Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.53% | — | Pbootcms | 12/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php. | |
| Modificada | Media (6.5) | 0.80% | — | Pbootcms | 9/7/2021 | 17/6/2026 | Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php. | |
| Modificada | Crítica (9.8) | 2.5% | — | Pbootcms | 8/7/2021 | 17/6/2026 | Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board. | |
| Modificada | Media (4.8) | 0.57% | — | Pbootcms | 8/7/2021 | 9/7/2026 | Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php. | |
| Modificada | Media (4.8) | 0.48% | — | Pbootcms | 3/6/2021 | 17/6/2026 | Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Pbootcms | 31/3/2021 | 17/6/2026 | PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account. | |
| Modificada | Media (6.5) | 0.44% | — | Pbootcms | 30/11/2020 | 17/6/2026 | Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user. | |
| Modificada | Crítica (9.8) | 1.8% | — | Pbootcms | 2/3/2020 | 17/6/2026 | An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter. | |
| Modificada | Crítica (9.8) | 1.8% | — | Pbootcms | 2/3/2020 | 17/6/2026 | An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter. | |
| Modificada | Media (4.8) | 0.65% | — | Pbootcms | 10/10/2019 | 17/6/2026 | PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs. | |
| Modificada | Alta (7.2) | 1.3% | — | Pbootcms | 17/2/2019 | 17/6/2026 | A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php. | |
| Modificada | Media (6.5) | 0.54% | — | Pbootcms | 7/2/2019 | 17/6/2026 | A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI. | |
| Modificada | Crítica (9.8) | 1.1% | — | Pbootcms | 6/12/2018 | 17/6/2026 | SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string. | |
| Modificada | Crítica (9.8) | 3.9% | — | Pbootcms | 27/11/2018 | 17/6/2026 | PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/list/5/?current={pboot:if(evAl($_GET[a]))}1{/pboot:if}&a=phpinfo(); URI, because of an incorrect apps\home\controller\ParserController.php parserIfLabel protection… | |
| Modificada | Alta (7.2) | 1.4% | — | Pbootcms | 7/11/2018 | 17/6/2026 | PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, followed by a SELECT statement containing this PHP code. | |
| Modificada | Crítica (9.8) | 1.5% | — | Pbootcms | 17/10/2018 | 17/6/2026 | apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/1/id/3 URI. | |
| Modificada | Alta (8.1) | 0.88% | — | Pbootcms | 10/10/2018 | 17/6/2026 | PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI. | |
| Modificada | Crítica (9.8) | 1.1% | — | Pbootcms | 22/5/2018 | 17/6/2026 | An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter. | |
| Modificada | Alta (8.8) | 0.60% | — | Pbootcms | 13/5/2018 | 17/6/2026 | An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php allows remote attackers to add administrator accounts via admin.php/role/add.html. | |
| Modificada | Crítica (9.8) | 1.4% | — | Pbootcms | 16/4/2018 | 17/6/2026 | PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel function in \apps\home\controller\ParserController.php. | |
| Modificada | Alta (8.8) | 0.51% | — | Pbootcms | 16/4/2018 | 17/6/2026 | PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontent parameter. |