Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
595 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.54% | — | Pbootcms | 7/2/2019 | 17/6/2026 | A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI. | |
| Modificada | Media (6.1) | 0.86% | — | Xsltcms.org Project Xsltcms.org | 31/12/2018 | 17/6/2026 | Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page "body" field. | |
| Modificada | Media (6.1) | 0.71% | — | Xsltcms.org Project Xsltcms.org | 31/12/2018 | 17/6/2026 | Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page title field. | |
| Modificada | Alta (7.2) | 1.5% | — | Craftcms Craft CMS | 25/12/2018 | 17/6/2026 | Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be… | |
| Modificada | Media (4.8) | 3.7% | 💥 Exploit | Craftcms Craft CMS | 24/12/2018 | 17/6/2026 | index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab. | |
| Modificada | Crítica (9.8) | 1.1% | — | Pbootcms | 6/12/2018 | 17/6/2026 | SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string. | |
| Modificada | Crítica (9.8) | 3.9% | — | Pbootcms | 27/11/2018 | 17/6/2026 | PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/list/5/?current={pboot:if(evAl($_GET[a]))}1{/pboot:if}&a=phpinfo(); URI, because of an incorrect apps\home\controller\ParserController.php parserIfLabel protection… | |
| Modificada | Media (5.4) | 0.60% | — | Dotcms | 26/11/2018 | 17/6/2026 | An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcms/dijit/image/image_tool.jsp. | |
| Modificada | Alta (7.2) | 1.4% | — | Pbootcms | 7/11/2018 | 17/6/2026 | PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, followed by a SELECT statement containing this PHP code. | |
| Modificada | Crítica (9.8) | 1.5% | — | Pbootcms | 17/10/2018 | 17/6/2026 | apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/1/id/3 URI. | |
| Modificada | Alta (8.1) | 0.88% | — | Pbootcms | 10/10/2018 | 17/6/2026 | PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI. | |
| Modificada | Alta (8.1) | 0.88% | — | Otcms | 23/9/2018 | 17/6/2026 | OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter. | |
| Modificada | Media (6.1) | 0.69% | — | Otcms | 16/9/2018 | 17/6/2026 | An issue was discovered in OTCMS 3.61. XSS exists in admin/share_switch.php via these parameters: fieldName fieldName2 tabName. | |
| Modificada | Media (6.1) | 0.69% | — | Otcms | 16/9/2018 | 17/6/2026 | An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr. | |
| Modificada | Media (6.1) | 0.84% | — | Dotcms | 12/9/2018 | 17/6/2026 | dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters. | |
| Modificada | Crítica (9.8) | 3.7% | — | Elefantcms Elefant | 12/9/2018 | 17/6/2026 | An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input validation in apps/designer/handlers/csspreview.php. | |
| Modificada | Crítica (9.8) | 3.6% | — | Elefantcms Elefant | 12/9/2018 | 17/6/2026 | An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /filemanager/api/rm/.htaccess to remove the .htaccess file, and then using a filename that ends in .php followed by space characters (for bypassing the blacklist). | |
| Modificada | Alta (8.8) | 0.65% | — | Elefantcms | 3/9/2018 | 17/6/2026 | An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add. | |
| Modificada | Crítica (9.8) | 1.6% | — | Elefantcms | 21/8/2018 | 17/6/2026 | apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload executable files" protection mechanism. | |
| Modificada | Crítica (9.8) | 3.8% | 💥 PoC | Flintcms | 17/8/2018 | 17/6/2026 | A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in password reset. | |
| Modificada | Alta (8.1) | 6.5% | — | Dotcms | 24/7/2018 | 17/6/2026 | The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, there are no checks on the types of files which the bundle contains. This… | |
| Modificada | Media (6.5) | 2.8% | — | Dotcms | 24/7/2018 | 17/6/2026 | The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to path traversal. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, the filenames of its contents are not properly checked, allowing for writing files to… | |
| Modificada | Alta (8.8) | 1.1% | — | Dotcms | 24/7/2018 | 17/6/2026 | The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS administrator panel contains a cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and… | |
| Modificada | Media (6.1) | 0.86% | — | Instantcms | 18/7/2018 | 17/6/2026 | InstantCMS 2.10.1 has /redirect?url= XSS. | |
| Modificada | Crítica (9.8) | 1.1% | — | Pbootcms | 22/5/2018 | 17/6/2026 | An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter. |