Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
1468 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.8) | 0.29% | — | Wikimedia Mediawiki TemplatesandboxAI | 25/9/2026 | 28/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Pendiente de análisis | Media (6.9) | 0.27% | 💥 PoC | Mediawiki CargoAI | 25/9/2026 | 29/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4. | |
| Pendiente de análisis | Media (6.9) | 0.27% | 💥 PoC | Mediawiki CargoAI | 25/9/2026 | 29/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4. | |
| Pendiente de análisis | Media (6.9) | 0.27% | 💥 PoC | Mediawiki CargoAI | 25/9/2026 | 29/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4. | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Wikimedia ThanksAI | 25/9/2026 | 28/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension allows Stored XSS. This issue affects Mediawiki - Thanks Extension: from * before 1.43.10/1.45.5/1.46.1. | |
| Pendiente de análisis | Media (5.5) | 0.27% | 💥 PoC | Wikimedia CirrussearchAI | 24/9/2026 | 24/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. This issue affects Mediawiki - CirrusSearch extension through 1.46.0. | |
| Pendiente de análisis | Baja (2.9) | 0.23% | 💥 PoC | Wikimedia Mediawiki Wikilambda ExtensionAI | 23/9/2026 | 24/9/2026 | Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Windows allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - WikiLambda Extension: before 1.47.0. | |
| Pendiente de análisis | Media (6.1) | 0.33% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. In versions 7.0.0 through 7.1.0, `Special:Ask` accepts a `cursor` query parameter for keyset pagination (added in 7.0.0). The token is decoded by `CursorEncoder`, which is an **unsigned**… | |
| Pendiente de análisis | Media (6.1) | 0.26% | — | MediawikiAISemantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, query debug output (`format=debug`, or the `debug` request parameter on `Special:Ask`) is assembled by `SMW\Query\DebugFormatter` and emitted as raw HTML. Several of… | |
| Pendiente de análisis | Media (6.1) | 0.25% | — | MediawikiAISemantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `Special:URIResolver` resolves its user-controlled subpage to a MediaWiki title and issues an HTTP 303 redirect to `$title->getFullURL()` without validating the… | |
| Pendiente de análisis | Media (6.1) | 0.26% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when the `value` parameter was reflected back into rendered output and error messaging paths without enough output-context encoding. Version 7.2.0 fixes the issue. | |
| Pendiente de análisis | Media (6.1) | 0.26% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 23/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `sep` was inserted verbatim into HTML cell joins. This made it possible to inject HTML through the separator value. Version 7.2.0 fixes the issue. | |
| Pendiente de análisis | Media (6.1) | 0.26% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, when `headers=plain`, table header text was emitted into `<th>` via a raw HTML path. User-controlled `mainlabel` content could therefore become executable HTML. Version… | |
| Pendiente de análisis | Alta (8.6) | 0.29% | — | Semantic-mediawiki Semantic MediawikiAI | 18/9/2026 | 24/9/2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Versions starting in 3.1.0 and prior to 7.0.0 insert the unsanitized value of a data attribute into the DOM as HTML, allowing for stored XSS through wikitext. Version 7.0.0 patches the issue. | |
| Aplazada | Crítica (9.9) | 0.64% | — | Xwiki RenderingAI | 18/9/2026 | 24/9/2026 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or any other document can execute arbitrary script macros including Groovy and… | |
| Pendiente de análisis | Alta (8.6) | 0.45% | — | Requarks Wiki.jsAI | 16/9/2026 | 24/9/2026 | Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated pages with matching prefixes, bypassing intended access controls. | |
| Pendiente de análisis | Alta (7.1) | 0.41% | — | JS WikiAI | 16/9/2026 | 24/9/2026 | Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img elements with the prefetch-candidate class to make the server request internal… | |
| Pendiente de análisis | Media (5.3) | 0.37% | — | Requarks Wiki.jsAI | 16/9/2026 | 24/9/2026 | Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve restricted page metadata including titles, descriptions, paths, and tag… | |
| Aplazada | Alta (7.5) | 0.49% | — | Mediawiki EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled, includes/EmbedService/EmbedHtmlFormatter.php places JSON… | |
| Aplazada | Alta (8.6) | 0.48% | — | Mediawiki EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/EmbedService/EmbedHtmlFormatter.php passes the user-supplied class value directly to… | |
| Pendiente de análisis | Alta (7.1) | 0.77% | — | Xwiki PlatformAI | 15/9/2026 | 30/9/2026 | XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API allows a user who can edit a page to change that page's rights without executing the normal document-saving authorization checks. The user can grant script right and then execute… | |
| Aplazada | Alta (8.7) | 0.51% | — | Deepwiki-openAI | 14/9/2026 | 23/9/2026 | DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including Python, JavaScript,… | |
| Aplazada | Alta (8.2) | 1.1% | — | Xwiki PlatformAIEclipse JettyAIApache TomcatAI | 14/9/2026 | 30/9/2026 | XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix when Jetty 12 or later decodes the request path. The affected lookup is replaced… | |
| Pendiente de análisis | Baja (3.1) | 0.24% | — | Mediawiki ProofreadpageAI | 14/9/2026 | 16/9/2026 | An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables. | |
| Pendiente de análisis | Media (5.4) | 0.21% | — | Mediawiki MassmessageAIMediawikiAI | 14/9/2026 | 28/9/2026 | An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS. |