Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 2.6% | — | Wondercms | 27/2/2018 | 17/6/2026 | In index.php in WonderCMS before 2.4.1, remote attackers can delete arbitrary files via directory traversal. | |
| Modificada | Media (4.4) | 0.58% | — | Wondercms | 9/2/2018 | 17/6/2026 | WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction(), 'svg' => 'image/svg+xml' that can result in An attacker can execute arbitrary script on an unsuspecting user's browser. This attack appear to be exploitable via Crafted SVG File. | |
| Modificada | Alta (7.5) | 8.0% | 💥 Exploit | Wondercms | 26/1/2018 | 17/6/2026 | WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack | |
| Modificada | Media (6.1) | 1.2% | — | Wondercms | 26/1/2018 | 17/6/2026 | In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOTE: the vendor disputes this issue stating that this is a feature that enables only a logged in administrator to write execute JavaScript anywhere on their website | |
| Modificada | Alta (8.8) | 7.3% | 💥 Exploit | Wondercms | 26/1/2018 | 17/6/2026 | In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload. | |
| Modificada | Alta (8.8) | 0.56% | — | Wondercms | 21/4/2017 | 17/6/2026 | WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context. | |
| Modificada | Crítica (9.8) | 1.5% | — | Wondercms | 17/3/2017 | 17/6/2026 | PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the hook parameter. | |
| Modificada | Crítica (9.8) | 2.0% | — | Wondercms | 17/3/2017 | 17/6/2026 | Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted theme. | |
| Modificada | Media (6.1) | 0.78% | — | Wondercms | 17/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Media (5.3) | 1.4% | — | Wondercms | 17/3/2017 | 17/6/2026 | Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, which reveals the installation path in an error message. | |
| Modificada | Alta (7.5) | 1.5% | — | Wondercms | 17/3/2017 | 17/6/2026 | Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed password. | |
| Modificada | Media (4.3) | 0.94% | — | Wondercms | 1/1/2015 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in editText.php in WonderCMS before 0.4 allows remote attackers to inject arbitrary web script or HTML via the content parameter. |