Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
866 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.23% | — | Joomla HikashopAI | 9/4/2026 | 26/9/2026 | Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, from_task, or… | |
| Aplazada | Media (5.1) | 0.23% | — | Joomla SolidresAI | 9/4/2026 | 26/9/2026 | Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters including show, reviews, type_id, distance, facilities, categories, prices, location, and Itemid. Attackers can craft malicious URLs… | |
| Aplazada | Media (5.1) | 0.19% | — | Joomla VirtuemartAIVirtuemart Shopping CartAI | 9/4/2026 | 26/9/2026 | Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft malicious URLs containing script payloads in the keyword parameter of the product-variants endpoint to execute… | |
| Aplazada | Media (5.1) | 0.19% | — | Joomla Jlex ReviewAI | 9/4/2026 | 26/9/2026 | Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers when clicked, enabling session hijacking… | |
| Analizada | Alta (8.6) | 0.40% | — | Joomla! | 1/4/2026 | 17/6/2026 | An improper access check allows unauthorized access to webservice endpoints. | |
| Analizada | Alta (8.6) | 0.45% | — | Joomla! | 1/4/2026 | 17/6/2026 | Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism. | |
| Analizada | Media (5.9) | 0.19% | — | Joomla! | 1/4/2026 | 17/6/2026 | Lack of output escaping for article titles leads to XSS vectors in various locations. | |
| Analizada | Media (5.9) | 0.22% | — | Joomla! | 1/4/2026 | 17/6/2026 | Lack of output escaping leads to a XSS vector in the multilingual associations component. | |
| Analizada | Media (6.9) | 0.34% | — | Joomla! | 1/4/2026 | 17/6/2026 | Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint. | |
| Analizada | Media (6.3) | 0.25% | — | Joomla! | 1/4/2026 | 17/6/2026 | The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was potentially unexpected by 3rd party developers. | |
| Aplazada | Alta (7.1) | 0.18% | — | Rsjoomla RsfirewallAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RSJoomla! RSFirewall! rsfirewall allows Stored XSS.This issue affects RSFirewall!: from n/a through <= 1.1.45. | |
| Pendiente de análisis | Crítica (9.8) | 0.80% | — | Joomla COM Mb24sysapiAI | 23/3/2026 | 17/6/2026 | Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383. | |
| Aplazada | Crítica (9.5) | 1.6% | 💥 PoC | JoomlaAITassos FrameworkAI | 20/2/2026 | 17/6/2026 | The vulnerability was rooted in how the Tassos Framework plugin handled specific AJAX requests through Joomla’s com_ajax entry point. Under certain conditions, internal framework functionality could be invoked without proper restriction. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Mojoomla WpchurchAI | 7/1/2026 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.This issue affects WPCHURCH: from n/a through 2.7.0. | |
| Aplazada | Alta (8.1) | 0.49% | — | Mojoomla WpchurchAI | 6/1/2026 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mojoomla WPCHURCH allows PHP Local File Inclusion.This issue affects WPCHURCH: from n/a through 2.7.0. | |
| Analizada | Media (5.9) | 0.36% | — | Joomla! | 6/1/2026 | 7/10/2026 | Lack of output escaping leads to a XSS vector in the pagebreak plugin. | |
| Analizada | Media (5.9) | 0.36% | — | Joomla! | 6/1/2026 | 7/10/2026 | Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags. | |
| Aplazada | Media (5.4) | 0.12% | — | JdownloadsAIJoomlaAI | 28/10/2025 | 17/6/2026 | Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered. | |
| Aplazada | Media (6.1) | 0.20% | — | VirtuemartAIJoomlaAI | 25/10/2025 | 17/6/2026 | A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Joomla MOD Vvisit CounterAI | 3/10/2025 | 17/6/2026 | SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retrieve database content via the ‘cip_vvisitcounter’ cookie at all endpoints where the plugin counts visits. | |
| Aplazada | Crítica (9.9) | 0.37% | — | Mojoomla School ManagementAI | 31/8/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Mojoomla School Management allows Upload a Web Shell to a Web Server.This issue affects School Management: from n/a through 1.93.1 (02-07-2025). | |
| Aplazada | Media (6.5) | 0.23% | — | Mojoomla School ManagementAI | 26/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Mojoomla School Management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects School Management: from n/a through 93.2.0. | |
| Aplazada | Alta (8.5) | 0.31% | — | Joomla Quantum ManagerAI | 25/8/2025 | 17/6/2026 | A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. File names are not properly escaped. | |
| Aplazada | Alta (8.5) | 0.31% | — | Joomla Quantum ManagerAI | 25/8/2025 | 17/6/2026 | A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. The SVG upload feature does not sanitize uploads. | |
| Aplazada | Alta (8.1) | 0.66% | — | Joomla EventlistAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ovatheme eventlist eventlist allows PHP Local File Inclusion.This issue affects eventlist: from n/a through <= 1.9.2. |