Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.53% | — | Wbce CMS | 21/11/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field. | |
| Modificada | Media (4.8) | 0.53% | — | Wbce CMS | 21/11/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field. | |
| Modificada | Alta (7.5) | 0.84% | — | Wbce CMS | 15/11/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper restriction of excessive… | |
| Modificada | Media (5.4) | 0.86% | — | Wbce CMS | 17/5/2022 | 17/6/2026 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters. | |
| Modificada | Media (5.4) | 1.6% | 💥 Exploit | Wbce CMS | 17/5/2022 | 17/6/2026 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php. | |
| Modificada | Media (6.1) | 0.98% | — | Wbce CMS | 28/4/2022 | 17/6/2026 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Alta (7.8) | 1.2% | — | Wbce CMS | 24/2/2022 | 17/6/2026 | A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (7.8) | 1.2% | — | Wbce CMS | 24/2/2022 | 17/6/2026 | A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Crítica (9.8) | 38% | 💥 Exploit | Wbce CMS | 9/12/2021 | 17/6/2026 | wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command | |
| Modificada | Alta (7.2) | 1.4% | — | Wbce CMS | 14/10/2019 | 17/6/2026 | A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an authenticated user with admin privileges to rename a media filename and extension. (For example: place PHP code in a .jpg file, and then change the file's base name to filename.ph and change the… | |
| Modificada | Media (4.8) | 0.63% | — | Wbce CMS | 25/1/2018 | 17/6/2026 | Cross-site scripting (XSS) in WBCE CMS 1.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the Modify Page screen, a different issue than CVE-2017-2118. | |
| Modificada | Media (4.8) | 0.61% | — | Wbce CMS | 17/11/2017 | 17/6/2026 | WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search | |
| Modificada | Alta (7.2) | 1.3% | — | Wbce CMS | 28/4/2017 | 17/6/2026 | SQL injection vulnerability in the WBCE CMS 1.1.10 and earlier allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (8.6) | 3.5% | — | Wbce CMS | 28/4/2017 | 17/6/2026 | Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.1) | 1.2% | — | Wbce CMS | 28/4/2017 | 17/6/2026 | Cross-site scripting vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |