Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
351 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.40% | — | Craftcms Craft CMSAI | 22/4/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the <VolumeName> volume" and "Create assets in… | |
| Aplazada | Media (5.3) | 0.36% | — | Craftcms Craft CMSAI | 22/4/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it performs no equivalent… | |
| Analizada | Crítica (9) | 0.51% | — | Craftycontrol Crafty Controller | 21/4/2026 | 17/6/2026 | An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation. | |
| Aplazada | Alta (7.5) | 0.56% | — | Markhuot CraftqlAI | 17/4/2026 | 17/6/2026 | Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the vendor/markhuot/craftql/src/Listeners/GetAssetsFieldSchema.php file | |
| Aplazada | Alta (8.7) | 0.46% | — | Craftcms CommerceAI | 13/4/2026 | 17/6/2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability exists where the ProductQuery::hasVariant and VariantQuery::hasProduct properties bypass the input sanitization blocklist added to ElementIndexesController in a prior security fix… | |
| Aplazada | Alta (7.7) | 0.60% | — | Craftcms CommerceAIYiisoft Yii2-queueAIGuzzlephp GuzzleAI | 13/4/2026 | 17/6/2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerability in the Commerce TotalRevenue widget which allows any authenticated control panel user to achieve remote code execution through a four-step exploitation chain. The… | |
| Aplazada | Baja (1.7) | 0.51% | — | Craftcms Craft CommerceAI | 13/4/2026 | 17/6/2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the PaymentsController::actionPay discloses some order data to unauthenticated users when an order number is provided and the email check fails during an anonymous payment. The JSON error response includes… | |
| Analizada | Media (4.9) | 0.38% | — | Craftcms Craft CMS | 24/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they do not have saveEntries:{sectionUid} permission for either source or destination… | |
| Analizada | Baja (1.3) | 0.34% | — | Craftcms Craft CMS | 24/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call assets/image-editor with the ID of a private asset they cannot view and still receive editor response data, including… | |
| Analizada | Baja (2.7) | 0.41% | — | Craftcms Craft CMS | 24/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, an unauthenticated user can call assets/generate-transform with a private assetId, receive a valid transform URL, and fetch transformed image bytes. The endpoint is… | |
| Analizada | Media (6.9) | 0.43% | — | Craftcms Craft CMS | 24/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, guest users can access Config Sync updater index, obtain signed data, and execute state-changing Config Sync actions (regenerate-yaml, apply-yaml-changes) without… | |
| Analizada | Media (4.9) | 0.42% | — | Craftcms Craft CMS | 24/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can read private asset content by calling assets/edit-image with an arbitrary assetId that they are not authorized to view. The… | |
| Analizada | Alta (8.6) | 1.1% | 💥 PoC | Craftcms Craft CMS | 24/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RCE) vulnerability exists in Craft CMS, it can be exploited by any authenticated user with control panel access. This is a bypass of a previous fix. The existing patches add cleanseConfig() to… | |
| Aplazada | Media (5.5) | 0.42% | — | Putyourlightson SprigAICraftcms Craft CMSAI | 23/3/2026 | 17/6/2026 | The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.2, admin users, and users with explicit permission to access the Sprig Playground, could potentially expose the security key, credentials, and other sensitive… | |
| Analizada | Media (5.3) | 0.29% | — | Craftcms Craft CMS | 20/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s fullName as raw HTML due to the use of Template::raw() combined with Craft::t() string interpolation. A low-privileged control panel user (e.g., Author)… | |
| Aplazada | Alta (8.7) | 0.43% | — | Craftcms Azure Blob StorageAICraftcms Craft CMSAI | 18/3/2026 | 17/6/2026 | The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.1.1, unauthenticated users can view a list of buckets the plugin has access to. The `DefaultController->actionLoadContainerData()` endpoint allows unauthenticated users with a… | |
| Aplazada | Baja (2.4) | 0.46% | — | Google Cloud StorageAICraftcms Craft CMSAICraftcms Google Cloud StorageAI | 18/3/2026 | 17/6/2026 | The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.2.1, the `DefaultController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to… | |
| Aplazada | Media (6.9) | 0.46% | — | Amazon S3 FOR Craft CMS Project Amazon S3 FOR Craft CMSAICraftcms Craft CMSAI | 18/3/2026 | 17/6/2026 | The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, unauthenticated users can view a list of buckets the plugin has access to. The `BucketsController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of… | |
| Analizada | Alta (7.7) | 0.49% | — | Craftcms Craft CMS | 16/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing… | |
| Analizada | Alta (8.6) | 0.68% | — | Craftcms Craft CMS | 16/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, there is a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController. Craft control panel administrator permissions and allowAdminChanges must… | |
| Analizada | Alta (8.6) | 0.65% | — | Craftcms Craft CMS | 16/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settings array from parse_str is passed directly to Craft::configure() without Component::cleanseConfig(). This allows injecting Yii2 behavior/event handlers via "as" or "on"… | |
| Analizada | Media (5.3) | 0.35% | — | Craftcms Craft CMS | 16/3/2026 | 17/6/2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, the AssetsController->replaceFile() method has a targetFilename body parameter that is used unsanitized in a deleteFile() call before Assets::prepareAssetName() is… | |
| Aplazada | Alta (8.5) | 0.44% | — | Craftcms WebhooksAI | 16/3/2026 | 17/6/2026 | Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests when certain events occur. From version 3.0.0 to before version 3.2.0, the Webhooks plugin renders user-supplied template content through Twig’s renderString() function without sandbox protection.… | |
| Pendiente de análisis | Crítica (9.8) | 1.6% | — | Claude-hovercraftAI | 16/3/2026 | 17/6/2026 | claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of claude-hovercraft. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (6.3) | 0.32% | — | Craftcms Craft Commerce | 11/3/2026 | 17/6/2026 | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (IDOR) vulnerability exists in Craft Commerce’s cart functionality that allows users to hijack any shopping cart by knowing or guessing its 32-character number. The CartController accepts a… |