Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.55%—Codologic Codoforum7/1/202017/6/2026
Codoforum 4.8.3 allows XSS in the admin dashboard via a category to the Manage Users screen.
ModificadaMedia (4.8)1.1%—Codologic Codoforum5/1/202017/6/2026
Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.
ModificadaMedia (4.8)0.57%—Codologic Codoforum5/1/202017/6/2026
Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.
ModificadaCrítica (9.8)1.2%—Guidestar WEC Discussion Forum26/11/201916/6/2026
The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-supplied input.
ModificadaCrítica (9)5.4%—Fudforum13/11/201917/6/2026
FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits the user information, the payload will execute. This will allow for PHP files to be written to the…
ModificadaCrítica (9)8.2%💥 ExploitFudforum12/11/201917/6/2026
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user information under "User Manager" in the control panel, the payload will execute. This will…
ModificadaMedia (5.4)0.65%—Jitbit .net Forum1/11/201917/6/2026
A cross-site scripting (XSS) vulnerability in Jitbit .NET Forum (aka ASP.NET forum) 8.3.8 allows remote attackers to inject arbitrary web script or HTML via the gravatar URL parameter.
ModificadaCrítica (9.8)2.7%—Gvectors Wpforo Forum19/6/201917/6/2026
An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of user interaction.
ModificadaMedia (6.5)0.60%—Mylittleforum MY Little Forum21/5/201917/6/2026
my little forum before 2.4.20 allows CSRF to delete posts, as demonstrated by mode=posting&delete_posting.
ModificadaBaja (2.7)2.4%—Vanillaforums Vanilla21/3/201917/6/2026
In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An attacker can leverage this vulnerability to execute code under the context of the web server.
ModificadaAlta (8.1)1.7%—Simplemachines Simple Machines Forum7/3/201917/6/2026
Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.
ModificadaMedia (6.1)0.85%—Simplemachines Simple Machines Forum7/3/201917/6/2026
Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.
ModificadaAlta (8.8)4.0%—Simplemachines Simple Machines Forum7/3/201917/6/2026
Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory traversal in the db_type parameter if install.php remains present after installation.
ModificadaMedia (5.4)0.81%—Vanillaforums Vanilla Forums2/3/201917/6/2026
Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum.
ModificadaMedia (5.3)1.8%—Jforum12/2/201917/6/2026
In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an "is already in use" error is produced. NOTE: this product is discontinued.
ModificadaAlta (7.2)2.0%—Vanillaforums Vanilla23/11/201817/6/2026
Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class.
ModificadaCrítica (9.8)5.2%—Vanillaforums Vanilla3/11/201817/6/2026
Vanilla 2.6.x before 2.6.4 allows remote code execution.
ModificadaCrítica (9.8)1.8%—Wikidforum Project Wikidforum9/10/201817/6/2026
WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort parameter.
ModificadaMedia (6.1)0.68%—Vanillaforums Vanilla28/9/201817/6/2026
Vanilla before 2.6.1 allows XSS via the email field of a profile.
ModificadaMedia (6.5)0.94%—Vanillaforums Vanilla3/9/201817/6/2026
Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invitationmodel.php and applications/dashboard/controllers/class.profilecontroller.php.
ModificadaMedia (4.3)0.88%—Vanillaforums Vanilla Forums26/8/201817/6/2026
In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of a single user to select multiple Poll Options (e.g., vote for multiple items).
ModificadaMedia (6.5)0.41%—Mylittleforum MY Little Forum20/8/201817/6/2026
my little forum 2.4.12 allows CSRF for deletion of users.
ModificadaMedia (4.8)0.91%—Mylittleforum MY Little Forum5/8/201817/6/2026
The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field.
ModificadaMedia (4.8)0.91%—Mylittleforum MY Little Forum5/8/201817/6/2026
The Add page option in my little forum 2.4.12 allows XSS via the Title field.
ModificadaMedia (6.1)2.3%💥 ExploitGoodoldweb Orange Forum20/7/201817/6/2026
views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.
Orbitaley — Vulnerabilidades