Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
824 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.25% | — | Rawchen EcmsAI | 28/12/2025 | 7/10/2026 | A vulnerability has been found in rawchen ecms up to b59d7feaa9094234e8aa6c8c6b290621ca575ded. Affected by this vulnerability is the function updateProductServlet of the file src/servlet/product/updateProductServlet.java of the component Add New Product Page. The manipulation of the argument productName leads to cross… | |
| Analizada | Baja (2.1) | 0.35% | — | Dedecms | 22/12/2025 | 17/6/2026 | A vulnerability was identified in DedeCMS up to 5.7.118. This impacts an unknown function of the file /freelist_main.php. The manipulation of the argument orderby leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Analizada | Alta (7.5) | 1.3% | — | Ritecms | 17/12/2025 | 17/6/2026 | A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file and default_page_language_file in the admin.php component | |
| Analizada | Media (6.8) | 0.19% | — | Ritecms | 17/12/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via a crafted POST request. | |
| Analizada | Alta (7.5) | 0.82% | — | Ritecms | 17/12/2025 | 17/6/2026 | Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal. | |
| Analizada | Media (6.1) | 0.27% | — | Ritecms | 17/12/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in RiteCMS v3.1.0 allows attackers to execute arbitrary code in the context of a user's browser via a crafted payload. | |
| Analizada | Media (5.3) | 0.14% | — | Ritecms | 17/12/2025 | 17/6/2026 | RiteCMS v3.1.0 was discovered to use insecure encryption to store passwords. | |
| Analizada | Alta (7.2) | 0.92% | — | Ritecms | 17/12/2025 | 5/10/2026 | RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_special_tags() function. | |
| Aplazada | Baja (2.1) | 0.34% | — | Yida Ecms Consulting Enterprise Management SystemAI | 14/9/2025 | 17/6/2026 | A vulnerability was found in Yida ECMS Consulting Enterprise Management System 1.0. This affects an unknown part of the file /login.do of the component POST Request Handler. The manipulation of the argument requestUrl results in cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.46% | — | SiemprecmsAI | 9/9/2025 | 17/6/2026 | A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admin/file_upload.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.33% | — | SiemprecmsAI | 9/9/2025 | 17/6/2026 | A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php. This manipulation of the argument name/userName causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (6.1) | 0.27% | — | Apostrophecms Sanitize-html | 8/9/2025 | 17/6/2026 | 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in anchor tags (`<a>`), allowing bypasses that contain different casings, whitespace characters, or hexadecimal encodings. | |
| Analizada | Media (6.1) | 0.27% | — | Apostrophecms Sanitize-html | 8/9/2025 | 17/6/2026 | `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into… | |
| Analizada | Baja (2) | 0.44% | 💥 Exploit | Concretecms Concrete CMS | 5/8/2025 | 17/6/2026 | Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page. Version 8 was not affected. A rogue admin could set up a malicious folder containing XSS to which users could be directed upon login. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score… | |
| Analizada | Media (4.8) | 0.33% | 💥 PoC | Concretecms Concrete CMS | 5/8/2025 | 17/6/2026 | Concrete CMS 9 to 9.4.2 and versions below 8.5.21 are vulnerable to Reflected Cross-Site Scripting (XSS) in the Conversation Messages Dashboard Page. Unsanitized input could cause theft of session cookies or tokens, defacement of web content, redirection to malicious sites, and (if victim is an admin), the execution… | |
| Analizada | Alta (8.7) | 3.7% | 💥 Exploit | Get-simple Getsimplecms | 25/7/2025 | 16/6/2026 | An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated users to upload arbitrary files without proper validation of MIME types or extensions. By uploading a .pht file containing PHP code, an attacker can bypass… | |
| Analizada | Baja (2) | 6.5% | 💥 PoC | Dedecms | 20/6/2025 | 17/6/2026 | A vulnerability was found in DedeCMS up to 5.7.2 and classified as critical. This issue affects some unknown processing of the file /include/dedetag.class.php of the component Template Handler. The manipulation of the argument notes leads to command injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.1) | 0.56% | — | Dedecms | 25/5/2025 | 17/6/2026 | A vulnerability was found in DedeCMS 5.7.117. It has been classified as critical. Affected is an unknown function of the file dede/sys_verifies.php?action=getfiles of the component Incomplete Fix CVE-2018-9175. The manipulation of the argument refiles leads to code injection. It is possible to launch the attack… | |
| Aplazada | Media (5.3) | 0.24% | — | LecmsAI | 28/4/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-profile-ajax-1 of the component Personal Information Page. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.30% | — | Lecms | 27/4/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-ajax-1 of the component Password Change Handler. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.52% | — | Lecms | 27/4/2025 | 17/6/2026 | A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin/view/default/user_set.htm. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Media (4.8) | 0.33% | — | LecmsAI | 19/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in dazhouda lecms up to 3.0.3. Affected by this issue is some unknown functionality of the file /admin of the component Edit Profile Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (4.3) | 0.41% | — | Bluecms Project Bluecms | 10/4/2025 | 17/6/2026 | BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request. | |
| Analizada | Media (5.1) | 0.19% | — | Concretecms Concrete CMS | 3/4/2025 | 17/6/2026 | Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Address attribute because addresses are not properly sanitized in the output when a country is not specified. Attackers are limited to individuals whom a site administrator has granted the ability to fill… | |
| Analizada | Media (4.8) | 0.33% | — | Concretecms Concrete CMS | 10/3/2025 | 17/6/2026 | Concrete CMS versions 9.0.0 through 9.3.9 are affected by a stored XSS in Folder Function.The "Add Folder" functionality lacks input sanitization, allowing a rogue admin to inject XSS payloads as folder names. The Concrete CMS security team gave this vulnerability a CVSS 4.0 Score of 4.8 with vector:… |