Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.20% | — | Yzmcms | 23/9/2025 | 5/7/2026 | Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page. | |
| Modificada | Crítica (9.8) | 0.88% | — | Sueamcms Project Sueamcms | 12/9/2025 | 5/7/2026 | File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering. | |
| Aplazada | Baja (2.1) | 0.35% | — | Uxblondon BoomcmsAI | 3/9/2025 | 17/6/2026 | Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits specific browser bugs to spy on users via JavaScript. This type of attack is based on social engineering and depends entirely on the browser chosen by the user, so it is perceived as a minor threat… | |
| Analizada | Media (6.1) | 0.21% | — | Formcms | 28/8/2025 | 25/9/2026 | FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload .html files containing malicious JavaScript, which are accessible via a public URL. When a privileged user accesses the file, the script executes in their browser context. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php. | |
| Modificada | Media (5.4) | 0.24% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php. | |
| Modificada | Crítica (9.8) | 0.78% | — | Mingsoft Mcms | 21/4/2025 | 5/7/2026 | An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Analizada | Media (5.3) | 0.54% | — | Yzmcms | 8/4/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file message.tpl. The manipulation of the argument gourl leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor… | |
| Analizada | Crítica (9.8) | 0.50% | — | Sem-cms Semcms | 27/3/2025 | 17/6/2026 | semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php. | |
| Analizada | Media (5.3) | 0.51% | — | Sem-cms Semcms | 8/1/2025 | 17/6/2026 | A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file SEMCMS_Images.php of the component Image Library Management Page. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Baja (3.8) | 0.29% | — | Sem-cms Semcms | 3/12/2024 | 17/6/2026 | Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page. | |
| Modificada | Media (4.9) | 0.55% | — | Sem-cms Semcms | 20/11/2024 | 5/7/2026 | SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component. | |
| Analizada | Crítica (9.8) | 0.51% | — | Sem-cms Semcms | 20/9/2024 | 17/6/2026 | SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php. | |
| Analizada | Alta (8.1) | 0.81% | — | Mingsoft Mcms | 3/9/2024 | 17/6/2026 | MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution. | |
| Aplazada | Alta (7.5) | 0.41% | — | WmcmsAI | 19/7/2024 | 17/6/2026 | An issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request. | |
| Analizada | Media (6.1) | 0.29% | — | Yzmcms | 5/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a published article. | |
| Analizada | Media (5.9) | 0.39% | — | Sem-cms Semcms | 4/6/2024 | 17/6/2026 | A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php. | |
| Analizada | Alta (7.5) | 0.70% | — | Sem-cms Semcms | 4/6/2024 | 17/6/2026 | A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php. |