Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
421 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.69% | — | ApostrophecmsAISanitize-htmlAI | 12/6/2026 | 10/9/2026 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This… | |
| Aplazada | Media (5.1) | 0.44% | — | Typo3 Html-sanitizerAI | 8/6/2026 | 23/7/2026 | Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2. | |
| Aplazada | Baja (2.1) | 0.44% | — | Typo3 Html-sanitizerAI | 8/6/2026 | 23/7/2026 | When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer… | |
| Modificada | Alta (7.5) | 0.51% | — | Oalders Html\ | 4/6/2026 | 22/7/2026 | HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::Entities::_decode_entities cached a pointer (repl) into the entity-value SV returned by hv_fetch on the entity2char hash. When the input SV was identical to a value SV in that hash, and that value… | |
| Aplazada | Crítica (9.8) | 3.0% | — | Openlabs Docker-wkhtmltopdf-aasAI | 3/6/2026 | 22/7/2026 | An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request. | |
| Aplazada | Media (6.5) | 0.14% | — | Recorp Export WP Page TO Static Html CSSAI | 25/5/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery. This issue affects Export WP Page to Static HTML/CSS: from n/a through 6.0.0. | |
| Aplazada | Media (6.1) | 0.34% | — | Template Toolkit Template Plugin HtmlAI | 19/5/2026 | 19/9/2026 | Template::Plugin::HTML versions before 3.103 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For example, the variable "var" in would not be properly escaped. An attacker could insert some… | |
| Analizada | Alta (7.3) | 0.21% | — | Joplinapp JoplinMsiemens One2html | 18/5/2026 | 24/7/2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing… | |
| Analizada | Crítica (10) | 1.0% | — | Dhtmlx PDF Export Module | 15/5/2026 | 17/6/2026 | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "data" parameter sanitization. An unauthenticated attacker can inject the malicious JavaScript code to the parameter whose value is processed by Node.js and subsequently executed. This can lead to… | |
| Analizada | Crítica (9.2) | 0.55% | — | Dhtmlx PDF Export Module | 15/5/2026 | 17/6/2026 | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated PDF. This issue was fixed in PDF Export Module version… | |
| Aplazada | Media (6.1) | 0.25% | — | FluentcmsAIFluentcms TexthtmlAI | 5/5/2026 | 24/7/2026 | FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin. | |
| Analizada | Alta (8) | 0.50% | — | Jenkins Html Publisher | 29/4/2026 | 17/6/2026 | Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Aplazada | Alta (8.9) | 0.41% | — | HtmlyAI | 28/4/2026 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails to properly sanitize user input, allowing injection of arbitrary code | |
| Analizada | Media (6.1) | 0.28% | — | ApostrophecmsApostrophecms Sanitize-html | 15/4/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included in versions 2.17.1 of the ApostropheCMS-maintained sanitize-html package bypasses allowedTags enforcement for text inside nonTextTagsArray elements (textarea and option). ApostropheCMS version 4.28.0… | |
| Analizada | Alta (8.6) | 0.21% | — | Socusoft Html5 Video Player | 12/4/2026 | 17/6/2026 | HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and… | |
| Aplazada | Media (5.9) | 0.24% | — | Ashish Ajani WP Simple Html SitemapAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani WP Simple HTML Sitemap wp-simple-html-sitemap allows DOM-Based XSS.This issue affects WP Simple HTML Sitemap: from n/a through <= 3.8. | |
| Aplazada | Media (5.4) | 0.18% | — | Dogblocker Minify HtmlAI | 31/3/2026 | 25/7/2026 | The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing or incorrect nonce validation on the 'minify_html_menu_options' function. This makes it possible for unauthenticated attackers to update plugin settings via a forged… | |
| Aplazada | Media (4.3) | 0.14% | — | SR WP Minify HtmlAI | 21/3/2026 | 17/6/2026 | The SR WP Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing nonce validation on the sr_minify_html_theme() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted… | |
| Aplazada | Media (6.4) | 0.36% | — | Scoreboard FOR Html5 Games LiteAI | 21/3/2026 | 17/6/2026 | The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboard' shortcode in all versions up to, and including, 1.2. The shortcode function sfhg_shortcode() allows arbitrary HTML attributes to be added to the rendered <iframe> element, with only a small… | |
| Analizada | Baja (2.1) | 0.84% | — | Html-js Doracms | 9/3/2026 | 17/6/2026 | A security flaw has been discovered in doramart DoraCMS 3.0.x. Impacted is the function createFileBypath of the file /DoraCMS/server/app/router/api/v1.js. Performing a manipulation results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.… | |
| Analizada | Media (5.5) | 0.99% | — | Html-js Doracms | 9/3/2026 | 17/6/2026 | A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component Email API. Such manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The… | |
| Analizada | Media (6.1) | 0.28% | — | Fedoralovespython Lxml Html Clean | 5/3/2026 | 17/6/2026 | lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_structure=True removes html, head, and title tags, there is no specific handling for <base>, allowing an attacker to inject… | |
| Analizada | Media (6.1) | 0.29% | — | Fedoralovespython Lxml Html Clean | 5/3/2026 | 17/6/2026 | lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for dangerous CSS keywords. This causes CSS Unicode escape sequences to bypass the @import and expression() filters, allowing… | |
| Aplazada | Media (4.4) | 0.25% | — | Allow Html IN Category DescriptionsAI | 14/2/2026 | 17/6/2026 | The Allow HTML in Category Descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via category descriptions in all versions up to, and including, 1.2.4. This is due to the plugin unconditionally removing the `wp_kses_data` output filter for term_description, link_description, link_notes, and… | |
| Aplazada | Media (6.4) | 0.27% | — | Html TAG ShortcodesAI | 11/2/2026 | 17/6/2026 | The HTML Tag Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… |