Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
351 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.35% | — | Craftcms Craft CMSAI | 2/9/2026 | 4/9/2026 | Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement. | |
| Aplazada | Media (4.8) | 0.25% | — | Craftcms Craft CMSAI | 2/9/2026 | 2/9/2026 | Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the site name that execute when other users view the control panel settings pages. | |
| Aplazada | Media (5.3) | 0.29% | — | Craftcms Craft CMSAI | 2/9/2026 | 2/9/2026 | Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by… | |
| Aplazada | Alta (8.7) | 0.45% | — | YIIAICraftcms Craft CMSAI | 27/8/2026 | 28/8/2026 | The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities. | |
| Aplazada | Media (5.3) | 0.40% | — | Minecraft Lost-auctionAI | 25/8/2026 | 9/9/2026 | MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8, players can take items like barrier blocks or duplicate items from the GUI. Commit 88c920b05042929db334ba06d57f052b42d6b3f8 fixes the issue. | |
| Aplazada | Alta (8.7) | 1.0% | — | Craftcms Craft CMSAI | 24/8/2026 | 28/8/2026 | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding,… | |
| Aplazada | Alta (8.2) | 0.45% | — | CraftplanAI | 21/8/2026 | 31/8/2026 | Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials by exploiting an unconditional authorization policy on the Settings resource. Attackers can send a GET request to the settings API endpoint with a valid record ID to retrieve… | |
| Aplazada | Crítica (9.8) | 1.3% | — | Verbb FormieAICraftcms Craft CMSAI | 19/8/2026 | 10/9/2026 | Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Value to Craft's Twig rendering layer during front-end form rendering. An… | |
| Aplazada | Media (5.1) | 0.26% | — | Craftcms Craft CMSAI | 12/8/2026 | 31/8/2026 | Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that executes in the browser of any… | |
| Aplazada | Alta (7.1) | 0.46% | — | Craftcms Craft CMSAI | 12/8/2026 | 31/8/2026 | Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password including administrators by exploiting the unprotected newPassword… | |
| Aplazada | Crítica (9.3) | 0.27% | — | Craftcms Craft CMSAI | 11/8/2026 | 28/8/2026 | Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify that group's category structure — reordering and re-parenting categories — via the… | |
| Aplazada | Media (6.9) | 0.24% | — | Craftcms Craft CMSAI | 11/8/2026 | 8/9/2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<Volume>Asset mutation, which fetches an attacker-supplied URL server-side. The anti-SSRF validation is incomplete: validateIp() does not cover CGNAT (100.64.0.0/10) or… | |
| Aplazada | Media (6.9) | 0.20% | — | Craftcms Craft CMSAI | 11/8/2026 | 26/8/2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContained function of the Local file system class. The order of operations validates the path before normalization, so normalization could invalidate prior validation… | |
| Aplazada | Alta (7.1) | 0.39% | — | Craftcms Craft CMSAI | 11/8/2026 | 28/8/2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in the elementId parameter) into Twig templates before rendering, even when the Twig sandbox is enabled. An authenticated attacker with control panel access can render a… | |
| Aplazada | Alta (8.7) | 0.79% | — | Craftcms Craft CMSAI | 11/8/2026 | 8/9/2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft marks the ElementInterface as safe (via the AllowedInSandbox attribute) and the sandbox allowlisting extends to the entire class hierarchy… | |
| Aplazada | Alta (7.1) | 0.39% | — | Craftcms Craft CMSAI | 11/8/2026 | 28/8/2026 | Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create additional authenticated sessions for victim accounts. | |
| Aplazada | Alta (8.7) | 0.38% | — | Craftcms Craft CMSAI | 11/8/2026 | 8/9/2026 | Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entry blocklist that does not include SplFileObject, allowing an authenticated administrator (with allowAdminChanges=true) to configure a… | |
| Aplazada | Alta (8.7) | 0.80% | — | Craftcms Craft CMSAI | 11/8/2026 | 26/8/2026 | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses the outer request-controlled condition array via Component::cleanseConfig(), but… | |
| Analizada | Crítica (9.1) | 0.80% | — | Craftycontrol Crafty Controller | 11/8/2026 | 18/8/2026 | Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution. | |
| Aplazada | Alta (7.2) | 0.58% | — | FormcraftAI | 27/7/2026 | 28/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions. | |
| Aplazada | Alta (7.2) | 0.34% | — | FormcraftAI | 23/7/2026 | 23/7/2026 | The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Analizada | Crítica (9.8) | 0.97% | — | Microsoft Minecraft Bedrock Dedicated Server | 14/7/2026 | 22/7/2026 | Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (5.3) | 0.39% | — | Craftcms Craft CMSAI | 6/7/2026 | 6/7/2026 | A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData of the file src/controllers/ChartsController.php of the component Charts Endpoint. This manipulation of the argument userGroupId causes improper authorization. The attack is possible to be carried… | |
| Aplazada | Media (5.3) | 0.39% | — | Craftcms Craft CMSAI | 6/7/2026 | 6/7/2026 | A vulnerability was detected in Craft CMS up to 4.18.0.1. Affected is the function actionReorderSets of the file src/controllers/GlobalsController.php of the component reorder-sets Endpoint. The manipulation results in authorization bypass. The attack can be executed remotely. Upgrading to version 4.18.1 is able to… | |
| Aplazada | Media (4.9) | 0.35% | — | Craftcms Craft CMSAI | 2/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a conflicting destination folder without destination delete permission. Function… |