Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
866 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.48% | — | Joomla! | 26/5/2026 | 24/7/2026 | An improper access check allows privilege escalation through the com_users batch task. | |
| Analizada | Alta (8.2) | 0.36% | — | Joomla! | 26/5/2026 | 24/7/2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | |
| Analizada | Alta (8.2) | 0.36% | — | Joomla! | 26/5/2026 | 24/7/2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | |
| Analizada | Media (5.9) | 0.49% | — | Joomla! | 26/5/2026 | 24/7/2026 | An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability. | |
| Analizada | Alta (7.5) | 0.56% | — | Joomla! | 26/5/2026 | 24/7/2026 | An improper validation of user-supplied input leads to a local file inclusion vulnerability. | |
| Analizada | Alta (8.6) | 0.51% | — | Joomla! | 26/5/2026 | 24/7/2026 | An improper access check allows unauthorized access to com_config webservice endpoints. | |
| Analizada | Media (6.9) | 0.45% | — | Joomla! | 26/5/2026 | 24/7/2026 | Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. | |
| Analizada | Media (6.9) | 0.45% | — | Joomla! | 26/5/2026 | 24/7/2026 | Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. | |
| Analizada | Media (4.6) | 0.14% | — | Joomla! | 26/5/2026 | 20/7/2026 | Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users. | |
| Analizada | Media (6.9) | 0.24% | — | Joomla! | 26/5/2026 | 24/7/2026 | Lack of output escaping leads to a XSS vector in the readmore links for com_content. | |
| Analizada | Media (6.9) | 0.24% | — | Joomla! | 26/5/2026 | 24/7/2026 | Lack of output escaping leads to a XSS vector in the content history component. | |
| Analizada | Media (6.9) | 0.24% | — | Joomla! | 26/5/2026 | 24/7/2026 | Lack of output escaping leads to a XSS vector in the multilingual associations component. | |
| Analizada | Media (6.9) | 0.24% | — | Joomla! | 26/5/2026 | 20/7/2026 | Lack of output escaping leads to a XSS vector in the feed modules. | |
| Aplazada | Alta (7.1) | 0.28% | — | Joomla Responsive PortfolioAI | 25/5/2026 | 24/7/2026 | Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers can inject malicious SQL code via the filter_type_id, filter_pid_id, and filter_search parameters in POST requests to extract… | |
| Aplazada | Media (5.3) | 0.13% | — | Joomla JomresAI | 23/5/2026 | 23/7/2026 | Joomla Component jomres 9.11.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information by tricking authenticated users into visiting malicious pages. Attackers can craft HTML forms targeting the account/index endpoint with hidden fields to change passwords, email… | |
| Aplazada | Alta (8.8) | 0.36% | — | Joomla EkrishtaAI | 23/5/2026 | 20/7/2026 | Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the username parameter. Attackers can submit POST requests to the login endpoint with SQL injection payloads in the username field… | |
| Aplazada | Alta (8.8) | 0.36% | — | JoomlaAIHarmistechnology EK RishtaAI | 23/5/2026 | 23/7/2026 | Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET requests to the user_detail view with malicious cid values containing SQL commands to extract sensitive… | |
| Aplazada | Media (5.3) | 0.16% | — | Joomla JoomocshopAI | 17/5/2026 | 17/6/2026 | Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML forms targeting account endpoints like /joomoc2/?route=account/edit and to modify user information or reset passwords… | |
| Aplazada | Alta (8.8) | 0.32% | — | Joomla EkrishtaAI | 17/5/2026 | 17/6/2026 | Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow attackers to inject malicious code through profile fields and POST parameters. Attackers can inject script payloads in profile information fields like Address that execute when users visit the profile,… | |
| Aplazada | Media (6.9) | 0.14% | — | Joomla JS JobsAI | 17/5/2026 | 17/6/2026 | Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without token validation. Attackers can craft malicious HTML forms targeting administrative endpoints like job.jobenforcedelete to delete job entries or modify component settings… | |
| Aplazada | Alta (7.1) | 0.27% | — | Joomla J2 JobsAI | 13/5/2026 | 17/6/2026 | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' values to extract sensitive database… | |
| Aplazada | Alta (7.1) | 0.27% | — | Joomla J2 JobsAI | 13/5/2026 | 17/6/2026 | Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Attackers can send POST requests to the administrator index with malicious 'sortby' values to extract sensitive database… | |
| Aplazada | Alta (8.7) | 0.72% | — | Joomla COM FabrikAI | 13/5/2026 | 17/6/2026 | Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET requests to the onAjax_files method with path traversal sequences to enumerate files in system directories outside the… | |
| Aplazada | Alta (8.8) | 0.27% | — | Joomla COM HdwplayerAI | 13/5/2026 | 17/6/2026 | Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwplayersearch parameter… | |
| Aplazada | Alta (8.8) | 0.31% | — | Balbooa Joomla Forms BuilderAI | 10/5/2026 | 25/7/2026 | Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in the 'id' field parameter to extract… |