Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
824 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.25% | — | Concretecms Concrete CMS | 11/9/2026 | 18/9/2026 | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user with edit_page_contents permissions could store a payload which executes in the browser of any visitor who viewed a page where the block was configured to display a date-type attribute. The… | |
| Analizada | Media (5.1) | 0.24% | — | Concretecms Concrete CMS | 11/9/2026 | 18/9/2026 | Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Document Library block, so a user with permission to edit file properties could store a script payload that executed in the browser of any visitor to a page displaying the block with the description… | |
| Analizada | Media (6.1) | 0.14% | — | Concretecms Concrete CMS | 11/9/2026 | 24/9/2026 | Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforce a failed CSRF token check, allowing the destructive operation to proceed when… | |
| Analizada | Media (5.1) | 0.21% | — | Concretecms Concrete CMS | 11/9/2026 | 24/9/2026 | Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as hero_image and gallery, is where the referenced file is authorized against the user's file-manager visibility. As a result,… | |
| Analizada | Media (5.1) | 0.27% | — | Concretecms Concrete CMS | 11/9/2026 | 18/9/2026 | Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route. As a result, a user permitted to add entries to one Express object could create entries in a different Express object outside their… | |
| Analizada | Media (5.1) | 0.29% | — | Concretecms Concrete CMS | 11/9/2026 | 24/9/2026 | Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::submit() dashboard controller loaded and saved the Page Type identified by a user-supplied ptID without calling canEditPageType(), so a signed-in dashboard user permitted to edit one Page Type could… | |
| Analizada | Media (5.3) | 0.29% | — | Concretecms Concrete CMS | 11/9/2026 | 24/9/2026 | Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authentication, facilitating phishing and credential theft. The same handling is present in… | |
| Analizada | Media (5.7) | 0.19% | — | Concretecms Concrete CMS | 11/9/2026 | 24/9/2026 | Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard/users/groups/bulkupdate/confirm() endpoint moved the selected group tree nodes without validating an action token, so a state-changing group move could be processed for an authenticated user who did… | |
| Analizada | Media (5.8) | 0.24% | — | Concretecms Concrete CMS | 11/9/2026 | 18/9/2026 | Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_template endpoint authorizes the request only against the target board instance (canEditBoardContents()) and then persists the client-supplied selectedTemplateOption[collection] verbatim, rather than… | |
| Analizada | Media (5.3) | 0.11% | — | Concretecms Concrete CMS | 11/9/2026 | 25/9/2026 | Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canAccess() and the per-resource canAddCalendarEvent() permission, so a crafted… | |
| Aplazada | Media (5.9) | 0.44% | — | Concretecms Concrete CMSAI | 11/9/2026 | 11/9/2026 | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the target page, nor that the caller holds any permission over the source block. A user… | |
| Aplazada | Media (6) | 0.39% | — | Concretecms Concrete CMSAI | 11/9/2026 | 11/9/2026 | Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditionally returns true, so no per-object (tree node) authorization is enforced when the… | |
| Aplazada | Media (6) | 0.38% | — | Concretecms Concrete CMSAI | 11/9/2026 | 11/9/2026 | Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting. An attacker able to control a title in a syndicated feed could execute script in the site origin for any visitor to the affected page, including administrators, without… | |
| Aplazada | Media (6) | 0.23% | — | Concretecms Concrete CMSAI | 11/9/2026 | 11/9/2026 | Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth token with read scope for an Express entity could enumerate entries that its user… | |
| Aplazada | Media (6.3) | 0.62% | — | Concretecms Concrete CMSAI | 11/9/2026 | 11/9/2026 | Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that was fully authenticated for the callback… | |
| Aplazada | Media (6.3) | 0.36% | — | Concretecms Concrete CMSAI | 11/9/2026 | 11/9/2026 | Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alone and does not verify its type. As a result, a hash issued for one purpose can be… | |
| Aplazada | Media (6.3) | 0.29% | — | Concretecms Concrete CMSAI | 11/9/2026 | 11/9/2026 | Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calendar that owns the requested event occurrence. The controller loads the occurrence… | |
| Aplazada | Media (5.3) | 0.24% | — | Concretecms Concrete CMSAI | 10/9/2026 | 10/9/2026 | Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action. The action created a board_slot_proxy Block and dispatched an AddCustomSlotToBoardCommand against a board instance while gating only on… | |
| Aplazada | Media (5.9) | 0.47% | — | Concretecms Concrete CMSAI | 10/9/2026 | 10/9/2026 | Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (concrete/controllers/dialog/event/edit.php). The dialog checked permissions against the calendar identifier supplied in the request rather than the calendar owning the targeted event occurrence. A… | |
| Aplazada | Media (6.3) | 0.46% | — | Concretecms Concrete CMSAI | 8/9/2026 | 10/9/2026 | Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block. An unauthenticated visitor could recover configuration values emitted by a restricted sub-block's asset registration — such as a site's… | |
| Aplazada | Media (5.4) | 0.30% | — | Sanitize-htmlAIApostrophecmsAI | 1/9/2026 | 9/9/2026 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting… | |
| Aplazada | Baja (2.1) | 0.35% | — | DedecmsAI | 20/8/2026 | 21/8/2026 | A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_media_post.php. Executing a manipulation of the argument uploadfile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.41% | — | DedecmsAI | 20/8/2026 | 20/8/2026 | A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Alta (7.1) | 0.43% | — | ApostrophecmsAI | 17/8/2026 | 9/9/2026 | ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toString.call and passes it through the utility module to apos.util.set() and apos.util.get(), allowing an authenticated editor to overwrite the shared… | |
| Aplazada | Media (6.1) | 0.33% | — | ApostrophecmsAI | 17/8/2026 | 9/9/2026 | ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through packages/sanitize-html/index.js when textarea or xmp is included in allowedTags because a literal solidus after the raw-text end-tag name is treated as text by htmlparser2… |