Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.50% | — | Razormist Online Discussion Forum Site | 16/6/2022 | 17/6/2026 | Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_category, name. | |
| Modificada | Alta (7.2) | 0.96% | — | Razormist Online Discussion Forum Site | 16/6/2022 | 17/6/2026 | Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team. | |
| Modificada | Media (4.8) | 0.56% | — | Fudforum | 6/6/2022 | 17/6/2026 | FUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_title param in Page Manager in the Admin Control Panel. | |
| Modificada | Media (4.8) | 0.56% | — | Fudforum | 6/6/2022 | 17/6/2026 | FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature. | |
| Modificada | Alta (7.2) | 25% | — | Fudforum | 6/6/2022 | 17/6/2026 | FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel. | |
| Modificada | Media (5.4) | 0.47% | — | Fudforum | 6/5/2022 | 17/6/2026 | FUDforum 3.1.1 is vulnerable to Stored XSS. | |
| Modificada | Alta (7.2) | 9.2% | 💥 Exploit | Simplemachines Simple Machines Forum | 5/4/2022 | 17/6/2026 | SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's position is that administrators are intended to have the ability to modify themes, and can thus choose… | |
| Modificada | Alta (8.8) | 1.5% | — | Asgaros Forum | 28/2/2022 | 17/6/2026 | The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection | |
| Modificada | Crítica (9.8) | 1.5% | — | Diyhi BBS Forum | 14/2/2022 | 17/6/2026 | An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files. | |
| Modificada | Alta (8.1) | 1.3% | — | Nim-lang DocutilsNim-lang Nimforum | 1/2/2022 | 17/6/2026 | Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an include referencing a file local to the host operating system. Nimforum will render the file if able. This can also be done silently by using NimForum's post "preview"… | |
| Modificada | Alta (7.2) | 1.5% | — | Asgaros Forum | 24/1/2022 | 17/6/2026 | The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in a SQL statement when editing a forum, leading to an SQL injection issue | |
| Modificada | Media (5.3) | 8.4% | 💥 Exploit | Chronoengine Chronoforums | 12/1/2022 | 17/6/2026 | ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files. | |
| Modificada | Baja (2.7) | 1.1% | — | Chronoengine Chronoforums | 12/1/2022 | 17/6/2026 | ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files. | |
| Modificada | Crítica (9.8) | 1.2% | — | Oretnom23 Simple Forum/discussion System | 21/12/2021 | 17/6/2026 | Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability. | |
| Modificada | Media (4.8) | 0.70% | — | Asgaros Forum | 29/11/2021 | 17/6/2026 | The Asgaros Forums WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the name parameter found in the ~/admin/tables/admin-structure-table.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including… | |
| Modificada | Crítica (9.8) | 13% | 💥 Exploit | Asgaros Forum | 8/11/2021 | 17/6/2026 | The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue | |
| Modificada | Media (5.4) | 0.96% | — | Jforum | 4/9/2021 | 17/6/2026 | ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature. | |
| Modificada | Media (5.4) | 0.45% | — | Codologic Codoforum | 9/7/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Username' parameter. | |
| Modificada | Media (5.4) | 0.45% | — | Codologic Codoforum | 9/7/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into the 'Page Title' parameter. | |
| Modificada | Media (5.4) | 0.51% | — | Codologic Codoforum | 9/7/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into the 'Smiley Code' parameter. | |
| Modificada | Media (6.1) | 2.9% | 💥 Exploit | Gvectors Wpforo Forum | 6/7/2021 | 17/6/2026 | The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica… | |
| Modificada | Media (6.1) | 0.58% | — | Vanillaforums Vanilla Forums | 22/6/2021 | 16/6/2026 | It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher. | |
| Modificada | Media (6.1) | 0.66% | — | Vanillaforums Vanilla Forums | 22/6/2021 | 16/6/2026 | It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side. | |
| Modificada | Crítica (9.8) | 4.9% | — | Codologic Codoforum | 12/5/2021 | 17/6/2026 | A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authentication) to bypass the admin page via a leaked password-reset token of the admin. (As an admin, an attacker can upload a PHP shell and execute remote code on the operating system.) | |
| Modificada | Media (5.4) | 0.60% | — | Online Discussion Forum Project Online Discussion Forum | 19/4/2021 | 17/6/2026 | The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated user can send messages to arbitrary users on the system that include javascript that will execute when viewing the messages page. |