Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
866 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.23% | — | Regularlabs Joomla ExtensionsAIJoomlaAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers. | |
| Aplazada | Alta (7.5) | 0.42% | — | Regularlabs Regular Labs ExtensionsAIJoomlaAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored… | |
| Aplazada | Alta (8.8) | 0.20% | — | JoomlaAIRegularlabs Extension ManagerAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could… | |
| Aplazada | Alta (8.8) | 0.20% | — | Regularlabs ExtensionsAIJoomlaAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend… | |
| Aplazada | Crítica (9.4) | 0.38% | — | Joomla Page Builder CKAI | 22/7/2026 | 26/8/2026 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE. | |
| Aplazada | Crítica (9.1) | 0.40% | — | Joomlack Page Builder CKAI | 20/7/2026 | 23/7/2026 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views. | |
| Aplazada | Media (6.1) | 0.24% | — | HikashopAIJoomlaAI | 20/7/2026 | 23/7/2026 | Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect. | |
| Aplazada | Alta (8.7) | 0.52% | — | Themexpert Quix Page BuilderAIJoomlaAI | 20/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to a unauthenticated path traversal via form elements. Unauthenticated users frontend users are allowed traversal paths and read arbitrary files.… | |
| Aplazada | Alta (8.7) | 0.44% | — | Joomla ChronoformsAIJoomlaAI | 17/7/2026 | 23/7/2026 | Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability. | |
| Aplazada | Alta (8.7) | 0.40% | — | Themexpert Quix Page Builder PROAIJoomlaAI | 16/7/2026 | 23/7/2026 | Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection. | |
| Aplazada | Alta (8.7) | 0.44% | — | Joomla 4analyticsAI | 15/7/2026 | 23/7/2026 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in website takeover under some circumstances. | |
| Aplazada | Alta (8.6) | 0.44% | — | Joomla 4analyticsAI | 15/7/2026 | 23/7/2026 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS in relation to the AI analysis feature. | |
| Aplazada | Alta (8.7) | 0.40% | — | Digital-peak DP CalendarAIJoomlaAI | 15/7/2026 | 23/7/2026 | Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection. | |
| Modificada | Crítica (10) | 2.3% | 💥 Exploit | Rsjoomla Rsfiles! | 11/7/2026 | 23/7/2026 | Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. | |
| Analizada | Media (6.4) | 0.46% | — | Joomla! | 7/7/2026 | 9/7/2026 | An improper access check allows unauthorized users to create custom fields via webservices endpoints. | |
| Analizada | Media (6.4) | 0.42% | — | Joomla! | 7/7/2026 | 9/7/2026 | An improper access check allows unauthorized users to access com_privacy datasets. | |
| Analizada | Media (6.4) | 0.27% | — | Joomla! | 7/7/2026 | 9/7/2026 | An improper access check allows users to display a list of modules in the frontend. | |
| Analizada | Media (6.4) | 0.34% | — | Joomla! | 7/7/2026 | 9/7/2026 | An improper access check allows unauthorized users to access workflow stage and transition information. | |
| En análisis | Media (5.9) | 0.24% | — | Joomla! | 7/7/2026 | 9/7/2026 | Improper validation leads to a generic XSS vector in the language override feature. | |
| Analizada | Media (5.9) | 0.24% | — | Joomla! | 7/7/2026 | 9/7/2026 | Lack of escaping leads to an XSS vulnerability in the generic image output layout. | |
| Analizada | Media (5.9) | 0.24% | — | Joomla! | 7/7/2026 | 9/7/2026 | Lack of escaping leads to an XSS vulnerability in the update list view of com_installer. | |
| Analizada | Media (5.9) | 0.24% | — | Joomla! | 7/7/2026 | 9/7/2026 | Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components. | |
| Analizada | Media (5.9) | 0.24% | — | Joomla! | 7/7/2026 | 9/7/2026 | Lack of escaping leads to an XSS vulnerability in the file management view of com_templates. | |
| Analizada | Media (5.9) | 0.24% | — | Joomla! | 7/7/2026 | 9/7/2026 | Lack of validation leads to an XSS vulnerability in the MFA management views. | |
| Analizada | Media (6.4) | 0.42% | — | Joomla! | 7/7/2026 | 9/7/2026 | An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible. |