Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1468 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.3)0.28%—YeswikiAI2/10/20266/10/2026
YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via the Bazar entry-creation flow. Attackers can submit a crafted entry with an attacker-controlled id_fiche matching an existing…
AplazadaAlta (7.2)0.16%—YeswikiAI2/10/20262/10/2026
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET request carrying a jsonp_callback parameter without checking a CSRF token. Attackers can lure a logged-in administrator or page owner to a crafted link to delete arbitrary…
AplazadaAlta (7.1)0.13%—YeswikiAI2/10/20262/10/2026
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete installed packages via unprotected GET requests. Attackers can lure a logged-in administrator to a crafted link with action=delete and a package parameter to remove extensions like…
AplazadaMedia (6.9)0.43%—YeswikiAI2/10/20262/10/2026
YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through the wiki's SMTP server. Attackers can POST an XMLHttpRequest to the mail handler without field or type parameters, supplying arbitrary recipient, sender, subject and body…
AplazadaAlta (8.8)0.40%—YeswikiAI2/10/20266/10/2026
YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to…
AplazadaAlta (7.1)0.27%—YeswikiAI2/10/20262/10/2026
YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a…
AplazadaAlta (7.2)0.36%—YeswikiAI2/10/20262/10/2026
YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the…
AplazadaMedia (6.9)0.32%—YeswikiAI2/10/20262/10/2026
YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs by supplying a syndication action through the render handler's content parameter. Attackers can target internal hosts and ports, read back fetched feed content…
AplazadaMedia (6.9)0.29%—YeswikiAI2/10/20266/10/2026
YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary hosts and ports via the {{valeur}} action's url parameter. Attackers can submit the action through the content parameter of handlers/page/render.php to probe…
AplazadaMedia (6.9)0.29%—YeswikiAI2/10/20262/10/2026
YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side requests via the idtypeannonce parameter of /api/entries/bazarlist. Because isValidURL() always returns true, attackers can supply internal URLs fetched by curl in…
AplazadaAlta (7.1)0.34%—YeswikiAI2/10/20262/10/2026
YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePassePerdu recovery page without rate limiting to identify valid accounts for…
AplazadaAlta (8.7)0.30%—YeswikiAI2/10/20262/10/2026
YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. Unauthenticated or unprivileged attackers can embed these actions with a chosen tag or page name to disclose the names and…
AplazadaAlta (8.7)0.43%—Deepwiki-openAI30/9/20262/10/2026
DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL repo_url value to bypass path containment checks and read any file accessible to the API process by specifying absolute file…
Pendiente de análisisBaja (1.2)0.30%—Wikimedia MediasearchAI30/9/20261/10/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki MediaSearch extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki MediaSearch extension: 1.46, 1.45, and 1.43.
Pendiente de análisisBaja (1.1)0.29%—Wikimedia CommonsmetadataAI30/9/20261/10/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43.
Pendiente de análisisAlta (7.4)0.33%—Wikimedia WikilambdaAI30/9/20266/10/2026
Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extension: 1.46.
Pendiente de análisisBaja (1.2)0.30%—Wikimedia Page FormsAI30/9/202630/9/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Page_Forms extension allows Stored XSS. This issue affects MediaWiki Page_Forms extension: 1.46, 1.45, and 1.43.
Pendiente de análisisBaja (1.2)0.27%—Wikimedia PagetriageAI30/9/202630/9/2026
Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43.
Pendiente de análisisBaja (0.3)0.11%—Wikimedia WikbaseAI30/9/202630/9/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikbase extension: 1.46, 1.45, and 1.43.
Pendiente de análisisBaja (0.3)0.11%—Wikimedia WikistoriesAI30/9/202630/9/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikistories extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikistories extension: 1.46, 1.45, and 1.43.
Pendiente de análisisBaja (1.1)0.30%—Wikimedia Reading ListsAI30/9/202630/9/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki ReadingLists extension allows Reflected XSS. This issue affects MediaWiki ReadingLists extension: 1.46 and 1.45.
Pendiente de análisisBaja (1.1)0.34%—Wikimedia WikiforumAI30/9/202630/9/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS. This issue affects MediaWiki WikiForum extension: master.
Pendiente de análisisBaja (1.1)0.20%—Wikimedia Mediawiki CollectionAI30/9/202630/9/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Collection (Book) extension allows XSS Targeting Non-Script Elements. This issue affects MediaWiki Collection (Book) extension: 1.46, 1.45, and 1.43.
Pendiente de análisisAlta (7.2)0.28%—Wikimedia CentralauthAI30/9/202630/9/2026
External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection. This issue affects MediaWiki CentralAuth extension: 1.46, 1.45, and 1.43.
Pendiente de análisisAlta (7.2)0.28%—Wikimedia WikibaseAI30/9/202630/9/2026
Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files. This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43.