Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
595 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.53% | — | Wtcms Project Wtcms | 1/9/2021 | 17/6/2026 | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module. | |
| Modificada | Media (5.4) | 0.50% | — | Wtcms Project Wtcms | 1/9/2021 | 17/6/2026 | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module. | |
| Modificada | Media (5.4) | 0.55% | — | Wtcms Project Wtcms | 1/9/2021 | 9/7/2026 | WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box. | |
| Modificada | Media (5.4) | 0.50% | — | Wtcms Project Wtcms | 1/9/2021 | 17/6/2026 | WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module. | |
| Modificada | Media (6.5) | 0.43% | — | Wtcms Project Wtcms | 1/9/2021 | 17/6/2026 | WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the administrator background. | |
| Modificada | Alta (8.8) | 2.0% | — | Dotcms | 18/8/2021 | 17/6/2026 | Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Exponentcms | 16/8/2021 | 17/6/2026 | A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can change links on the webpage to an arbitrary value, leading to a possible attack vector for MITM. | |
| Modificada | Media (4.8) | 0.53% | — | Pbootcms | 12/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php. | |
| Modificada | Media (4.8) | 0.56% | — | Dotcms | 9/7/2021 | 17/6/2026 | A reflected cross site scripting (XSS) vulnerability in dotAdmin/#/c/links of dotCMS 21.05.1 allows attackers to execute arbitrary commands or HTML via a crafted payload. | |
| Modificada | Media (4.8) | 0.56% | — | Dotcms | 9/7/2021 | 17/6/2026 | A reflected cross site scripting (XSS) vulnerability in dotAdmin/#/c/containers of dotCMS 21.05.1 allows attackers to execute arbitrary commands or HTML via a crafted payload. | |
| Modificada | Media (4.8) | 0.50% | — | Dotcms | 9/7/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in dotAdmin/#/c/c_Images of dotCMS 21.05.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' and 'Filename' parameters. | |
| Modificada | Media (6.5) | 0.80% | — | Pbootcms | 9/7/2021 | 17/6/2026 | Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php. | |
| Modificada | Crítica (9.8) | 2.5% | — | Pbootcms | 8/7/2021 | 17/6/2026 | Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board. | |
| Modificada | Media (4.8) | 0.57% | — | Pbootcms | 8/7/2021 | 9/7/2026 | Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php. | |
| Modificada | Crítica (9.8) | 2.8% | — | Craftcms Craft CMS | 30/6/2021 | 17/6/2026 | An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session). | |
| Modificada | Media (6.1) | 0.99% | — | Craftcms Craft CMS | 30/6/2021 | 17/6/2026 | An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads. | |
| Modificada | Media (4.8) | 0.48% | — | Pbootcms | 3/6/2021 | 17/6/2026 | Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php. | |
| Modificada | Media (6.1) | 0.73% | — | Craftcms Craft CMS | 7/5/2021 | 17/6/2026 | Craft CMS before 3.6.13 has an XSS vulnerability. | |
| Modificada | Media (5.4) | 0.84% | — | Dotcms | 23/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" component. | |
| Modificada | Crítica (9.8) | 2.4% | — | Lightcms Project Lightcms | 15/4/2021 | 17/6/2026 | LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading of external images. | |
| Modificada | Alta (7.5) | 1.1% | — | Pbootcms | 31/3/2021 | 17/6/2026 | PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account. | |
| Modificada | Media (5.4) | 0.85% | — | Craftcms Craft CMS | 26/3/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new. | |
| Modificada | Media (5.4) | 7.2% | 💥 Exploit | Lightcms Project Lightcms | 24/2/2021 | 17/6/2026 | A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords. | |
| Modificada | Alta (7.5) | 1.7% | — | Boltcms Bolt | 17/2/2021 | 17/6/2026 | Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal. | |
| Modificada | Crítica (9.8) | 1.3% | — | Exponentcms Exponent CMS | 31/12/2020 | 17/6/2026 | Exponent CMS before 2.6.0 has improper input validation in fileController.php. |