Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
340 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 0.34% | — | Joomla! | 18/8/2026 | 3/9/2026 | Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI. | |
| Analizada | Media (6.4) | 0.46% | — | Joomla! | 7/7/2026 | 9/7/2026 | An improper access check allows unauthorized users to create custom fields via webservices endpoints. | |
| Analizada | Media (6.4) | 0.42% | — | Joomla! | 7/7/2026 | 9/7/2026 | An improper access check allows unauthorized users to access com_privacy datasets. | |
| Analizada | Media (6.4) | 0.27% | — | Joomla! | 7/7/2026 | 9/7/2026 | An improper access check allows users to display a list of modules in the frontend. | |
| Analizada | Media (6.4) | 0.34% | — | Joomla! | 7/7/2026 | 9/7/2026 | An improper access check allows unauthorized users to access workflow stage and transition information. | |
| En análisis | Media (5.9) | 0.24% | — | Joomla! | 7/7/2026 | 9/7/2026 | Improper validation leads to a generic XSS vector in the language override feature. | |
| Analizada | Media (5.9) | 0.24% | — | Joomla! | 7/7/2026 | 9/7/2026 | Lack of escaping leads to an XSS vulnerability in the generic image output layout. | |
| Analizada | Media (5.9) | 0.24% | — | Joomla! | 7/7/2026 | 9/7/2026 | Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. | |
| Analizada | Media (5.9) | 0.24% | — | Joomla! | 7/7/2026 | 9/7/2026 | Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. | |
| Analizada | Media (5.9) | 0.24% | — | Joomla! | 7/7/2026 | 9/7/2026 | Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. | |
| Analizada | Media (5.9) | 0.24% | — | Joomla! | 7/7/2026 | 9/7/2026 | Lack of validation leads to an XSS vulnerability in the MFA management views. | |
| Analizada | Media (6.4) | 0.42% | — | Joomla! | 7/7/2026 | 9/7/2026 | An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. | |
| Analizada | Media (6.4) | 0.33% | — | Joomla! | 7/7/2026 | 9/7/2026 | An improper access check allows privileged users to overwrite media files without editing permissions. | |
| Analizada | Media (6.9) | 0.24% | — | Joomla! | 26/5/2026 | 20/7/2026 | Lack of input filtering leads to an XSS vector in the HTML filter code. | |
| Analizada | Alta (8.2) | 0.53% | — | Joomla! | 26/5/2026 | 24/7/2026 | An improper access check allows privelege escalation through the com_users group editing webservice endpoint. | |
| Analizada | Media (6.9) | 0.24% | — | Joomla! | 26/5/2026 | 24/7/2026 | Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. | |
| Modificada | Crítica (9.8) | 0.33% | — | Joomla! | 26/5/2026 | 24/7/2026 | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. | |
| Analizada | Alta (7.5) | 0.42% | — | Joomla! | 26/5/2026 | 24/7/2026 | The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. | |
| Analizada | Media (6.4) | 0.26% | — | Joomla! | 26/5/2026 | 24/7/2026 | An improper access check allowed low privileged users to edit the task types of existing scheduler tasks. | |
| Analizada | Media (5.3) | 0.42% | — | Joomla! | 26/5/2026 | 24/7/2026 | An improper access check allows privilege escalation through the com_users batch task. | |
| Analizada | Alta (8.2) | 0.48% | — | Joomla! | 26/5/2026 | 24/7/2026 | An improper access check allows privilege escalation through the com_users batch task. | |
| Analizada | Alta (8.2) | 0.36% | — | Joomla! | 26/5/2026 | 24/7/2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | |
| Analizada | Alta (8.2) | 0.36% | — | Joomla! | 26/5/2026 | 24/7/2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | |
| Analizada | Media (5.9) | 0.49% | — | Joomla! | 26/5/2026 | 24/7/2026 | An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability. | |
| Analizada | Alta (7.5) | 0.56% | — | Joomla! | 26/5/2026 | 24/7/2026 | An improper validation of user-supplied input leads to a local file inclusion vulnerability. |