Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.83% | — | Getgrav Grav-plugin-apiAI | 15/7/2026 | 15/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::validateFileExtension() inspects only the final file extension via pathinfo($filename, PATHINFO_EXTENSION), so a user with api.media.write permission can upload a file… | |
| Aplazada | Media (5.1) | 0.26% | — | Getgrav GravAI | 15/7/2026 | 15/7/2026 | Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page content before Twig processing. When Twig content processing is enabled (twig_content.process_enabled: true), an attacker with page-write API permission can use Twig's string… | |
| Aplazada | Media (6.9) | 0.33% | — | Getgrav Grav-plugin-apiAI | 15/7/2026 | 15/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim and therefore cannot be revoked server-side. Unlike refresh tokens, access tokens remain valid for their full lifetime (default 1 hour)… | |
| Aplazada | Crítica (9.4) | 0.42% | — | Getgrav Grav-plugin-apiAI | 15/7/2026 | 15/7/2026 | The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/forgot-password endpoint. The sanitizeHttpUrl() function only checks that the URL scheme is http/https and never verifies the host against the server's own origin, so an… | |
| Aplazada | Alta (7.1) | 0.44% | — | Getgrav GravAI | 15/7/2026 | 15/7/2026 | Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed size declared in each entry's ZIP central-directory header (ZipArchive::statIndex()['size']) and rejects archives exceeding system.gpm.archive.max_uncompressed_size before… | |
| Aplazada | Alta (8.7) | 1.1% | — | Getgrav Grav-plugin-flex-objectsAIGetgrav GravAI | 15/7/2026 | 15/7/2026 | The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin passes user-controlled frontmatter values (page.header.flex.collection.title or… | |
| Aplazada | Alta (7.6) | 0.38% | — | Hannan Persian Gravity FormsAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم فارسی persian-gravity-forms allows Blind SQL Injection.This issue affects گرویتی فرم فارسی: from n/a through <= 3.0.2. | |
| Analizada | Media (6.5) | 0.49% | — | Apache Gravitino | 13/7/2026 | 13/7/2026 | Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs. A vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 through 1.2.1. Users are recommended to upgrade to version 1.3.0, which… | |
| Analizada | Crítica (9.1) | 0.60% | — | Apache Gravitino | 13/7/2026 | 13/7/2026 | URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue. | |
| Aplazada | Alta (8.7) | 0.36% | — | Getgrav Grav-plugin-admin2AIGetgrav GravAI | 11/7/2026 | 13/7/2026 | The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned in every unauthenticated response and discloses the server URL, API prefix, admin base path, runtime… | |
| Modificada | Media (6.9) | 0.60% | — | Getgrav Grav | 10/7/2026 | 10/7/2026 | Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::extractTo without limits on uncompressed size, entry count, or directory depth.… | |
| Aplazada | Alta (8.7) | 0.36% | — | Getgrav Grav-plugin-adminAI | 10/7/2026 | 10/7/2026 | grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.52 and earlier, an authenticated attacker with admin.users permission can change the password of any user account, including the super administrator, by sending a direct POST request to… | |
| Aplazada | Media (5.1) | 0.50% | — | Grav-plugin-databaseAI | 10/7/2026 | 13/7/2026 | grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by directly concatenating user-configurable YAML values from fields such as host, dbname, charset, server, database, directory, and filename without sanitization or validation, allowing an administrator… | |
| Aplazada | Crítica (9.2) | 0.53% | — | Grav-plugin-databaseAI | 10/7/2026 | 10/7/2026 | grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a raw SQL query string without sanitization, escaping, quoting, or whitelisting, allowing attacker-controlled table names passed by consuming plugin or developer code to… | |
| Aplazada | Media (4.8) | 0.31% | — | Getgrav GravAI | 10/7/2026 | 10/7/2026 | Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media attribute action (CVE-2026-42841) leaves the sibling MediaObjectTrait::style method reachable through the same Markdown excerpt-action pipeline, allowing an editor to save Markdown image style… | |
| Aplazada | Media (6.8) | 0.27% | — | Getgrav GravAI | 10/7/2026 | 14/7/2026 | Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator password hash and user/config with site configuration, through the backup download… | |
| Aplazada | Alta (8.7) | 0.52% | — | Getgrav GravAI | 10/7/2026 | 10/7/2026 | Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust server memory and CPU by requesting image derivatives with oversized dimensions through URL query image actions such as forceResize in Grav::fallbackUrl, which passes request parameters to ImageMedium… | |
| Aplazada | Media (5.1) | 0.24% | — | Getgrav Grav-plugin-apiAI | 10/7/2026 | 10/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1/media endpoint. The HandlesMediaUploads::processUploadedFile() method validates only the file extension and never invokes Security::sanitizeSVG(), so an authenticated attacker with the… | |
| Aplazada | Alta (7.1) | 0.44% | — | Getgrav GravAI | 10/7/2026 | 10/7/2026 | Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompressed size, file count, and nesting depth. Attackers can supply a crafted ZIP archive that expands to fill available disk space, causing denial of service by exhausting storage resources. | |
| Aplazada | Alta (7.1) | 0.41% | — | Getgrav GravAI | 10/7/2026 | 10/7/2026 | Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to write to user/pages) to exfiltrate configuration secrets. Although the sandbox replaces the 'config' variable with a redacted facade and strips Config::get/toArray from the method allowlist, the raw… | |
| Aplazada | Media (4.8) | 0.37% | — | Getgrav GravAI | 8/7/2026 | 8/7/2026 | Grav before 2.0.0 (affected through 2.0.0-rc.9 and the 2.0 branch) contains a stored CSS injection vulnerability in the Markdown image resize() media action. Prior media hardening rejects direct ?style= payloads and unsafe attribute() fallbacks, but the resize() action in Excerpts::processMediaActions() writes… | |
| Aplazada | Alta (8.7) | 0.45% | — | Getgrav GravAI | 8/7/2026 | 8/7/2026 | Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-Allow-Origin: *, allowing unauthenticated attackers to make fully authenticated cross-origin API requests from any malicious website. Attackers who obtain a leaked JWT token from access logs,… | |
| Aplazada | Media (5.3) | 0.44% | — | Getgrav Grav-plugin-apiAIGetgrav GravAI | 8/7/2026 | 8/7/2026 | The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrestricted file upload vulnerability in the avatar upload endpoint (/api/v1/users/user/avatar). The endpoint validates only the client-declared MIME type (getClientMediaType) beginning with 'image/' and does not inspect the actual file content or… | |
| Aplazada | Crítica (9.1) | 1.5% | 💥 Exploit | Apache GravitinoAIH2AI | 8/7/2026 | 8/7/2026 | Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter. Vulnerability in Apache Gravitino. This issue affects Apache Gravitino: before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the… | |
| Aplazada | Crítica (9.3) | 2.5% | — | Getgrav GravAI | 30/6/2026 | 1/7/2026 | Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowed classes, enabling PHP object injection and, via a gadget chain, arbitrary code… |