Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.86% | — | Getgrav GravAI | 4/9/2026 | 8/9/2026 | Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name inside the sandbox; the remaining… | |
| Aplazada | Alta (7.1) | 0.63% | — | Getgrav GravAI | 4/9/2026 | 14/9/2026 | Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply directory traversal sequences in the lang POST field to write arbitrary .md files… | |
| Aplazada | Crítica (9.3) | 0.36% | — | Getgrav Grav-plugin-formAI | 4/9/2026 | 8/9/2026 | The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, an anonymous attacker can place their v3 token under the v2 field name… | |
| Aplazada | Media (5.1) | 0.28% | — | Getgrav GravAI | 4/9/2026 | 10/9/2026 | Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal components. Attackers can inject javascript: URI schemes in plugin or theme changelogs to execute arbitrary code in authenticated admin sessions… | |
| Aplazada | Media (5.1) | 0.24% | — | Getgrav Grav-plugin-admin2AI | 4/9/2026 | 8/9/2026 | Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into translation templates before parsing the result as markdown. Grav's server-side username… | |
| Aplazada | Media (5.1) | 0.26% | — | Getgrav Grav Shortcode CoreAI | 4/9/2026 | 8/9/2026 | Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that executes in the browsers of all page… | |
| Aplazada | Media (5.1) | 0.26% | — | Getgrav GravAI | 4/9/2026 | 14/9/2026 | Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious Twig code that executes in visitor browsers when the parent page is rendered,… | |
| Aplazada | Alta (8.1) | 0.50% | — | Gravityforms Gravity FormsAI | 1/9/2026 | 1/9/2026 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public form state URL hashes can be reused as chunk continuation hashes and… | |
| Aplazada | Crítica (9.3) | 0.24% | — | Getgrav Grav-plugin-apiAI | 26/8/2026 | 3/9/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTab() function of BlueprintController when deciding whether a page's security/permissions blueprint section is editable. Because the function performs raw isSuperAdmin()/hasPermission() checks without… | |
| Aplazada | Crítica (9.3) | 0.51% | — | Getgrav Grav-plugin-apiAI | 26/8/2026 | 3/9/2026 | The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rather than verifying whether the specific API key carries super authority… | |
| Aplazada | Alta (8.7) | 0.41% | — | Getgrav GravAI | 25/8/2026 | 31/8/2026 | Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig templates to retrieve sensitive values like system.cache.redis.password when… | |
| Aplazada | Alta (8.7) | 0.47% | — | Getgrav GravAI | 25/8/2026 | 31/8/2026 | Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User objects to extract hashed passwords and 2FA secrets, enabling offline password… | |
| Aplazada | Alta (8.7) | 0.66% | — | Getgrav Grav-plugin-emailAI | 25/8/2026 | 31/8/2026 | The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in header.form.process.email.body, publish the page, and… | |
| Aplazada | Crítica (9.3) | 0.15% | — | Getgrav Grav CMSAI | 25/8/2026 | 31/8/2026 | Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing delimiter. An attacker who controls a domain that begins with the victim… | |
| Aplazada | Media (6.3) | 0.28% | — | Getgrav Grav CMSAI | 25/8/2026 | 31/8/2026 | Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing differences to recover valid nonce values byte-by-byte through multiple requests,… | |
| Aplazada | Alta (8.7) | 0.43% | — | Getgrav Grav-plugin-loginAIGetgrav GravAI | 25/8/2026 | 16/9/2026 | The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() in classes/Controller.php (taskReset()) and login.php (activation handler). Because the token-submission endpoint… | |
| Aplazada | Crítica (9.3) | 0.34% | — | Getgrav Grav-plugin-loginAI | 25/8/2026 | 31/8/2026 | The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register() method in classes/Login.php throws a distinct exception (EMAIL_NOT_AVAILABLE) when a submitted email address already belongs to an existing account, while allowing registration to proceed… | |
| Aplazada | Alta (7.1) | 0.41% | — | Getgrav GravAI | 25/8/2026 | 31/8/2026 | Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can access raw configuration arrays including secrets like cache credentials by using dot notation in… | |
| Aplazada | Alta (7.1) | 0.46% | — | Getgrav GravAI | 25/8/2026 | 31/8/2026 | Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate and access files outside intended scope. Attackers with page authoring privileges can supply arbitrary filesystem paths to… | |
| Aplazada | Alta (8.6) | 0.20% | — | Getgrav GravAI | 25/8/2026 | 31/8/2026 | Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in the world-writable temp directory. Attackers can place a symlink at the predictable lock path pointing… | |
| Aplazada | Alta (7.1) | 0.90% | — | Getgrav GravAI | 25/8/2026 | 31/8/2026 | Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames with directory traversal sequences. The method validates only the basename portion of the filename while… | |
| Aplazada | Crítica (9.3) | 0.51% | — | Getgrav GravAIGetgrav LoginAI | 25/8/2026 | 31/8/2026 | Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without… | |
| Aplazada | Alta (8.7) | 0.43% | — | Getgrav GravAI | 25/8/2026 | 31/8/2026 | Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which… | |
| Aplazada | Media (6.9) | 0.28% | — | Grav API PluginAI | 25/8/2026 | 31/8/2026 | Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attackers to bypass hostname validation by DNS rebinding. Attackers controlling authoritative DNS for a configured webhook hostname can answer validation lookups with public addresses and delivery lookups… | |
| Aplazada | Alta (8.3) | 0.38% | — | Grav Flex ObjectsAI | 25/8/2026 | 31/8/2026 | Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in published pages to expose sensitive… |