Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1468 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.66% | — | Xwiki Confluence Migrator PROAI | 7/3/2025 | 17/6/2026 | XWiki Confluence Migrator Pro helps admins to import confluence packages into their XWiki instance. A user that doesn't have programming rights can execute arbitrary code due to an unescaped translation when creating a page using the Migration Page template. This vulnerability is fixed in 1.2.0. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Xwiki | 20/2/2025 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki installation. To reproduce on an instance,… | |
| Aplazada | Media (6.4) | 0.43% | — | WP Wiki TooltipAI | 19/2/2025 | 17/6/2026 | The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.7) | 0.37% | — | LakeusAIMediawikiAI | 13/2/2025 | 17/6/2026 | Lakeus is a simple skin made for MediaWiki. Starting in version 1.0.8 and prior to versions 1.3.1+REL1.39, 1.3.1+REL1.42, and 1.4.0, Lakeus is vulnerable to store cross-site scripting via malicious system messages, though editing the messages requires high privileges. Those with `(editinterface)` rights can edit… | |
| Analizada | Alta (7.1) | 0.59% | — | Yeswiki | 21/1/2025 | 17/6/2026 | YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for any authenticated user, through the use of the filemanager to delete any file owned by the user running the FastCGI Process Manager (FPM) on the host without any limitation on the filesystem's scope. This vulnerability… | |
| Analizada | Media (5.4) | 0.41% | — | Yeswiki | 21/1/2025 | 17/6/2026 | YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for an authenticated user with rights to edit/create a page or comment to trigger a stored XSS which will be reflected on any page where the resource is loaded. The vulnerability makes use of the content edition feature and… | |
| Analizada | Media (6.1) | 0.35% | — | Yeswiki | 21/1/2025 | 17/6/2026 | YesWiki is a wiki system written in PHP. Versions up to and including 4.4.5 are vulnerable to any end-user crafting a DOM based XSS on all of YesWiki's pages which is triggered when a user clicks on a malicious link. The vulnerability makes use of the search by tag feature. When a tag doesn't exist, the tag is… | |
| Aplazada | Baja (2.4) | 0.35% | — | Wikimedia Mediawiki Socialprofile ExtensionAI | 14/1/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - SocialProfile Extension allows Functionality Misuse.This issue affects Mediawiki - SocialProfile Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X before 1.42.2. | |
| Aplazada | Baja (3.5) | 0.34% | — | Wikimedia MediawikiAIWikimedia Globalblocking ExtensionAI | 14/1/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - GlobalBlocking Extension allows Retrieve Embedded Sensitive Data. This issue briefly impacted the master branch of MediaWiki’s GlobalBlocking Extension. | |
| Aplazada | Media (5.4) | 0.31% | — | Wikimedia Mediawiki Refreshspecial ExtensionAI | 14/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RefreshSpecial Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - RefreshSpecial Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from… | |
| Analizada | Alta (8) | 0.41% | — | Xwiki | 14/1/2025 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. NOTE: The Realtime WYSIWYG Editor extension was **experimental**, and thus **not recommended**, in the versions affected by this vulnerability. It has become enabled by default, and thus recommended, starting with… | |
| Aplazada | Media (6.1) | 0.19% | — | Wikimedia Mediawiki Datatransfer ExtensionAI | 14/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects Mediawiki - DataTransfer Extension:… | |
| Aplazada | Media (5.3) | 0.30% | — | Wikimedia MediawikiAIWikimedia Openbadges ExtensionAI | 14/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - OpenBadges Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - OpenBadges Extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.3, from 1.42.X… | |
| Aplazada | Media (6.1) | 0.24% | — | Wikimedia Mediawiki Articlefeedbackv5AI | 10/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - ArticleFeedbackv5 extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - ArticleFeedbackv5 extension: from 1.42.X before 1.42.2. | |
| Aplazada | Media (6.5) | 0.25% | — | Wikimedia Mediawiki Breadcrumbs2AI | 10/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Breadcrumbs2 extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Breadcrumbs2 extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.5, from… | |
| Aplazada | Alta (8.6) | 0.51% | — | Mediawiki TabbernewAI | 6/1/2025 | 17/6/2026 | TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so an XSS payload as the page name can be used here. This vulnerability is fixed in 2.7.2. | |
| Aplazada | Alta (7.5) | 0.52% | — | Tiki Wiki CMSAI | 30/12/2024 | 17/6/2026 | Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Aplazada | Crítica (9.8) | 1.6% | — | Tiki Wiki CMSAI | 30/12/2024 | 17/6/2026 | Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | |
| Aplazada | Media (6.1) | 0.32% | — | Tiki Wiki CMSAI | 30/12/2024 | 17/6/2026 | Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) | |
| Analizada | Alta (8.8) | 1.1% | — | Xwiki | 12/12/2024 | 17/6/2026 | XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availability of the whole… | |
| Analizada | Alta (8.8) | 1.6% | — | Xwiki | 12/12/2024 | 17/6/2026 | XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page. This compromises the confidentiality, integrity and availability of… | |
| Analizada | Media (5.4) | 0.59% | — | Xwiki | 12/12/2024 | 17/6/2026 | XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right, view the document `Scheduler.WebHome` in a… | |
| Analizada | Alta (8.6) | 0.75% | — | Xwiki | 12/12/2024 | 17/6/2026 | XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned documents is defined from an unsanitized request parameter (request.sort) and can allow any user to inject HQL. Depending on the used database… | |
| Analizada | Alta (8.8) | 0.79% | — | Xwiki | 12/12/2024 | 17/6/2026 | XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on the server. This vulnerability has been fixed in XWiki 15.10.9 and… | |
| Aplazada | Media (5.4) | 0.44% | — | WikidocsAI | 25/11/2024 | 17/6/2026 | WikiDocs before 1.0.65 allows stored XSS by authenticated users via data that comes after $$\\, which is mishandled by a KaTeX parser. |