Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 1.00% | — | Fourkitchens Recent Comments | 25/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Recent Comments module 5.x through 5.x-1.2 and 6.x through 6.x-1.0 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a "custom block title interface." | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Onnogroen COM Webeecomment | 22/2/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) color, (2) img, or (3) url BBCode tags in unspecified vectors. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Onnogroen COM Webeecomment | 22/2/2010 | 16/6/2026 | SQL injection vulnerability in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a default action to index2.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 9.8% | 💥 Exploit | Plohni Advanced Comment System | 18/1/2010 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the ACS_path parameter to (1) index.php and (2) admin.php in advanced_comment_system/. NOTE: this might only be a vulnerability when the administrator has not followed… | |
| Modificada | Media (5) | 1.2% | — | Kristof DE Jaeger Commentreference | 31/12/2009 | 16/6/2026 | The CCK Comment Reference module 5.x before 5.x-1.2 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to bypass intended access restrictions and read comments by using the autocomplete path. | |
| Modificada | Media (5) | 1.4% | — | Dave Reid CommentrssGabor Hojtsy Commentrss | 6/10/2009 | 16/6/2026 | Comment RSS 5.x before 5.x-2.2 and 6.x before 6.x-2.2, a module for Drupal, does not properly enforce permissions when a link is added to the RSS feed, which allows remote attackers to obtain the node title and possibly other sensitive content by reading the feed. | |
| Modificada | Media (4.3) | 1.1% | — | UDO VON Eynern Modern Guest Book Commenting System | 17/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Modern Guestbook / Commenting System (ve_guestbook) extension 2.7.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Drupal CCK Comment Reference | 20/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the CCK comment reference module 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via certain comment titles associated with a node edit form. | |
| Modificada | Media (4.3) | 1.0% | — | Scriptsez EZ PHP Comment | 6/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ScriptsEz Ez PHP Comment allows remote attackers to inject arbitrary web script or HTML via the name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 0.58% | — | Drupal Comment Mail | 2/3/2009 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Comment Mail 5.x before 5.x-1.1, a module for Drupal, allow remote attackers to hijack the authentication of administrators. | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 Eluna Page Comments Extension | 31/12/2008 | 16/6/2026 | SQL injection vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Typo3 Eluna Page Comments Extension | 31/12/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the eluna Page Comments (eluna_pagecomments) extension 1.1.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Pressography WP Comment Remix Plugin | 24/10/2008 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the wpcr_do_options_page function in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to perform unauthorized actions as administrators via a request that sets the wpcr_hidden_form_input parameter. | |
| Modificada | Media (4.3) | 2.1% | — | Pressography WP Comment Remix Plugin | 24/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in wpcommentremix.php in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) replytotext, (2) quotetext, (3) originallypostedby, (4) sep, (5) maxtags, (6) tagsep, (7) tagheadersep, (8) taglabel, and (9)… | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Pressography WP Comment Remix Plugin | 24/10/2008 | 16/6/2026 | SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the p parameter. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | PHP Jabbers Post Comment | 23/10/2008 | 16/6/2026 | PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie to "logged." | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joomla COM Yvcomment | 13/6/2008 | 16/6/2026 | SQL injection vulnerability in the yvComment (com_yvcomment) component 1.16.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the ArticleID parameter in a comment action to index.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Azrul JOM Comment | 18/4/2008 | 16/6/2026 | SQL injection vulnerability in the Jom Comment 2.0 build 345 component for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Crítica (9.8) | 2.9% | 💥 Exploit | Oocomments | 25/3/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ooComments 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the PathToComment parameter for (1) classes/class_admin.php and (2) classes/class_comments.php. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Joomla COM CommentsMambo COM CommentsPhil Taylor CommentsPhil Taylor Review Script | 14/2/2008 | 16/6/2026 | SQL injection vulnerability in Phil Taylor Comments (com_comments, aka Review Script) 0.5.8.5g and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.4) | 2.5% | — | Drupal Comment Upload Module | 5/2/2008 | 16/6/2026 | The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows remote attackers to bypass upload validation, and upload arbitrary files and possibly execute arbitrary code, via unspecified vectors. | |
| Modificada | Media (4.3) | 1.9% | — | Wordpress Math Comment Spam Protection Plugin | 10/1/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to… | |
| Modificada | Media (4.3) | 1.9% | — | Wordpress Math Comment Spam Protection Plugin | 10/1/2008 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in math-comment-spam-protection.php in the Math Comment Spam Protection 2.1 and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) mcsp_opt_msg_no_answer or (2) mcsp_opt_msg_wrong_answer parameter to… | |
| Modificada | Media (6.8) | 0.99% | — | Akocomment | 5/7/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in akocomment allow remote attackers to execute arbitrary SQL commands via the (1) acparentid or (2) acitemid parameter to an unspecified component, different vectors than CVE-2006-1421. | |
| Modificada | Alta (7.5) | 1.6% | — | Arthur Konze Webdesign Akocomment | 21/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in akocomments.php in AkoComment 1.1 module (com_akocomment) for Mambo 4.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. |