/2024 | 17/6/2026 | Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field. | |
| Aplazada | Media (5.3) | 0.55% | — | Fredericgilles FG Joomla TO WordpressAI | 24/4/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Joomla to WordPress.This issue affects FG Joomla to WordPress: from n/a through 4.20.2. | |
| Analizada | Media (6.5) | 49% | — | Joomla! | 29/2/2024 | 17/6/2026 | Inadequate content filtering leads to XSS vulnerabilities in various components. | |
| Analizada | Media (6.1) | 32% | — | Joomla! | 29/2/2024 | 17/6/2026 | Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components. | |
| Modificada | Media (6.1) | 0.51% | — | Joomla! | 29/2/2024 | 17/6/2026 | Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions. | |
| Analizada | Media (4.3) | 0.54% | — | Joomla! | 29/2/2024 | 17/6/2026 | Inadequate parsing of URLs could result into an open redirect. | |
| Analizada | Media (6.3) | 0.51% | — | Joomla! | 29/2/2024 | 17/6/2026 | The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified. | |
| Aplazada | Media (4.3) | 0.28% | — | Fredericgilles FG Prestashop TO WoocommerceAIFredericgilles FG Drupal TO WordpressAIFredericgilles FG Joomla TO WordpressAI | 21/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joomla to WordPress.This issue affects FG PrestaShop to WooCommerce: from n/a through 4.44.3; FG Drupal to WordPress: from n/a through 3.67.0; FG Joomla to… | |
| Modificada | Crítica (9.8) | 0.83% | — | Joomlart S5 Register | 14/12/2023 | 17/6/2026 | SQLi vulnerability in S5 Register module for Joomla. | |
| Modificada | Alta (7.5) | 0.81% | 💥 PoC | Joomla! | 29/11/2023 | 17/6/2026 | The language file parsing process could be manipulated to expose environment variables. Environment variables might contain sensible information. | |
| Modificada | Media (5.4) | 0.38% | — | 2joomla 2J Slideshow | 2/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in 2J Slideshow Team Slideshow, Image Slider by 2J plugin <= 1.3.54 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Joomlaserviceprovider Wsecure | 4/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay Lulia wSecure Lite plugin <= 2.5 versions. | |
| Modificada | Media (4.3) | 0.71% | — | 2joomla 2J Slideshow | 7/6/2023 | 17/6/2026 | The 2J-SlideShow Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'twoj_slideshow_setup' function called via the wp_ajax_twoj_slideshow_setup AJAX action in versions up to, and including, 1.3.31. This makes it possible for authenticated attackers (Subscriber, or above… | |
| Modificada | Alta (7.5) | 0.56% | — | Joomla! | 30/5/2023 | 17/6/2026 | An issue was discovered in Joomla! 4.2.0 through 4.3.1. The lack of rate limiting allowed brute force attacks against MFA methods. | |
| Modificada | Media (6.1) | 0.41% | — | Joomla! | 30/5/2023 | 17/6/2026 | An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen. | |
| Analizada | Media (5.3) | 100% | ⚠ Explotación activa💥 Exploit | Joomla! | 16/2/2023 | 17/6/2026 | An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. | |
| Modificada | Media (4.3) | 0.44% | — | Joomla! | 1/2/2023 | 17/6/2026 | An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_actionlogs. | |
| Modificada | Media (6.3) | 0.23% | — | Joomla! | 1/2/2023 | 17/6/2026 | An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages. | |
| Modificada | Crítica (9.8) | 0.66% | — | Joomla MOD Einsatz Stats Project Joomla MOD Einsatz Stats | 8/1/2023 | 17/6/2026 | A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2. It has been classified as critical. This affects the function getStatsByType of the file helper.php. The manipulation of the argument year leads to sql injection. Upgrading to version 0.3 is able to address this issue. The identifier of the… | |
| Analizada | Crítica (9.8) | 0.52% | — | Rsjoomla Rsfirewall! | 15/12/2022 | 17/6/2026 | RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented. | |
| Modificada | Media (6.1) | 0.48% | — | Joomla! | 8/11/2022 | 17/6/2026 | An issue was discovered in Joomla! 4.0.0 through 4.2.4. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in com_media. | |
| Modificada | Media (6.1) | 0.40% | 💥 PoC | Joomla! | 25/10/2022 | 17/6/2026 | An issue was discovered in Joomla! 4.2.0 through 4.2.3. Inadequate filtering of potentially malicious user input leads to reflected XSS vulnerabilities in various components. | |
| Modificada | Media (5.3) | 0.56% | — | Joomla! | 25/10/2022 | 17/6/2026 | An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous requests. | |
| Modificada | Media (5.3) | 0.59% | — | Joomla! | 31/8/2022 | 17/6/2026 | An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused by the PSR12 changes. | |
| Modificada | Media (6.1) | 0.54% | — | Joomlatools Docman | 10/7/2022 | 17/6/2026 | In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Site Scripting (XSS) in an image upload function |