Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.55% | — | Grav CMSAI | 3/8/2026 | 31/8/2026 | Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argument to RocketTheme\Toolbox\ResourceLocator\UniformResourceLocator::findResource(). Because the file:// scheme branch only lexically collapses '..' segments without a realpath/containment check,… | |
| Aplazada | Alta (8.6) | 0.41% | — | Getgrav GravAI | 3/8/2026 | 31/8/2026 | Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dynamic-field directives because Blueprint::isSafeDynamicCall() only applies its dangerous-callable denylist to strings that do not contain '::'. An account with only page-editing rights… | |
| Aplazada | Alta (7.1) | 0.37% | — | Getgrav Grav-plugin-formAI | 3/8/2026 | 31/8/2026 | The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, and Grav::redirect() accepts external URLs without origin validation. When a form blueprint defines a redirect… | |
| Aplazada | Media (6.3) | 0.24% | — | Grav Login PluginAI | 29/7/2026 | 30/7/2026 | Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php where the findTriplet() method fails to properly validate Remember Me token timestamps. Attackers with a captured Remember Me cookie can authenticate indefinitely instead of the configured timeout… | |
| Aplazada | Alta (8.7) | 0.52% | — | Getgrav Grav API PluginAI | 23/7/2026 | 28/8/2026 | Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can create invitation records with elevated group membership, and when accepted,… | |
| Aplazada | Alta (7.1) | 0.48% | — | Getgrav Grav-plugin-apiAI | 23/7/2026 | 28/8/2026 | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), which strips leading periods but does not neutralize '/' or '..' segments. An… | |
| Aplazada | Alta (8.2) | 0.33% | — | Grav API PluginAI | 23/7/2026 | 28/8/2026 | Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and… | |
| Aplazada | Alta (8.7) | 1.3% | — | Getgrav GravAI | 23/7/2026 | 23/7/2026 | Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_user_func_array() on attacker-influenced input, validating only that the target is callable (is_callable()) without restricting dangerous… | |
| Pendiente de análisis | Alta (8.7) | 0.44% | — | Getgrav Grav LoginAI | 22/7/2026 | 22/7/2026 | The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the update_user task). Unlike the registration handler, this handler does not strip privilege fields ('groups','access') from user-submitted form data… | |
| Aplazada | Crítica (9.3) | 2.5% | 💥 Exploit | Getgrav GravAI | 21/7/2026 | 22/7/2026 | Grav 2.0.4 (fixed in 2.0.7) contains a remote code execution vulnerability in Blueprint::dynamicData() (system/src/Grav/Common/Data/Blueprint.php), which passes a Class::method callable string and its arguments directly to call_user_func_array() without any allowlist. Because the form plugin routes page frontmatter… | |
| Aplazada | Alta (8.7) | 0.37% | — | Getgrav Grav-plugin-apiAI | 21/7/2026 | 23/7/2026 | The Grav api plugin (grav-plugin-api) before 1.0.8 fails to properly authorize API key generation and revocation: the plugin intercepts the apiKeyGenerate/apiKeyRevoke admin tasks before the account-management ACL runs and authorizes the caller on only the admin.login permission (the baseline permission held by every… | |
| Aplazada | Media (5.1) | 0.26% | — | Getgrav GravAI | 21/7/2026 | 23/7/2026 | Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers where the XSS detection scan only matches payloads containing literal angle brackets, allowing shortcode parameters to bypass validation. Attackers with admin.pages permission can inject malicious JavaScript through… | |
| Aplazada | Media (6.3) | 0.69% | — | Grav Scheduler-webhookAI | 20/7/2026 | 21/7/2026 | Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. Attackers can send a single unauthenticated POST request to the scheduler webhook… | |
| Aplazada | Alta (7.1) | 0.34% | — | Getgrav Grav-plugin-apiAI | 17/7/2026 | 17/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS configuration on all responses, including authenticated endpoints and preflight (OPTIONS) responses. Because the plugin accepts credentials via the Authorization and X-API-Token headers (set… | |
| Aplazada | Alta (8.2) | 0.43% | — | Getgrav Grav-plugin-apiAI | 17/7/2026 | 23/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are logged verbatim in web server access logs, leaked via the Referer header,… | |
| Aplazada | Media (6) | 0.44% | — | Getgrav GravAI | 17/7/2026 | 21/7/2026 | Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content sandbox. When Twig processing in page content is enabled (security.twig_content.process_enabled: true, disabled by default), an authenticated page… | |
| Aplazada | Baja (2.3) | 0.14% | — | Getgrav Grav-plugin-loginAI | 17/7/2026 | 17/7/2026 | grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which regenerates and persists a new TOTP secret for the authenticated session user without any anti-CSRF nonce or Origin/Referer check. Because Grav core dispatches the task from… | |
| Aplazada | Baja (2.3) | 0.29% | — | Getgrav GravAIGetgrav Flex-objectsAI | 17/7/2026 | 17/7/2026 | Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less directories. Attackers with api.access credentials can create, read, update,… | |
| Aplazada | Alta (8.4) | 0.40% | — | Getgrav GravAI | 17/7/2026 | 23/7/2026 | Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// URLs. Attackers can trigger webhook events to read local files, access process information, or pivot to internal services via… | |
| Aplazada | Alta (8.7) | 0.44% | — | Getgrav Grav-plugin-apiAI | 17/7/2026 | 17/7/2026 | grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to escalate to super-admin. Attackers can mint API keys bound to super-admin accounts or strip 2FA from super-admin users to achieve full instance… | |
| Aplazada | Crítica (9.1) | 0.45% | — | Getgrav GravAI | 17/7/2026 | 17/7/2026 | Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the pending TOTP challenge window. Attackers who know the victim's password can call this task without a CSRF nonce to overwrite the… | |
| Aplazada | Alta (8.6) | 0.39% | — | Getgrav Grav-plugin-apiAI | 17/7/2026 | 21/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a restricted scopes array, but the ApiKeyAuthenticator class never reads or enforces these scopes. It loads and returns the owning user's full account object, so a key created with limited scopes… | |
| Aplazada | Alta (8.7) | 0.48% | — | Getgrav GravAI | 17/7/2026 | 17/7/2026 | Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access to sensitive file types (.yaml, .php, .json, etc.) lack the [NC] flag, making extension matching case-sensitive. On case-insensitive filesystems (Windows/NTFS, macOS/HFS+, or Docker volume mounts), an… | |
| Aplazada | Alta (7.5) | 0.93% | — | Gravityforms Gravity FormsAI | 15/7/2026 | 15/7/2026 | The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Aplazada | Alta (7.2) | 0.46% | — | Getgrav GravAINeos FormAI | 15/7/2026 | 15/7/2026 | Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against path traversal before Twig processing but never re-validated after rendering. Attackers can submit form data containing path traversal sequences that are processed through… |