Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
866 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.27% | — | JoomlaAIJoomsky JS JobsAI | 15/8/2025 | 17/6/2026 | A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands. | |
| Aplazada | Alta (8.5) | 0.32% | — | Dj-classifiedsAIJoomlaAI | 15/8/2025 | 17/6/2026 | A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands. | |
| Aplazada | Crítica (9.2) | 0.40% | — | Phoca CommanderAIJoomlaAI | 15/8/2025 | 17/6/2026 | An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. The issue allows code execution via the unzip feature. | |
| Aplazada | Crítica (9.4) | 0.41% | — | Joomla NO Boss TestimonialsAI | 28/7/2025 | 17/6/2026 | A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered. | |
| Aplazada | Crítica (9.4) | 0.41% | — | Joomla CommentboxAI | 28/7/2025 | 17/6/2026 | A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered. | |
| Aplazada | Alta (7) | 0.24% | — | Joomla CcommentAI | 23/7/2025 | 17/6/2026 | A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered. | |
| Aplazada | Alta (7) | 0.24% | — | Joomla ProfilesAI | 23/7/2025 | 17/6/2026 | A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered. | |
| Aplazada | Media (5.1) | 0.31% | — | Dj-reviewsAIJoomlaAI | 23/7/2025 | 17/6/2026 | A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered. | |
| Aplazada | Crítica (9.3) | 0.32% | — | JoomlaAIStackideas KomentoAI | 23/7/2025 | 17/6/2026 | A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to execute arbitrary SQL commands. | |
| Aplazada | Alta (8.5) | 0.30% | — | Joomla DJ FlyerAIJoomlaAI | 23/7/2025 | 17/6/2026 | A SQLi vulnerability in DJ-Flyer component 1.0-3.2 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL commands. | |
| Aplazada | Media (5.3) | 0.34% | — | Joomla RsblogAI | 18/7/2025 | 17/6/2026 | A stored XSS vulnerability in the RSBlog! component 1.11.6-1.14.5 Joomla was discovered. The issue allows remote authenticated users to inject arbitrary web script or HTML via the jform[tags_text] parameter. | |
| Aplazada | Media (5.1) | 0.36% | — | RsdirectoryAIJoomlaAI | 18/7/2025 | 17/6/2026 | A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component. | |
| Aplazada | Media (6.9) | 0.39% | — | JoomlaAIJoomla RsfilesAI | 18/7/2025 | 17/6/2026 | A DOS vulnerability in RSFiles! component 1.16.3-1.17.7 Joomla was discovered. The issue allows unauthenticated remote attackers to deny access to service via the search feature. | |
| Aplazada | Media (5.1) | 0.39% | — | Joomla RsmailAIJoomlaAI | 18/7/2025 | 17/6/2026 | A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla was discovered. The issue allows remote attackers to inject arbitrary web script or HTML via the crafted parameter. | |
| Aplazada | Alta (8.6) | 0.30% | — | Balbooa GalleryAIJoomlaAI | 18/7/2025 | 17/6/2026 | A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicious scripts in gallery items. | |
| Aplazada | Alta (8.6) | 0.26% | — | Balbooa FormsAIJoomlaAI | 18/7/2025 | 17/6/2026 | A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter. | |
| Aplazada | Alta (8.7) | 3.8% | 💥 Exploit | Joomla JS JobsAI | 18/7/2025 | 17/6/2026 | A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee application feature. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Joomla Articles CalendarAIJoomlaAI | 18/7/2025 | 17/6/2026 | A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Joomla Articles Good SearchAI | 18/7/2025 | 17/6/2026 | A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands. | |
| Aplazada | Alta (8.5) | 0.37% | — | Mojoomla WpgymAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPGYM allows SQL Injection. This issue affects WPGYM: from n/a through 65.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mojoomla School ManagementAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla School Management allows Reflected XSS. This issue affects School Management: from n/a through 92.0.0. | |
| Aplazada | Alta (7.1) | 0.26% | — | Mojoomla WpcrmAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPCRM - CRM for Contact form CF7 & WooCommerce wpcrm allows Reflected XSS.This issue affects WPCRM - CRM for Contact form CF7 & WooCommerce: from n/a through <= 3.2.0. | |
| Aplazada | Crítica (9.3) | 0.45% | — | Mojoomla School ManagementAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows Blind SQL Injection. This issue affects School Management: from n/a through 92.0.0. | |
| Aplazada | Alta (7.5) | 0.72% | — | Mojoomla School ManagementAIPHPAI | 17/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in mojoomla School Management allows PHP Local File Inclusion. This issue affects School Management: from n/a through 93.0.0. | |
| Aplazada | Alta (7.5) | 0.67% | — | Mojoomla WpgymAI | 17/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in mojoomla WPGYM allows PHP Local File Inclusion. This issue affects WPGYM: from n/a through 65.0. |