Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
866 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.4) | 0.33% | — | Joomla! | 7/7/2026 | 9/7/2026 | An improper access check allows privileged users to overwrite media files without editing permissions. | |
| Analizada | Crítica (10) | 31% | ⚠ Explotación activa💥 Exploit | Joomlack Page Builder CK | 29/6/2026 | 24/7/2026 | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. | |
| Analizada | Media (6.3) | 0.28% | — | Joomlaworks K2 | 25/6/2026 | 28/6/2026 | The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php matches `\.php$` and executes them under the K2 web user. A K2 Author can upload a `shell.php`, then fetch `/media/k2/attachments/shell.php` and execute arbitrary PHP code in the web server's context. | |
| Analizada | Media (5.3) | 0.33% | — | Joomlaworks K2 | 25/6/2026 | 28/6/2026 | The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only renames image files (gif/jpg/jpeg/png/webp) to safe names — non-image files (including `.php`) are extracted as-is and remain executable via direct HTTP access. | |
| Analizada | Media (6.5) | 0.44% | — | Joomlaworks K2 | 25/6/2026 | 28/6/2026 | The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SITE/` and passed to `JFile::copy()`. `JPath::clean` does NOT strip `..`, and there is no allow-list of source paths. An Author can therefore copy `configuration.php` (or any other file readable by the… | |
| Analizada | Media (6.5) | 0.30% | — | Joomlaworks K2 | 25/6/2026 | 28/6/2026 | K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `profile.save` POST, can write arbitrary values into the `notes`, `image`, and `plugins` columns of their own row in the `#__k2_users` table… | |
| Analizada | Media (6.1) | 0.25% | — | Joomlaworks K2 | 25/6/2026 | 28/6/2026 | K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping. | |
| Analizada | Media (6.5) | 0.27% | — | Joomlaworks K2 | 25/6/2026 | 28/6/2026 | The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to address a `JFolder::delete()` call under `/media/k2/galleries/` | |
| Analizada | Baja (3.4) | 0.28% | — | Joomlaworks K2 | 25/6/2026 | 28/6/2026 | A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field contains a raw `<script>` tag; K2 stores it verbatim and renders it unescaped to any visitor of the article page. | |
| Analizada | Alta (8.8) | 0.48% | — | Joomlaboat Extra Search | 19/6/2026 | 19/8/2026 | Joomla! Component Extra Search 2.2.8 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the establename parameter. Attackers can send GET requests to index.php with the option=com_extrasearch parameter and malicious SQL in the… | |
| Analizada | Alta (8.8) | 0.43% | — | Extensions Joomla Payage | 19/6/2026 | 19/8/2026 | Joomla Payage 2.05 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the aid parameter. Attackers can send GET requests to index.php with malicious aid values in the make_payment task to extract sensitive database information… | |
| Analizada | Alta (8.8) | 0.46% | — | Joomboost Joomla Joomrecipe | 19/6/2026 | 19/8/2026 | Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests to the search endpoint to extract database information using boolean-based blind SQL injection techniques. | |
| Analizada | Alta (8.8) | 0.49% | — | Joomla Calendar Planner | 19/6/2026 | 19/8/2026 | Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id parameter to extract sensitive database… | |
| Analizada | Alta (8.8) | 0.49% | — | Joomlashack Osdownloads | 19/6/2026 | 19/8/2026 | Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_osdownloads&view=item&id=[SQL] to extract sensitive database… | |
| Aplazada | Alta (7.1) | 0.33% | — | Joomla COM JsjobsAI | 4/6/2026 | 22/7/2026 | Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requests to the job.savejob task with path traversal sequences in the field_2 parameter to delete arbitrary files accessible… | |
| Aplazada | Alta (8.8) | 0.23% | — | Mojoomla School ManagementAI | 3/6/2026 | 22/7/2026 | Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0. | |
| Aplazada | Alta (7.6) | 0.23% | — | Mojoomla School ManagementAI | 3/6/2026 | 22/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0. | |
| Aplazada | Alta (8.8) | 0.34% | — | Joomla JE Photo GalleryAI | 1/6/2026 | 22/7/2026 | Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com_jephotogallery… | |
| Analizada | Media (6.9) | 0.24% | — | Joomla! | 26/5/2026 | 20/7/2026 | Lack of input filtering leads to an XSS vector in the HTML filter code. | |
| Analizada | Alta (8.2) | 0.53% | — | Joomla! | 26/5/2026 | 24/7/2026 | An improper access check allows privelege escalation through the com_users group editing webservice endpoint. | |
| Analizada | Media (6.9) | 0.24% | — | Joomla! | 26/5/2026 | 24/7/2026 | Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. | |
| Modificada | Crítica (9.8) | 0.33% | — | Joomla! | 26/5/2026 | 24/7/2026 | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. | |
| Analizada | Alta (7.5) | 0.42% | — | Joomla! | 26/5/2026 | 24/7/2026 | The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. | |
| Analizada | Media (6.4) | 0.26% | — | Joomla! | 26/5/2026 | 24/7/2026 | An improper access check allowed low privileged users to edit the task types of existing scheduler tasks. | |
| Analizada | Media (5.3) | 0.42% | — | Joomla! | 26/5/2026 | 24/7/2026 | An improper access check allows privilege escalation through the com_users batch task. |