Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

595 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.54%—Pbootcms7/2/201917/6/2026
A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.
ModificadaMedia (6.1)0.86%—Xsltcms.org Project Xsltcms.org31/12/201817/6/2026
Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page "body" field.
ModificadaMedia (6.1)0.71%—Xsltcms.org Project Xsltcms.org31/12/201817/6/2026
Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page title field.
ModificadaAlta (7.2)1.5%—Craftcms Craft CMS25/12/201817/6/2026
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be…
ModificadaMedia (4.8)3.7%💥 ExploitCraftcms Craft CMS24/12/201817/6/2026
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
ModificadaCrítica (9.8)1.1%—Pbootcms6/12/201817/6/2026
SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string.
ModificadaCrítica (9.8)3.9%—Pbootcms27/11/201817/6/2026
PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/list/5/?current={pboot:if(evAl($_GET[a]))}1{/pboot:if}&a=phpinfo(); URI, because of an incorrect apps\home\controller\ParserController.php parserIfLabel protection…
ModificadaMedia (5.4)0.60%—Dotcms26/11/201817/6/2026
An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcms/dijit/image/image_tool.jsp.
ModificadaAlta (7.2)1.4%—Pbootcms7/11/201817/6/2026
PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, followed by a SELECT statement containing this PHP code.
ModificadaCrítica (9.8)1.5%—Pbootcms17/10/201817/6/2026
apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/1/id/3 URI.
ModificadaAlta (8.1)0.88%—Pbootcms10/10/201817/6/2026
PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.
ModificadaAlta (8.1)0.88%—Otcms23/9/201817/6/2026
OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.
ModificadaMedia (6.1)0.69%—Otcms16/9/201817/6/2026
An issue was discovered in OTCMS 3.61. XSS exists in admin/share_switch.php via these parameters: fieldName fieldName2 tabName.
ModificadaMedia (6.1)0.69%—Otcms16/9/201817/6/2026
An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr.
ModificadaMedia (6.1)0.84%—Dotcms12/9/201817/6/2026
dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.
ModificadaCrítica (9.8)3.7%—Elefantcms Elefant12/9/201817/6/2026
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in /designer/add/stylesheet.php by using a .php extension in the New Stylesheet Name field in conjunction with <?php content, because of insufficient input validation in apps/designer/handlers/csspreview.php.
ModificadaCrítica (9.8)3.6%—Elefantcms Elefant12/9/201817/6/2026
An issue was discovered in Elefant CMS before 2.0.7. There is a PHP Code Execution Vulnerability in apps/filemanager/upload/drop.php by using /filemanager/api/rm/.htaccess to remove the .htaccess file, and then using a filename that ends in .php followed by space characters (for bypassing the blacklist).
ModificadaAlta (8.8)0.65%—Elefantcms3/9/201817/6/2026
An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add.
ModificadaCrítica (9.8)1.6%—Elefantcms21/8/201817/6/2026
apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload executable files" protection mechanism.
ModificadaCrítica (9.8)3.8%💥 PoCFlintcms17/8/201817/6/2026
A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in password reset.
ModificadaAlta (8.1)6.5%—Dotcms24/7/201817/6/2026
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, there are no checks on the types of files which the bundle contains. This…
ModificadaMedia (6.5)2.8%—Dotcms24/7/201817/6/2026
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to path traversal. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, the filenames of its contents are not properly checked, allowing for writing files to…
ModificadaAlta (8.8)1.1%—Dotcms24/7/201817/6/2026
The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS administrator panel contains a cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and…
ModificadaMedia (6.1)0.86%—Instantcms18/7/201817/6/2026
InstantCMS 2.10.1 has /redirect?url= XSS.
ModificadaCrítica (9.8)1.1%—Pbootcms22/5/201817/6/2026
An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter.
Orbitaley — Vulnerabilidades