Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
351 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.43% | — | Craft CMSAI | 2/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw in the bulk-duplicate element action. An attacker who is only able to duplicate their own entires can submit an arbitrary id through the newAttributes request parameter. The duplication routine… | |
| Aplazada | Alta (8.7) | 0.41% | 💥 PoC | Craftcms Craft CMSAI | 2/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with the ability to edit entries can execute unsandboxed Twig code via the HTTP Referrer header, potentially leading to authenticated RCE. The issue happens when a user is saving entries. Strings for a… | |
| Aplazada | Media (6) | 0.40% | — | Craftcms Craft CMSAI | 2/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 and above, prior to 5.10.0, the dataUrl() Twig function is included in Craft’s Twig sandbox allowlist, allowing any control panel user granted the utility:system-messages permission to embed a… | |
| Aplazada | Media (6.9) | 0.46% | — | Craftcms Craft CMSAI | 2/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forgery (SSRF) and Arbitrary JavaScript Injection through the /actions/app/resource-js endpoint. By exploiting the default permissive… | |
| Aplazada | Media (6) | 0.40% | — | Craftcms Craft CMSAI | 2/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::actionMoveToSection() endpoint gates the destination section only by viewEntries:$section->uid rather than requiring saveEntries permission (the source entry is separately checked via… | |
| Aplazada | Alta (7.6) | 0.36% | — | Craftcms Craft CMSAI | 2/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). IN versions 5.0.0-RC1 and above prior to 5.9.21, theEntriesController::actionSaveEntry() performs entry-edit permission checks before request-controlled author changes are applied to the model, allowing for authorship spoofing. The subsequent author mutation path accepts… | |
| Aplazada | Alta (7.4) | 0.46% | — | Craftcms CMSAI | 1/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15, an attacker with only a GitHub account can plant a JavaScript payload in a craftcms/cms issue title. When a Craft admin uses the CraftSupport widget’s "Give feedback" screen and types a search term that… | |
| Aplazada | Alta (7.1) | 0.39% | — | Craft CMSAI | 1/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 through 4.17.14, theAssetsController::actionDeleteFolder() only requires the deleteAssets:<volume-uid> permission for the target folder. It never enforces deletePeerAssets:<volume-uid>, even though… | |
| Aplazada | Media (5.3) | 0.36% | — | Craftcms Craft CMSAI | 1/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain an authorization issue in the AssetsController::actionReplaceFile that can delete a source asset without source delete permission by supplying both assetId and sourceAssetId.… | |
| Aplazada | Media (5.9) | 0.41% | — | Craftcms Craft CMSAI | 1/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22, an author-level control panel user can store a malicious JavaScript payload in an entry title. When an admin, or any control panel user with saveEntries for the same Structure section, drags another entry under the poisoned entry in… | |
| Aplazada | Alta (7.1) | 0.49% | — | Craftcms Craft CMSAI | 21/6/2026 | 23/6/2026 | Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowing local file read… | |
| Aplazada | Media (4.6) | 0.32% | — | Craftcms Craft CMSAI | 21/6/2026 | 22/6/2026 | Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rendered without sanitization (e.g., via the checkbox.twig template, which used {{ label|raw }}). An authenticated… | |
| Aplazada | Media (5.3) | 0.36% | — | Craftcms Craft CMSAI | 21/6/2026 | 22/6/2026 | Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization before returning preview content, allowing an authenticated low-privileged user to supply a controlled assetId for an… | |
| Aplazada | Media (5.3) | 0.33% | — | Craftcms Craft CMSAI | 21/6/2026 | 24/6/2026 | Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an attacker-controlled assetId and receive preview HTML containing a signed fallback transform preview link for that private… | |
| Aplazada | Media (4.6) | 0.31% | — | Craftcms Craft CMSAI | 21/6/2026 | 23/6/2026 | Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the 'Row Heading' column type. The application fails to sanitize input within row heading default values, allowing an attacker with an administrator account (with allowAdminChanges enabled) to inject… | |
| Aplazada | Alta (8.6) | 0.89% | — | Craftcms CMSAI | 21/6/2026 | 22/6/2026 | Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the fieldLayoutConfig POST parameter directly to Fields::createLayout() without calling Component::cleanseConfig(). An… | |
| Aplazada | Media (4.6) | 0.25% | — | Craftcms Craft CMSAI | 21/6/2026 | 23/6/2026 | Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where user group names are rendered without proper HTML escaping. Attackers with admin access can inject arbitrary JavaScript via the user group name field that executes when other users view or edit… | |
| Aplazada | Media (4.9) | 0.44% | — | OptincraftAI | 6/6/2026 | 23/7/2026 | The OptinCraft – Drag & Drop Optins & Popup Builder for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Alta (8.1) | 0.41% | — | Axiomthemes CraftiAI | 2/6/2026 | 22/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Crafti allows PHP Local File Inclusion. This issue affects Crafti: from n/a through 1.12. | |
| Aplazada | Crítica (9.8) | 0.81% | — | Verbb FormieAICraftcms Craft CMSAI | 29/5/2026 | 22/7/2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox… | |
| Aplazada | Alta (7.3) | 0.39% | 💥 PoC | Craft CMSAI | 27/5/2026 | 17/6/2026 | Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate). | |
| Aplazada | Alta (7.1) | 0.36% | — | Craftcms Craft CMSAI | 12/5/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filename and complete folder hierarchy (including volume handle, volume UID, folder names, folder UIDs, and folder URI paths) without checking whether the… | |
| Aplazada | Alta (8.6) | 0.44% | 💥 PoC | Craftcms Craft CMSAI | 12/5/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execute arbitrary commands on the server. The request-controlled condition field… | |
| Aplazada | Alta (7.1) | 0.36% | — | Craftcms Craft CMSAI | 12/5/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php) performs no schema scope filtering on top-level queries. A GraphQL API token scoped to a single low-privilege user group can read every address in the… | |
| Aplazada | Media (5.5) | 0.40% | — | Craftcms Craft CMSAI | 22/4/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. When `trustedHosts` is not explicitly restricted (default configuration), the… |