Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1468 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.45% | — | Wikimedia Mediawiki Uploadwizard ExtensionAI | 18/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - UploadWizard Extension allows Stored XSS.This issue affects Mediawiki - UploadWizard Extension: from master before 1.39. | |
| Aplazada | Media (6.9) | 0.45% | — | Wikimedia Mediawiki Advanced Search ExtensionAI | 18/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - AdvancedSearch Extension allows Stored XSS.This issue affects Mediawiki - AdvancedSearch Extension: from master before 1.39. | |
| Aplazada | Media (6.9) | 0.45% | — | Wikimedia Mediawiki Skin BlueskyAI | 18/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Skin:BlueSky allows Stored XSS.This issue affects Mediawiki - Skin:BlueSky: from master before 1.39. | |
| Aplazada | Baja (2.1) | 0.27% | — | Wikimedia Mediawiki CargoAI | 17/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki Cargo extension allows SQL Injection.This issue affects MediaWiki Cargo extension: 1.39, 1.43, 1.44. | |
| Aplazada | Baja (2) | 0.31% | — | Wikimedia Mediawiki QuizgameAIWikimedia MediawikiAI | 17/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki QuizGame extension allows Stored XSS.This issue affects MediaWiki QuizGame extension: 1.39, 1.43, 1.44. | |
| Aplazada | Baja (2) | 0.31% | — | Wikimedia Mediawiki PollnyAIWikimedia MediawikiAI | 17/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki PollNY extension allows Stored XSS.This issue affects MediaWiki PollNY extension: 1.39, 1.43, 1.44. | |
| Aplazada | Media (5.9) | 0.39% | — | Wikimedia Mediawiki Webauthn ExtensionAI | 17/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44. | |
| Aplazada | Media (6.5) | 0.38% | — | Mediawiki BucketAI | 6/10/2025 | 17/6/2026 | Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to version 1.0.0, infinite recursion can occur if a user queries a bucket using the `!=` comparator. This will result in PHP's call stack limit exceeding, and/or increased memory consumption, potentially leading to a denial of… | |
| Aplazada | Media (6.5) | 1.5% | 💥 Exploit | DokuwikiAI | 6/10/2025 | 17/6/2026 | Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitrary code via the q parameter | |
| Aplazada | Crítica (9.3) | 2.4% | 💥 Exploit | Xwiki PlatformAI | 6/10/2025 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 4.3-milestone-1 and prior to versions 16.10.9, 17.4.2, and 17.5.0, the REST search URL is vulnerable to HQL injection via the `orderField` parameter. The specified value is added twice in the… | |
| Aplazada | Crítica (9.2) | 0.44% | — | Xwiki OidcAI | 6/10/2025 | 17/6/2026 | XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to version 2.18.2, anyone with VIEW access to a user profile can create a token for that user. If that XWiki instance is configured to allow token authentication, it allows authentication with any user… | |
| Aplazada | Crítica (10) | 0.73% | — | Xwiki Remote MacrosAI | 9/9/2025 | 17/6/2026 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the title in the confluence paste code macro allows remote code execution for any user who can edit any page. The classes parameter is… | |
| Aplazada | Crítica (10) | 0.73% | — | Xwiki Remote MacrosAI | 9/9/2025 | 17/6/2026 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the ac:type in the ConfluenceLayoutSection macro allows remote code execution for any user who can edit any page The classes parameter is… | |
| Analizada | Crítica (9.8) | 0.79% | — | Xwiki PRO Macros | 9/9/2025 | 17/6/2026 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the classes parameter in the panel macro allows remote code execution for any user who can edit any page The classes parameter is used… | |
| Analizada | Crítica (9.8) | 1.0% | — | Xwiki PRO Macros | 9/9/2025 | 17/6/2026 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the width parameter in the column macro allows remote code execution for any user who can edit any page or who can access the CKEditor… | |
| Modificada | Media (6.1) | 0.39% | — | Yeswiki | 9/9/2025 | 5/7/2026 | Cross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted payload to the meta configuration robots field | |
| Aplazada | Alta (8.7) | 0.58% | — | Xwiki BlogAI | 8/9/2025 | 17/6/2026 | The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Prior to version 9.14, the blog application in XWiki allowed remote code execution for any user who has edit right on any page. Normally, these are all logged-in users as they can edit their own user profile. For an exploit,… | |
| Analizada | Crítica (9.3) | 1.7% | 💥 Exploit | Xwiki | 3/9/2025 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are accessible through the webjars API. This is fixed in version 16.10.7. | |
| Analizada | Crítica (9.3) | 1.8% | 💥 Exploit | Xwiki | 3/9/2025 | 30/9/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to access and read configuration files by using URLs such as… | |
| Analizada | Alta (7.5) | 0.36% | — | Xwiki | 28/8/2025 | 25/9/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs store sensitive cookies unencrypted in job statuses. XWiki shouldn't store… | |
| Analizada | Alta (8.8) | 3.7% | 💥 Exploit | Xwiki | 20/8/2025 | 17/6/2026 | XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info field of the Global Preferences Presentation section. An authenticated administrator can inject crafted Apache Velocity template code, which is rendered on the… | |
| Analizada | Media (4.8) | 0.50% | 💥 Exploit | Xwiki | 20/8/2025 | 17/6/2026 | XWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administration interface, specifically under the Presentation section of the Global Preferences panel. An authenticated administrator can inject arbitrary JavaScript payloads into the HTTP Meta Info, Footer… | |
| Analizada | Alta (8.7) | 1.4% | 💥 Exploit | Xwiki | 6/8/2025 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 1.1 through 16.4.6, 16.5.0-rc-1 through 16.10.4 and 17.0.0-rc-1 through 17.1.0, the XML export of a page in XWiki that can be triggered by any… | |
| Analizada | Alta (7.1) | 0.45% | — | Xwiki | 6/8/2025 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 9.8-rc-1 through 16.4.6, 16.5.0-rc-1 through 16.10.4, and 17.0.0-rc-1 through 17.1.0, any user with editing rights can create an XClass with a… | |
| Analizada | Media (6.5) | 0.65% | 💥 Exploit | Xwiki | 6/8/2025 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-3 through 16.4.7, 16.5.0-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, two templates contain reflected XSS vulnerabilities, allowing an attacker to execute malicious JavaScript code… |