Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 0.40% | — | Simplemachines Simple Machines Forum | 21/3/2025 | 17/6/2026 | A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file ManageAttachments.php. The manipulation of the argument Notice leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.5) | 0.38% | — | Gvectors Wpforo Forum | 28/2/2025 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'update' method of the 'Members' class in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with subscriber-level privileges or higher, to read arbitrary… | |
| Analizada | Media (6.9) | 0.79% | — | Codezips Technical Discussion Forum | 19/12/2024 | 17/6/2026 | A vulnerability was found in Codezips Technical Discussion Forum 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file signinpost.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.71% | — | Ultimatemember Forumwp | 16/12/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue affects ForumWP: from n/a through <= 2.1.0. | |
| Analizada | Media (6.9) | 1.00% | 💥 PoC | Codezips Technical Discussion Forum | 12/12/2024 | 17/6/2026 | A vulnerability classified as critical was found in Codezips Technical Discussion Forum 1.0. This vulnerability affects unknown code of the file /signuppost.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Media (5.4) | 0.30% | — | Gvectors Wpforo Forum | 9/12/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Code Injection.This issue affects wpForo Forum: from n/a through 2.2.5. | |
| Modificada | Media (6.1) | 0.35% | — | Ultimatemember Forumwp | 6/12/2024 | 17/6/2026 | The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (6.1) | 0.40% | — | Ultimatemember Forumwp | 6/12/2024 | 17/6/2026 | The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Analizada | Media (5.4) | 0.27% | — | Emiloimagtolis Online Discussion Forum | 4/12/2024 | 17/6/2026 | Itsourcecode Online Discussion Forum Project v.1.0.0 is vulnerable to Cross Site Scripting (XSS) via /bcc_forum/members/home.php. | |
| Aplazada | Media (6.1) | 0.45% | — | ForumengineAI | 21/11/2024 | 17/6/2026 | The ForumEngine theme for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can… | |
| Analizada | Alta (8.8) | 1.1% | — | Emiloimagtolis Online Discussion Forum | 4/10/2024 | 17/6/2026 | File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "poster.php" file, and the uploaded file was received using the "$- FILES" variable | |
| Analizada | Alta (8.8) | 1.1% | — | Emiloimagtolis Online Discussion Forum | 4/10/2024 | 17/6/2026 | File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "sendreply.php" file, and the uploaded file was received using the "$- FILES" variable. | |
| Analizada | Media (5.3) | 0.75% | — | Oretnom23 Simple Forum/discussion System | 20/9/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument page leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.48% | — | Ultimatemember Forumwp | 6/9/2024 | 17/6/2026 | The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submit_form_handler due to missing validation on the 'user_id' user controlled key. This makes it possible for authenticated… | |
| Analizada | Alta (8.8) | 0.54% | — | Oretnom23 Simple Forum Website | 6/9/2024 | 17/6/2026 | Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=. | |
| Analizada | Alta (7.5) | 0.45% | — | Gvectors Wpforo Forum | 26/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4. | |
| Analizada | Media (6.9) | 0.49% | — | Oretnom23 Simple Forum Website | 19/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Forum Website 1.0. This affects an unknown part of the file /registration.php of the component Signup Page. The manipulation of the argument username leads to cross site scripting. It is possible to initiate the attack remotely.… | |
| Analizada | Alta (8.1) | 0.31% | — | Gvectors Wpforo Forum | 18/8/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4. | |
| Analizada | Media (5.3) | 0.48% | — | Simplemachines Simple Machines Forum | 3/8/2024 | 17/6/2026 | A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Alert Read Status Handler. The manipulation of the argument aid leads to improper… | |
| Analizada | Media (5.3) | 0.44% | — | Simplemachines Simple Machines Forum | 3/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the component Delete User Handler. The manipulation of the argument aid leads to improper control of resource identifiers. It… | |
| Analizada | Alta (8.2) | 0.45% | — | Emiloi Online Discussion Forum | 9/7/2024 | 17/6/2026 | SQL injection vulnerability in login.php in Itsourcecode Online Discussion Forum Project in PHP with Source Code 1.0 allows remote attackers to execute arbitrary SQL commands via the email parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Gvectors Wpforo Forum | 21/6/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Content Spoofing.This issue affects wpForo Forum: from n/a through 2.0.9. | |
| Modificada | Media (5.3) | 0.62% | — | Online Discussion Forum Project Online Discussion Forum | 7/6/2024 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. Affected is an unknown function of the file /members/poster.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.9) | 0.62% | — | Online Discussion Forum Project Online Discussion Forum | 7/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Online Discussion Forum 1.0. It has been rated as critical. This issue affects some unknown processing of the file register_me.php. The manipulation of the argument eaddress leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.5) | 0.46% | — | Gvectors Wpforo Forum | 1/6/2024 | 17/6/2026 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and including, 2.3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… |