Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
236 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.77% | — | FlatnuxAI | 19/12/2025 | 17/6/2026 | Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitrary PHP files through the file manager. Attackers with admin credentials can upload malicious PHP scripts to the web root directory, enabling remote code execution on the server. | |
| Aplazada | Media (5.3) | 0.37% | — | FlatboardAI | 11/12/2025 | 17/6/2026 | Flatboard 3.2 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts in forum information fields. Attackers can insert JavaScript payloads that execute when other users view the forum, potentially stealing session cookies and executing client-side… | |
| Aplazada | Crítica (9.8) | 0.49% | — | Themesflat TF WOO Product GridAI | 22/10/2025 | 5/10/2026 | Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For Elementor tf-woo-product-grid allows Object Injection.This issue affects TF Woo Product Grid Addon For Elementor: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.4) | 0.20% | — | Uxthemes FlatsomeAI | 5/9/2025 | 17/6/2026 | The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions up to, and including, 3.20.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Media (5.1) | 0.33% | — | Flatboard PROAI | 3/7/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a stored XSS due to lack of proper validation of user input, through the footer_text and announcement parameters in config.php. | |
| Aplazada | Media (5.1) | 0.33% | — | Flatboard PROAI | 3/7/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a stored XSS due to lack of proper validation of user input, through the replace parameter in /config.php/tags. | |
| Aplazada | Alta (7.1) | 0.28% | — | Sneeit FlatnewsAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sneeit WordPress FlatNews Theme flatnews allows Reflected XSS.This issue affects WordPress FlatNews Theme: from n/a through <= 5.8. | |
| Analizada | Media (4.8) | 0.33% | — | Flatpress | 19/5/2025 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently. | |
| Aplazada | Media (4.8) | 0.20% | — | Xu-yijie Grpo-flatAI | 16/5/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in XU-YIJIE grpo-flat up to 9024b43f091e2eb9bac65802b120c0b35f9ba856. Affected is the function main of the file grpo_vanilla.py. The manipulation leads to deserialization. Local access is required to approach this attack. Continious delivery with rolling… | |
| Analizada | Media (6.1) | 0.29% | — | Flatpress | 7/5/2025 | 17/6/2026 | flatpress 1.3.1 is vulnerable to Cross Site Scripting (XSS) in Administration area via Manage categories. | |
| Aplazada | Media (6.4) | 0.31% | — | Themesflat Addons FOR ElementorAI | 19/4/2025 | 17/6/2026 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider widget in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Analizada | Media (6.6) | 0.52% | — | Flattern Project Flattern | 31/3/2025 | 17/6/2026 | Vulnerability in Drupal Flattern – Multipurpose Bootstrap Business Profile.This issue affects Flattern – Multipurpose Bootstrap Business Profile: *.*. | |
| Aplazada | Media (6.5) | 0.26% | — | Themesflat-addons-for-elementorAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesflat-addons-for-elementor themesflat-addons-for-elementor allows Stored XSS.This issue affects themesflat-addons-for-elementor: from n/a through <= 2.3.1. | |
| Analizada | Crítica (9.8) | 0.87% | — | Alizeait Unflatto | 28/3/2025 | 17/6/2026 | alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/index.js. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
| Aplazada | Media (5.9) | 0.23% | — | Michele Marri FlattyAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michele Marri Flatty flatty-flat-admin-theme allows Stored XSS.This issue affects Flatty: from n/a through <= 2.0.0. | |
| Analizada | Alta (8) | 0.34% | — | Flatpress | 20/3/2025 | 17/6/2026 | FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf of a victim user. The attacker can craft a malicious link or script that, when clicked by an authenticated user, will send a request to the FlatPress CMS server to… | |
| Analizada | Media (5.4) | 0.35% | — | Flatpress | 20/3/2025 | 17/6/2026 | A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScript payload disguised as a filename. This can lead to a Cross-Site Scripting (XSS) attack if the uploaded file is accessed by other users. The issue is fixed in version… | |
| Analizada | Alta (8.1) | 0.79% | — | Flatpress | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in flatpressblog/flatpress version 1.3. When a user uploads a file with a `.xsig` extension and directly accesses this file, the server responds with a Content-type of application/octet-stream, leading to the file being processed as an HTML file. This allows an… | |
| Analizada | Media (4.8) | 0.55% | — | Flatpress | 24/2/2025 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input… | |
| Aplazada | Alta (7.5) | 0.51% | — | FlatnotesAI | 14/1/2025 | 17/6/2026 | Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function. | |
| Analizada | Media (5.4) | 0.31% | — | Themesflat Addons FOR Elementor | 8/1/2025 | 17/6/2026 | The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Crítica (9.8) | 25% | — | Nextu Flata Ax1500AI | 16/12/2024 | 17/6/2026 | Buffer Overflow vulnerability in NEXTU FLATA AX1500 Router v.1.0.2 allows a remote attacker to execute arbitrary code via the POST request handler component. | |
| Modificada | Media (5.4) | 0.32% | — | Themesflat Addons FOR Elementor | 6/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesflat-addons-for-elementor themesflat-addons-for-elementor allows DOM-Based XSS.This issue affects themesflat-addons-for-elementor: from n/a through <= 2.2.2. | |
| Analizada | Media (5.4) | 0.30% | — | Tiandiyoyo Flat UI Button | 18/10/2024 | 17/6/2026 | The Flat UI Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's flatbtn shortcode in version 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Modificada | Media (5.4) | 0.28% | — | Themesflat Addons FOR Elementor | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesflat themesflat-addons-for-elementor themesflat-addons-for-elementor allows Stored XSS.This issue affects themesflat-addons-for-elementor: from n/a through <= 2.2.0. |