Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2914▼ 57 respecto a la semana anterior
Críticas / altas1416▲ 118 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.78% | — | Bookstackapp Bookstack | 7/5/2020 | 17/6/2026 | In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A user with permission to create comments could POST HTML directly to the system to be saved in a comment, which would then be executed/displayed to others users viewing the comment. Through this… | |
| Modificada | Alta (8.8) | 2.0% | — | Bookstackapp Bookstack | 9/3/2020 | 17/6/2026 | BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to execute code on the host system remotely. They would then have the permissions of the PHP process. This most impacts scenarios where non-trusted users are given permission… | |
| Modificada | Media (5.4) | 0.76% | — | Bookstackapp Bookstack | 3/1/2018 | 17/6/2026 | BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code. |