Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
421 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.40% | — | Html-js DoracmsAI | 10/2/2026 | 14/7/2026 | DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fetch functionality. The application accepts user-supplied URLs and performs server-side HTTP or HTTPS requests without sufficient validation or destination restrictions. The implementation does not… | |
| Modificada | Alta (7.1) | 0.43% | — | Lolypop55 Html5 Snmp | 6/2/2026 | 17/6/2026 | html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through Router_ID and Router_IP parameters. Attackers can exploit error-based, time-based, and union-based injection techniques to potentially extract or modify database information by sending crafted… | |
| Modificada | Media (5.1) | 0.24% | — | Lolypop55 Html5 Snmp | 6/2/2026 | 17/6/2026 | html5_snmp 1.11 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through the 'Remark' parameter in add_router_operation.php. Attackers can craft a POST request with a script payload in the Remark field to execute arbitrary JavaScript in victim browsers when the… | |
| Analizada | Media (5.3) | 0.55% | — | GO Html | 5/2/2026 | 17/6/2026 | The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content. | |
| Analizada | Media (5.3) | 0.57% | — | GO Html | 5/2/2026 | 17/6/2026 | The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content. | |
| Analizada | Media (6.3) | 0.40% | — | Htmlsanitizer Project Htmlsanitizer | 4/2/2026 | 17/6/2026 | HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. Prior to versions 9.0.892 and 9.1.893-beta, if the template tag is allowed, its contents are not sanitized. The template tag is a special tag that does not usually render its contents, unless the… | |
| Modificada | Crítica (9.8) | 0.54% | — | Apryse Html2pdf | 22/1/2026 | 5/7/2026 | An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker to execute arbitrary operating system commands on the local server. | |
| Modificada | Alta (7.5) | 0.47% | — | Apryse Html2pdf | 22/1/2026 | 5/7/2026 | A Local File Inclusion (LFI) and a Server-Side Request Forgery (SSRF) vulnerability was found in the InsertFromHtmlString() function of the Apryse HTML2PDF SDK thru 11.6.0. These vulnerabilities could allow an attacker to read local files on the server or make arbitrary HTTP requests to internal or external services.… | |
| Aplazada | Alta (7.1) | 0.30% | — | Lambertgroup Html5 Video Player With Playlist AND Multiple SkinsAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5 Video Player with Playlist & Multiple Skins lbg-vp2-html5-rightside allows Reflected XSS.This issue affects HTML5 Video Player with Playlist & Multiple Skins: from n/a through <= 5.3.5. | |
| Aplazada | Alta (7.1) | 0.21% | — | Lambertgroup Html5 Video PlayerAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5 Video Player lbg-vp2-html5-bottom allows Reflected XSS.This issue affects HTML5 Video Player: from n/a through <= 5.3.5. | |
| Analizada | Alta (8.7) | 0.38% | — | Ekoopmans Html2pdf.js | 14/1/2026 | 17/6/2026 | html2pdf.js converts any webpage or element into a printable PDF entirely client-side. Prior to 0.14.0, html2pdf.js contains a cross-site scripting (XSS) vulnerability when given a text source rather than an element. This text is not sufficiently sanitized before being attached to the DOM, allowing malicious scripts… | |
| Modificada | Media (5.3) | 0.83% | — | Phphtmledit Rich Text Editor | 13/1/2026 | 17/6/2026 | CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal… | |
| Aplazada | Alta (7.2) | 0.24% | — | Bplugins Html5 Audio PlayerAI | 19/12/2025 | 17/6/2026 | The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions from 2.4.0 up to, and including, 2.5.1 via the getIcyMetadata() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary… | |
| Aplazada | Media (6.1) | 0.26% | — | HtmlformsAI | 17/12/2025 | 17/6/2026 | The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.0 due to insufficient sanitization of fabricated file upload field metadata before displaying it in the WordPress admin dashboard. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 2.1% | — | Export WP Page TO Static Html PDFAI | 13/12/2025 | 17/6/2026 | The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.4 through publicly exposed cookies.txt files containing authentication cookies. This makes it possible for unauthenticated attackers to cookies that may have been… | |
| Analizada | Alta (8.6) | 0.25% | — | Owasp Java Html Sanitizer | 26/11/2025 | 17/6/2026 | OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by third-parties in web applications while protecting against XSS. In version 20240325.1, OWASP java html sanitizer is vulnerable to XSS if HtmlPolicyBuilder allows noscript and style tags with allowTextIn… | |
| Aplazada | Alta (7.6) | 0.22% | — | Prosemirror TO HtmlAI | 10/11/2025 | 17/6/2026 | ProsemirrorToHtml is a JSON converter which takes ProseMirror-compatible JSON and outputs HTML. In versions 0.2.0 and below, the `prosemirror_to_html` gem is vulnerable to Cross-Site Scripting (XSS) attacks through malicious HTML attribute values. While tag content is properly escaped, attribute values are not,… | |
| Aplazada | Media (4.4) | 0.19% | — | Html Forms Simple Wordpress Forms PluginAI | 8/11/2025 | 17/6/2026 | The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Analizada | Media (6.1) | 0.28% | — | Rems Markdown TO Html Converter | 7/10/2025 | 17/6/2026 | Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" field, allowing a remote attacker to inject arbitrary HTML/JavaScript code that executes in the victim's browser upon clicking the "Convert to HTML" button. | |
| Modificada | Media (6.1) | 0.32% | — | Htmly | 2/10/2025 | 17/6/2026 | htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The name parameter is not properly sanitized before being reflected in the HTML response, allowing attackers to inject arbitrary JavaScript payloads. | |
| Analizada | Baja (1.9) | 0.30% | — | Htmly | 21/9/2025 | 17/6/2026 | A security vulnerability has been detected in htmly up to 3.1.0. The impacted element is an unknown function of the file /htmly/admin/field/post of the component Custom Field Handler. Such manipulation of the argument label leads to cross site scripting. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.3) | 0.23% | — | Recorp Export WP Page TO Static HtmlAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in recorp Export WP Page to Static HTML/CSS export-wp-page-to-static-html allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Export WP Page to Static HTML/CSS: from n/a through <= 4.1.0. | |
| Analizada | Media (6.1) | 0.27% | — | Apostrophecms Sanitize-html | 8/9/2025 | 17/6/2026 | 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (`<a>`), allowing bypasses that contain different casings, whitespace characters, or hexadecimal encodings. | |
| Analizada | Media (6.1) | 0.27% | — | Apostrophecms Sanitize-html | 8/9/2025 | 17/6/2026 | `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into… | |
| Aplazada | Media (6.4) | 0.24% | — | Html Social Share ButtonsAI | 6/9/2025 | 17/6/2026 | The Html Social share buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zm_sh_btn' shortcode in all versions up to, and including, 2.1.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… |