Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

62 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.56%💥 PoCAmasty Blog PRO17/11/202217/6/2026
The Preview functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 uses eval unsafely. This allows attackers to perform Cross-site Scripting attacks on admin panel users by manipulating the generated preview application response.
ModificadaMedia (6.1)0.64%—Mogublog Project Mogublog12/7/202217/6/2026
Mogu blog 5.2 is vulnerable to Cross Site Scripting (XSS).
ModificadaMedia (5.4)0.30%—Sideblog Project Sideblog13/6/202217/6/2026
The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping
ModificadaMedia (4.3)0.45%—Easy Blog Project Easy Blog13/6/202217/6/2026
Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthenticated attacker to hijack the authentication of the administrator and delete a blog article or a category via a specially crafted page.
ModificadaCrítica (9.8)2.0%—Responsive Online Blog Project Responsive Online Blog2/6/202217/6/2026
Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.
ModificadaMedia (5.4)0.88%—Simple Blog Project Simple Blog23/5/202217/6/2026
The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur.
ModificadaCrítica (9.8)1.4%—Fantastic Blog Project Fantastic Blog4/5/202217/6/2026
A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters.
ModificadaMedia (6.1)0.56%—Forestblog Project Forestblog16/4/202217/6/2026
ForestBlog through 2022-02-16 allows admin/profile/save userAvatar XSS during addition of a user avatar.
ModificadaAlta (8.8)9.9%💥 ExploitBlog Project Blog8/2/202217/6/2026
m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` have not been checked properly. Although PHP issued warnings and the upload function returned `false`, the original file (that could contain a malicious payload) was kept on the disk. Users are…
ModificadaMedia (6.5)0.67%—Oneblog Project Oneblog25/1/202217/6/2026
OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators beyond their authority.
ModificadaMedia (6.1)0.59%—Forestblog Project Forestblog25/1/202217/6/2026
A problem was found in ForestBlog, as of 2021-12-29, there is a XSS vulnerability that can be injected through the nickname input box.
ModificadaCrítica (9.8)1.2%—Forestblog Project Forestblog25/1/202217/6/2026
In ForestBlog, as of 2021-12-28, File upload can bypass verification.
ModificadaMedia (4.3)0.36%—Mblog Project Mblog20/1/202217/6/2026
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.
ModificadaMedia (5.4)0.50%—Oneblog Project Oneblog19/1/202217/6/2026
A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in the background.
ModificadaMedia (6.1)0.57%—Thinkphp-bjyblog Project Thinkphp-bjyblog2/12/202117/6/2026
thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function terminates the script and prints a message to the user that contains $_SERVER['HTTP_HOST'].
ModificadaAlta (8.1)0.54%—Print MY Blog Project Print MY Blog20/9/202117/6/2026
The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link
ModificadaMedia (4.8)0.61%—Drawblog Project Drawblog2/8/202117/6/2026
The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them back in the page, leading to an authenticated stored Cross-Site Scripting issue
ModificadaMedia (6.1)0.84%—Fantastic Blog Project Fantastic Blog22/7/202117/6/2026
Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject arbitrary web script or HTML via the search field to search.php.
ModificadaAlta (8.8)0.55%—Forestblog Project Forestblog11/5/202117/6/2026
Cross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, which could let a remote malicious gain privileges.
ModificadaMedia (5.4)0.64%—Mblog Project Mblog1/4/202117/6/2026
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.
ModificadaMedia (5.4)0.64%—Mblog Project Mblog1/4/202117/6/2026
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing.
ModificadaMedia (5.4)0.60%—Mblog Project Mblog1/4/202117/6/2026
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile.
ModificadaMedia (5.4)0.60%—Mblog Project Mblog1/4/202117/6/2026
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing.
ModificadaCrítica (9.8)1.3%—Koa2-blog Project Koa2-blog1/2/202117/6/2026
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signup page.
ModificadaCrítica (9.8)1.3%—Koa2-blog Project Koa2-blog1/2/202117/6/2026
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signin page.
Orbitaley — Vulnerabilidades