Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)298▼ 212 respecto a la semana anterior
329 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.69% | — | 1234n Minicms | 5/1/2026 | 7/10/2026 | A flaw has been found in bg5sbk MiniCMS up to 1.8. Impacted is the function delete_page of the file /minicms/mc-admin/page.php of the component File Recovery Request Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be… | |
| Analizada | Media (5.3) | 0.22% | — | Zwiicms | 31/12/2025 | 23/9/2026 | ZwiiCMS versions prior to 13.7.00 contain a denial-of-service vulnerability in multiple administrative endpoints due to improper authorization checks combined with flawed resource state management. When an authenticated low-privilege user requests an administrative page, the application returns "404 Not Found" as… | |
| Analizada | Baja (2) | 0.48% | — | Idreamsoft Icms | 31/12/2025 | 23/9/2026 | A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php of the component POST Parameter Handler. The manipulation of the argument config results in code injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor… | |
| Analizada | Baja (2.1) | 0.44% | — | Kodicms-kohana Kodicms | 31/12/2025 | 23/9/2026 | A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file cms/modules/kodicms/classes/kodicms/model/file.php of the component Layout API Endpoint. The manipulation of the argument content leads to code injection. The attack can be initiated remotely. The… | |
| Analizada | Baja (2.1) | 0.29% | — | Kodicms-kohana Kodicms | 31/12/2025 | 23/9/2026 | A weakness has been identified in Kohana KodiCMS up to 13.82.135. This affects the function like of the file cms/modules/pages/classes/kodicms/model/page.php of the component Search API Endpoint. Executing manipulation of the argument keyword can lead to sql injection. It is possible to launch the attack remotely. The… | |
| Analizada | Media (5.5) | 0.40% | — | Feehicms | 30/12/2025 | 17/6/2026 | A vulnerability was determined in FeehiCMS up to 2.1.1. Impacted is an unknown function of the file frontend/web/timthumb.php of the component TimThumb. Executing manipulation of the argument src can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and… | |
| Modificada | Baja (2.1) | 0.37% | — | Xunruicms | 28/12/2025 | 17/6/2026 | A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. The impacted element is the function dr_show_error/dr_exit_msg of the file /dayrui/Fcms/Init.php of the component JSONP Callback Handler. This manipulation of the argument callback causes cross site scripting. The attack can be initiated remotely. The… | |
| Modificada | Media (5.1) | 0.37% | — | Ulicms | 17/12/2025 | 17/6/2026 | UliCMS 2023.1 contains a stored cross-site scripting vulnerability that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the file management interface that execute arbitrary scripts when viewed by other users. | |
| Analizada | Alta (8.7) | 0.94% | — | Ulicms | 17/12/2025 | 17/6/2026 | UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar upload. Attackers can trigger code execution by visiting the uploaded file's location, enabling system command execution through maliciously… | |
| Modificada | Crítica (9.3) | 0.55% | — | Ulicms | 17/12/2025 | 17/6/2026 | UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific parameters to generate a new admin user with full system access. | |
| Analizada | Crítica (9.3) | 0.69% | — | Ulicms | 17/12/2025 | 17/6/2026 | UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with specific parameters to generate an administrative account with full… | |
| Analizada | Alta (8.6) | 1.1% | — | Popojicms | 10/12/2025 | 26/9/2026 | PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to create a web shell that executes arbitrary system commands through a GET parameter. | |
| Analizada | Baja (1.9) | 0.28% | — | Jizhicms | 4/12/2025 | 17/6/2026 | A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.php/admins/Comment/addcomment.html of the component Comment Handler. The manipulation of the argument body leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly… | |
| Modificada | Baja (2) | 0.38% | — | Jizhicms | 4/12/2025 | 17/6/2026 | A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of the file /index.php/admins/Comment/deleteAll.html of the component Batch Delete Comments. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has… | |
| Modificada | Baja (2) | 0.38% | — | Jizhicms | 4/12/2025 | 17/6/2026 | A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Comment/addcomment.html of the component Add Display Name Field. Performing a manipulation of the argument aid/tid results in sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Baja (2) | 0.41% | — | Xunruicms | 4/12/2025 | 17/6/2026 | A flaw has been found in dayrui XunRuiCMS up to 4.7.1. This vulnerability affects unknown code of the file admin79f2ec220c7e.php?c=api&m=test_site_domain of the component Project Domain Change Test. This manipulation of the argument v causes server-side request forgery. It is possible to initiate the attack remotely.… | |
| Modificada | Baja (1.9) | 0.29% | — | Xunruicms | 4/12/2025 | 17/6/2026 | A weakness has been identified in dayrui XunRuiCMS up to 4.7.1. Affected by this vulnerability is an unknown functionality of the file /admind45f74adbd95.php?c=field&m=add&rname=site&rid=1&page=0 of the component Add Display Name Field. Executing a manipulation of the argument data[name] can lead to cross site… | |
| Modificada | Baja (2) | 0.43% | — | Xunruicms | 4/12/2025 | 17/6/2026 | A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind45f74adbd95.php?c=email&m=add of the component Email Setting Handler. Performing a manipulation results in server-side request forgery. Remote exploitation of the attack is possible. The exploit has… | |
| Analizada | Baja (1.1) | 0.27% | — | Xunruicms | 4/12/2025 | 25/9/2026 | A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7e.php?c=api&m=demo&name=mobile of the component Domain Name Binding Page. The manipulation results in cross site scripting. The attack may be performed from remote. A high complexity level is… | |
| Analizada | Baja (2) | 0.27% | — | Xunruicms | 4/12/2025 | 25/9/2026 | A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1. Affected by this issue is some unknown functionality of the file /admind45f74adbd95.php?c=field&m=add&rname=site&rid=1&page=1 of the component Add Data Validation Page. The manipulation of the argument data[name] leads to cross site scripting.… | |
| Analizada | Media (6.5) | 0.40% | — | Feehicms | 2/12/2025 | 17/6/2026 | FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files that the server later executes (or stores in an executable location) without sufficient validation, sanitization, or execution restrictions. An… | |
| Analizada | Media (6.5) | 0.26% | — | Feehicms | 1/12/2025 | 17/6/2026 | FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticated attacker can intercept and modify the parameter in transit and the backend accepts the changes. This can lead to unintended username changes. | |
| Analizada | Media (4.6) | 0.20% | — | Feehicms | 1/12/2025 | 17/6/2026 | Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function | |
| Analizada | Media (6.1) | 0.24% | — | Feehicms | 1/12/2025 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate). | |
| Modificada | Alta (8.8) | 0.39% | — | Zwiicms | 5/11/2025 | 5/7/2026 | An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, authenticated attacker to escalate their privileges. By sending a specially crafted HTTP request, a low-privilege user can access and modify the profile data of any other user, including administrators. |