Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.41% | — | Getgrav Grav APIAIGetgrav GravAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.8, the Grav API plugin intercepts the apiKeyGenerate and apiKeyRevoke admin tasks in user/plugins/api/api.php and authorizes the caller with only admin.login. A basic panel user can select another… | |
| Aplazada | Alta (8.5) | 0.46% | — | Grav Shortcode CoreAI | 19/8/2026 | 9/9/2026 | Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common format utilized by WordPress and BBCode. Prior to 6.2.2, Grav Shortcode Core passes shortcode syntax through Security::detectXss() because it contains no literal less-than character, then ColorShortcode.php and related… | |
| Aplazada | Alta (8.7) | 0.47% | — | Getgrav GravAI | 19/8/2026 | 9/9/2026 | Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array() without rejecting dangerous callback parameters. An account with admin.pages or api.pages.write can use… | |
| Aplazada | Alta (7.5) | 0.49% | — | Grav API PluginAIGetgrav Grav CMSAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin JwtAuthenticator::extractBearerToken() accepts a JWT from the token URL query parameter on every /api/v1 route, including state-changing endpoints. Request URLs… | |
| Aplazada | Alta (8.2) | 0.38% | — | Getgrav Grav API PluginAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin CorsMiddleware returns Access-Control-Allow-Origin: * and permissive OPTIONS responses for authenticated /api/v1 endpoints. JavaScript from any origin can submit an… | |
| Aplazada | Alta (8.2) | 0.54% | — | Getgrav GravAI | 19/8/2026 | 9/9/2026 | Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive directory and file-extension patterns case-sensitively. On a case-insensitive filesystem, an unauthenticated requester can use uppercase… | |
| Aplazada | Media (6) | 0.38% | — | Getgrav GravAI | 19/8/2026 | 9/9/2026 | Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in system/config/security.yaml, and GravExtension::regexReplace() passes an editor-controlled pattern directly to preg_replace(). When security.twig_content.process_enabled is enabled, an authenticated page editor… | |
| Aplazada | Media (6.3) | 0.33% | — | Getgrav Flex ObjectsAI | 19/8/2026 | 9/9/2026 | Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Objects Admin Next API requireFlexPermission() method in classes/Api/FlexApiController.php returns without denying access when a directory blueprint omits config.admin.permissions. An authenticated account with… | |
| Aplazada | Alta (7.4) | 0.50% | — | Getgrav Grav LoginAI | 19/8/2026 | 9/9/2026 | Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task checks only that the pending-session user exists rather than requiring $user->authorized. After submitting a victim's correct password, an attacker can invoke… | |
| Aplazada | Crítica (9.4) | 0.45% | — | Getgrav Grav API PluginAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin WebhookController.php accepts webhook URLs after only FILTER_VALIDATE_URL syntax validation, and WebhookDispatcher.php initializes cURL without CURLOPT_PROTOCOLS or… | |
| Aplazada | Alta (8.1) | 0.41% | — | Grav API PluginAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin ApiKeyManager::generateKey() stores a declared scopes array, but ApiKeyAuthenticator::authenticate() does not read keyData[scopes] and returns the owning user's complete… | |
| Aplazada | Alta (8.8) | 0.64% | — | Getgrav Grav API PluginAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, Grav API plugin UsersController::createApiKey(), generate2fa(), and disable2fa() omit the accessGrantsSuper() target check used by sibling user mutation endpoints. A non-super account with… | |
| Aplazada | Media (6.5) | 0.44% | — | Getgrav GravAI | 19/8/2026 | 9/9/2026 | Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, print_r, yaml_encode, and string filters to serialize that object without passing through GravSecurityPolicy::checkMethodAllowed. A user with… | |
| Aplazada | Media (6.5) | 0.53% | — | Getgrav GravAI | 19/8/2026 | 9/9/2026 | Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives to ZipArchive::extractTo() without enforcing the system.gpm.archive uncompressed-size, file-count, or nesting-depth limits. Code using Archiver::create('zip') to extract… | |
| Aplazada | Media (4.6) | 0.29% | — | Grav API PluginAI | 19/8/2026 | 9/9/2026 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2, the Grav API plugin POST /api/v1/media pipeline in HandlesMediaUploads::processUploadedFile() validates an SVG filename extension but does not invoke Security::sanitizeSVG(). An attacker with… | |
| Aplazada | Media (5.3) | 0.53% | — | Getgrav GravAI | 19/8/2026 | 9/9/2026 | Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and allows an unauthenticated request to set an external http, https, or protocol-relative Location target. Controller::execute() applies the field when taskTwofa_cancel()… | |
| Aplazada | Media (5.4) | 0.23% | — | Gravity BoosterAI | 18/8/2026 | 20/8/2026 | Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Gravityforms BookingsAI | 18/8/2026 | 20/8/2026 | Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | |
| Aplazada | Crítica (9.3) | 0.49% | — | Getgrav GravAI | 18/8/2026 | 8/9/2026 | Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation capabilities. | |
| Aplazada | Alta (8.7) | 0.47% | — | Getgrav GravAIGetgrav Grav Plugin APIAI | 18/8/2026 | 8/9/2026 | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction(). While the GET /menubar/items listing endpoint correctly filters menubar items via userPassesAuthorize(), the POST… | |
| Aplazada | Crítica (9.3) | 0.31% | — | Getgrav Grav Plugin APIAI | 18/8/2026 | 8/9/2026 | Grav API plugin (getgrav/grav-plugin-api) before 1.0.14 contains a missing authorization vulnerability in userPassesAuthorize() (AbstractApiController.php). The function fails to consult the calling request's API key scopes, relying instead on the account's raw super-admin flag and ACL grants. As a result, an… | |
| Aplazada | Media (5.1) | 0.26% | — | Getgrav GravAI | 18/8/2026 | 8/9/2026 | Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a single invalid UTF-8 byte anywhere in page content causes preg_match() to return false for every… | |
| Aplazada | Alta (8.6) | 0.22% | — | Getgrav Grav-plugin-apiAIGetgrav GravAI | 18/8/2026 | 8/9/2026 | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an open redirect weakness in SsoController::sanitizeReturnTo(). The function rejects a literal '//' prefix but does not account for browsers normalizing backslashes to slashes in special… | |
| Aplazada | Crítica (9.3) | 0.30% | — | Getgrav GravAIGetgrav Grav-plugin-apiAI | 18/8/2026 | 8/9/2026 | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0) before version 1.0.14 (fixed in 1.0.15) contains a missing authorization vulnerability in BlueprintPathResolver::resolveUserScope(). The method gates the users/<name> scope on the account's raw super-admin ACL flag (access.api.super) instead of… | |
| Aplazada | Media (5.1) | 0.35% | — | Getgrav GravAI | 18/8/2026 | 8/9/2026 | Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allowing attackers to inject arbitrary HTML and JavaScript that executes in viewers'… |