Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.3)0.22%—Codelyfe Stupid Simple CMS1/3/202417/6/2026
Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php
AnalizadaMedia (6.1)0.43%—Codelyfe Stupid Simple CMS1/3/202417/6/2026
Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings.
ModificadaAlta (8.8)0.30%—Codelyfe Stupid Simple CMS17/1/202417/6/2026
Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.
ModificadaMedia (6.1)0.38%—Codelyfe Stupid Simple CMS17/1/202417/6/2026
Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content.
ModificadaMedia (5.4)0.91%—Codelyfe Stupid Simple CMS21/12/202317/6/2026
A vulnerability, which was classified as critical, has been found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this issue is some unknown functionality of the file /file-manager/rename.php. The manipulation of the argument newName leads to path traversal: '../filedir'. The attack may be launched remotely.…
ModificadaMedia (6.5)0.76%—Codelyfe Stupid Simple CMS21/12/202317/6/2026
A vulnerability classified as problematic was found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this vulnerability is an unknown functionality of the file /file-manager/rename.php. The manipulation of the argument oldName leads to path traversal: '../filedir'. The attack can be launched remotely. The…
ModificadaCrítica (9.1)1.2%—Codelyfe Stupid Simple CMS18/12/202317/6/2026
A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /file-manager/delete.php of the component Deletion Interface. The manipulation of the argument file leads to improper authentication. The exploit…
ModificadaCrítica (9.8)0.97%—Codelyfe Stupid Simple CMS17/12/202317/6/2026
A vulnerability has been found in codelyfe Stupid Simple CMS up to 1.2.4 and classified as critical. This vulnerability affects unknown code of the file /file-manager/upload.php. The manipulation of the argument file leads to unrestricted upload. The exploit has been disclosed to the public and may be used. The…
ModificadaCrítica (9.8)2.9%—Codelyfe Stupid Simple CMS17/12/202317/6/2026
A vulnerability, which was classified as critical, was found in codelyfe Stupid Simple CMS up to 1.2.3. This affects an unknown part of the file /terminal/handle-command.php of the component HTTP POST Request Handler. The manipulation of the argument command with the input whoami leads to os command injection. It is…
ModificadaCrítica (9.8)11%—Get-simple Getsimple CMS18/10/202217/6/2026
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php.
ModificadaMedia (5.4)0.66%—Get-simple Getsimple CMS27/4/202217/6/2026
A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the file /admin/edit.php of the Content Module. The manipulation of the argument post-content with an input like <script>alert(1)</script> leads to cross site scripting. The attack may be launched remotely…
ModificadaMedia (5.4)0.88%—Get-simple Getsimple CMS1/10/202017/6/2026
GetSimple CMS 3.3.16 allows in parameter 'permalink' on the Settings page persistent Cross Site Scripting which is executed when you create and open a new page
ModificadaMedia (6.1)10%—Get-simple Getsimple CMS1/9/202017/6/2026
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers to execute JavaScript code in the client's browser and harvest login credentials after a client clicks a link, enters credentials, and submits the login form.
ModificadaMedia (6.1)1.1%—Get-simple Getsimple CMS2/1/202016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to backup-edit.php; (2) title or (3) menu parameter to edit.php; or (4) path or (5) returnid parameter to filebrowser.php in admin/. NOTE: the path…
ModificadaMedia (5.4)0.67%—Get-simple Getsimple CMS15/9/201917/6/2026
GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.
ModificadaCrítica (9.8)72%—Get-simple Getsimple CMS22/5/201917/6/2026
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of files with arbitrary content (PHP code, for example). This vulnerability is triggered by an authenticated user; however, authentication can be bypassed. According to the official…
ModificadaMedia (5.4)0.57%—Get-simple Getsimple CMS31/12/201817/6/2026
There is Stored XSS in GetSimple CMS 3.3.12 via the admin/edit.php "post-menu" parameter, a related issue to CVE-2018-16325.
ModificadaBaja (3.8)0.78%—Get-simple Getsimple CMS21/11/201817/6/2026
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML elements in a .eml file, because of admin/upload-uploadify.php, and validate_safe_file in admin/inc/security_functions.php.
ModificadaBaja (3.8)0.78%—Get-simple Getsimple CMS21/11/201817/6/2026
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename), because of admin/upload-uploadify.php, and validate_safe_file in…
ModificadaMedia (4.8)0.67%—Get-simple Getsimple CMS1/10/201817/6/2026
An issue was discovered in GetSimple CMS 3.3.15. An administrator can insert stored XSS via the admin/settings.php Custom Permalink Structure parameter, which injects the XSS payload into any page created at the admin/pages.php URI.
ModificadaAlta (8.8)0.65%—Get-simple Getsimple CMS16/9/201817/6/2026
An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. NOTE: The vendor reported that the PoC was sending a value for the nonce parameter
ModificadaMedia (6.1)0.80%—Get-simple Getsimple CMS1/9/201817/6/2026
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.
ModificadaMedia (4.8)0.62%—Get-simple Getsimple CMS25/8/201817/6/2026
GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field.
ModificadaAlta (8.8)0.57%—Simple-cms Project Simple CMS20/8/201817/6/2026
An issue was discovered in daveismyname simple-cms through 2014-03-11. admin/addpage.php does not require authentication for adding a page. This can also be exploited via CSRF.
ModificadaAlta (8.8)0.46%—Simple-cms Project Simple CMS20/8/201817/6/2026
An issue was discovered in daveismyname simple-cms through 2014-03-11. There is a CSRF vulnerability that can delete any page via admin/?delpage=8.