Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.49% | — | Craftcms Craft CMSAI | 21/6/2026 | 23/6/2026 | Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowing local file read… | |
| Aplazada | Media (4.6) | 0.32% | — | Craftcms Craft CMSAI | 21/6/2026 | 22/6/2026 | Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rendered without sanitization (e.g., via the checkbox.twig template, which used {{ label|raw }}). An authenticated… | |
| Aplazada | Media (5.3) | 0.36% | — | Craftcms Craft CMSAI | 21/6/2026 | 22/6/2026 | Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization before returning preview content, allowing an authenticated low-privileged user to supply a controlled assetId for an… | |
| Aplazada | Media (5.3) | 0.33% | — | Craftcms Craft CMSAI | 21/6/2026 | 24/6/2026 | Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an attacker-controlled assetId and receive preview HTML containing a signed fallback transform preview link for that private… | |
| Aplazada | Media (4.6) | 0.31% | — | Craftcms Craft CMSAI | 21/6/2026 | 23/6/2026 | Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the 'Row Heading' column type. The application fails to sanitize input within row heading default values, allowing an attacker with an administrator account (with allowAdminChanges enabled) to inject… | |
| Aplazada | Alta (8.6) | 0.89% | — | Craftcms CMSAI | 21/6/2026 | 22/6/2026 | Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the fieldLayoutConfig POST parameter directly to Fields::createLayout() without calling Component::cleanseConfig(). An… | |
| Aplazada | Media (4.6) | 0.25% | — | Craftcms Craft CMSAI | 21/6/2026 | 23/6/2026 | Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where user group names are rendered without proper HTML escaping. Attackers with admin access can inject arbitrary JavaScript via the user group name field that executes when other users view or edit… | |
| Aplazada | Crítica (9.8) | 0.81% | — | Verbb FormieAICraftcms Craft CMSAI | 29/5/2026 | 22/7/2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox… | |
| Aplazada | Alta (7.1) | 0.36% | — | Craftcms Craft CMSAI | 12/5/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filename and complete folder hierarchy (including volume handle, volume UID, folder names, folder UIDs, and folder URI paths) without checking whether the… | |
| Aplazada | Alta (8.6) | 0.44% | — | Craftcms Craft CMSAI | 12/5/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execute arbitrary commands on the server. The request-controlled condition field… | |
| Aplazada | Alta (7.1) | 0.36% | — | Craftcms Craft CMSAI | 12/5/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php) performs no schema scope filtering on top-level queries. A GraphQL API token scoped to a single low-privilege user group can read every address in the… | |
| Aplazada | Media (5.5) | 0.40% | — | Craftcms Craft CMSAI | 22/4/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. When `trustedHosts` is not explicitly restricted (default configuration), the… | |
| Aplazada | Media (5.5) | 0.40% | — | Craftcms Craft CMSAI | 22/4/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the <VolumeName> volume" and "Create assets in… | |
| Aplazada | Media (5.3) | 0.36% | — | Craftcms Craft CMSAI | 22/4/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it performs no equivalent… | |
| Aplazada | Alta (8.7) | 0.46% | — | Craftcms CommerceAI | 13/4/2026 | 17/6/2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability exists where the ProductQuery::hasVariant and VariantQuery::hasProduct properties bypass the input sanitization blocklist added to ElementIndexesController in a prior security fix… | |
| Aplazada | Alta (7.7) | 0.60% | — | Craftcms CommerceAIYiisoft Yii2-queueAIGuzzlephp GuzzleAI | 13/4/2026 | 17/6/2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerability in the Commerce TotalRevenue widget which allows any authenticated control panel user to achieve remote code execution through a four-step exploitation chain. The… | |
| Aplazada | Baja (1.7) | 0.51% | — | Craftcms Craft CommerceAI | 13/4/2026 | 17/6/2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the PaymentsController::actionPay discloses some order data to unauthenticated users when an order number is provided and the email check fails during an anonymous payment. The JSON error response includes… | |
| Analizada | Media (4.9) | 0.38% | — | Craftcms Craft CMS | 24/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they do not have saveEntries:{sectionUid} permission for either source or destination… | |
| Analizada | Baja (1.3) | 0.34% | — | Craftcms Craft CMS | 24/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call assets/image-editor with the ID of a private asset they cannot view and still receive editor response data, including… | |
| Analizada | Baja (2.7) | 0.41% | — | Craftcms Craft CMS | 24/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, an unauthenticated user can call assets/generate-transform with a private assetId, receive a valid transform URL, and fetch transformed image bytes. The endpoint is… | |
| Analizada | Media (6.9) | 0.43% | — | Craftcms Craft CMS | 24/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, guest users can access Config Sync updater index, obtain signed data, and execute state-changing Config Sync actions (regenerate-yaml, apply-yaml-changes) without… | |
| Analizada | Media (4.9) | 0.42% | — | Craftcms Craft CMS | 24/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can read private asset content by calling assets/edit-image with an arbitrary assetId that they are not authorized to view. The… | |
| Analizada | Alta (8.6) | 1.1% | — | Craftcms Craft CMS | 24/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RCE) vulnerability exists in Craft CMS, it can be exploited by any authenticated user with control panel access. This is a bypass of a previous fix. The existing patches add cleanseConfig() to… | |
| Aplazada | Media (5.5) | 0.42% | — | Putyourlightson SprigAICraftcms Craft CMSAI | 23/3/2026 | 17/6/2026 | The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.2, admin users, and users with explicit permission to access the Sprig Playground, could potentially expose the security key, credentials, and other sensitive… | |
| Analizada | Media (5.3) | 0.29% | — | Craftcms Craft CMS | 20/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s fullName as raw HTML due to the use of Template::raw() combined with Craft::t() string interpolation. A low-privileged control panel user (e.g., Author)… |