Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

175 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.56%—CodeigniterAICi4-cms-erp Ci4msAI7/5/202617/6/2026
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In version 0.31.4.0, an attacker can achieve Full Account Takeover & Privilege Escalation via Stored DOM XSS in backup module filename field manipulated via a sql file that…
AplazadaMedia (5.1)0.29%—Igniterealtime OpenfireAIOpenfire Nodejs PluginAI26/1/202617/6/2026
Openfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject malicious scripts through the 'path' parameter. Attackers can craft a payload with script tags to execute arbitrary JavaScript in the context of administrative users viewing the nodejs configuration…
AplazadaAlta (8.7)0.51%—WebigniterAI15/12/202517/6/2026
WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the application server.
AplazadaMedia (5.3)0.41%—WebigniterAI4/12/202517/6/2026
WEBIGniter 28.7.23 contains a cross-site scripting vulnerability in the user creation process that allows unauthenticated attackers to execute malicious JavaScript code, enabling potential XSS attacks.
AplazadaMedia (6.4)0.23%—Cssigniter ShortcodesAI3/12/202517/6/2026
The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode attribute in all versions up to, and including, 2.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…
AnalizadaAlta (8.8)0.60%—Tastyigniter20/10/202517/6/2026
Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized…
AnalizadaCrítica (9.8)1.5%—Codeigniter28/7/202517/6/2026
CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the ImageMagick handler for image processing (`imagick` as the image library) and either allow file uploads with user-controlled filenames and process uploaded images using…
AplazadaMedia (6.1)0.33%—Codeigniter4AI25/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in CodeIgniter4 v4.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the debugbar_time parameter. NOTE: this is disputed by the Supplier because attackers cannot influence the value of debugbar_time, and because…
AnalizadaMedia (6.5)0.29%—Tastyigniter18/3/202517/6/2026
TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the index_onUpdateStatus() function within Orders.php, which fails to verify if the user has permission to modify an order's status. This flaw…
AnalizadaAlta (8.1)0.72%💥 PoCTastyigniter18/3/202517/6/2026
TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices due to missing permission checks.
AnalizadaCrítica (9.5)3.1%—Apache Ignite14/2/202517/6/2026
In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose class is present in the Ignite server classpath and sends it…
AnalizadaMedia (5.3)0.50%—Codeigniter20/1/202517/6/2026
CodeIgniter is a PHP full-stack web framework. Prior to 4.5.8, CodeIgniter lacked proper header validation for its name and value. The potential attacker can construct deliberately malformed headers with Header class. This could disrupt application functionality, potentially causing errors or generating invalid HTTP…
AplazadaAlta (7.5)0.48%—THE Cssigniter Team MaxsliderAI16/10/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxSlider maxslider allows Path Traversal.This issue affects MaxSlider: from n/a through <= 1.2.3.
AnalizadaAlta (7.5)0.23%—Codeigniter15/10/202417/6/2026
A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.
AplazadaCrítica (9.8)36%💥 ExploitAsis Aplikasi Sistem SekolahAICodeigniterAI2/9/202417/6/2026
ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass.
ModificadaMedia (5.3)0.52%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap5/7/202417/6/2026
A vulnerability classified as problematic has been found in CodeIgniter Ecommerce-CodeIgniter-Bootstrap up to 1998845073cf433bc6c250b0354461fbd84d0e03. This affects an unknown part. The manipulation of the argument search_title/catName/sub/name/categorie leads to cross site scripting. It is possible to initiate the…
ModificadaCrítica (9.8)1.7%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202424/8/2026
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.
AnalizadaCrítica (9.8)1.9%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202417/6/2026
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component.
AnalizadaAlta (8)1.1%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202417/6/2026
SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Orders_model.php component.
AnalizadaCrítica (9.8)1.9%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202417/6/2026
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component.
AplazadaMedia (6.5)0.31%—THE Cssigniter Team Elements PlusAI17/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The CSSIgniter Team Elements Plus! allows Stored XSS.This issue affects Elements Plus!: from n/a through 2.16.3.
AnalizadaAlta (7.5)0.77%—Codeigniter29/3/202417/6/2026
CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server. Upgrade to v4.4.7 or later.
AnalizadaCrítica (9.8)1.7%—Igniterealtime Openfire26/3/202417/6/2026
An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.
ModificadaAlta (7.2)1.4%—Igniterealtime Openfire26/3/202417/6/2026
An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.
ModificadaMedia (6.5)0.63%—Codeigniter Shield24/11/202317/6/2026
CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded with the raw tokens stored in the log table. If a malicious person somehow views the data in the log table they can obtain a raw token which can then be used to send a…
Orbitaley — Vulnerabilidades