Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.50%—Razormist Online Discussion Forum Site16/6/202217/6/2026
Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_category, name.
ModificadaAlta (7.2)0.96%—Razormist Online Discussion Forum Site16/6/202217/6/2026
Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.
ModificadaMedia (4.8)0.56%—Fudforum6/6/202217/6/2026
FUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_title param in Page Manager in the Admin Control Panel.
ModificadaMedia (4.8)0.56%—Fudforum6/6/202217/6/2026
FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature.
ModificadaAlta (7.2)25%—Fudforum6/6/202217/6/2026
FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel.
ModificadaMedia (5.4)0.47%—Fudforum6/5/202217/6/2026
FUDforum 3.1.1 is vulnerable to Stored XSS.
ModificadaAlta (7.2)9.2%💥 ExploitSimplemachines Simple Machines Forum5/4/202217/6/2026
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's position is that administrators are intended to have the ability to modify themes, and can thus choose…
ModificadaAlta (8.8)1.5%—Asgaros Forum28/2/202217/6/2026
The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection
ModificadaCrítica (9.8)1.5%—Diyhi BBS Forum14/2/202217/6/2026
An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files.
ModificadaAlta (8.1)1.3%—Nim-lang DocutilsNim-lang Nimforum1/2/202217/6/2026
Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an include referencing a file local to the host operating system. Nimforum will render the file if able. This can also be done silently by using NimForum's post "preview"…
ModificadaAlta (7.2)1.5%—Asgaros Forum24/1/202217/6/2026
The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in a SQL statement when editing a forum, leading to an SQL injection issue
ModificadaMedia (5.3)8.4%💥 ExploitChronoengine Chronoforums12/1/202217/6/2026
ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.
ModificadaBaja (2.7)1.1%—Chronoengine Chronoforums12/1/202217/6/2026
ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.
ModificadaCrítica (9.8)1.2%—Oretnom23 Simple Forum/discussion System21/12/202117/6/2026
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability.
ModificadaMedia (4.8)0.70%—Asgaros Forum29/11/202117/6/2026
The Asgaros Forums WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the name parameter found in the ~/admin/tables/admin-structure-table.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including…
ModificadaCrítica (9.8)13%💥 ExploitAsgaros Forum8/11/202117/6/2026
The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic before using it in a SQL statement, leading to an unauthenticated SQL injection issue
ModificadaMedia (5.4)0.96%—Jforum4/9/202117/6/2026
ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature.
ModificadaMedia (5.4)0.45%—Codologic Codoforum9/7/202117/6/2026
A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Username' parameter.
ModificadaMedia (5.4)0.45%—Codologic Codoforum9/7/202117/6/2026
A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into the 'Page Title' parameter.
ModificadaMedia (5.4)0.51%—Codologic Codoforum9/7/202117/6/2026
A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into the 'Smiley Code' parameter.
ModificadaMedia (6.1)2.9%💥 ExploitGvectors Wpforo Forum6/7/202117/6/2026
The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica…
ModificadaMedia (6.1)0.58%—Vanillaforums Vanilla Forums22/6/202116/6/2026
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
ModificadaMedia (6.1)0.66%—Vanillaforums Vanilla Forums22/6/202116/6/2026
It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side.
ModificadaCrítica (9.8)4.9%—Codologic Codoforum12/5/202117/6/2026
A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authentication) to bypass the admin page via a leaked password-reset token of the admin. (As an admin, an attacker can upload a PHP shell and execute remote code on the operating system.)
ModificadaMedia (5.4)0.60%—Online Discussion Forum Project Online Discussion Forum19/4/202117/6/2026
The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated user can send messages to arbitrary users on the system that include javascript that will execute when viewing the messages page.
Orbitaley — Vulnerabilidades