Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.47% | — | Crmperks WP Gravity Forms Freshdesk Plugin | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5. | |
| Aplazada | Alta (7.5) | 0.35% | — | Bplugins PDF FOR Gravity FormsAIGravityforms Gravity FormsAI | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Gravity Forms + Drag And Drop Template Builder pdf-for-gravity-forms allows Object Injection.This issue affects PDF for Gravity Forms + Drag And Drop Template Builder: from n/a through <= 6.5.0. | |
| Analizada | Crítica (9.1) | 0.29% | — | Getgrav Grav | 15/12/2025 | 17/6/2026 | In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates when page content is processed by Twig and the configuration allows undefined PHP functions to be registered | |
| Analizada | Media (5.4) | 0.16% | — | Getgrav Grav | 15/12/2025 | 17/6/2026 | grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An authenticated low-privileged user with permission to edit content can inject malicious JavaScript payloads into editable fields. The payload is stored on the server and later executed when any other… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Multi Uploader FOR Gravity FormsAI | 12/12/2025 | 17/6/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'plupload_ajax_delete_file' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the… | |
| Aplazada | Media (4.7) | 0.20% | — | Crmperks WP Gravity Forms FreshdeskAI | 9/12/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Phishing.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5. | |
| Aplazada | Media (4.3) | 0.24% | — | Gravitec.net WEB Push NotificationsAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Gravitec.net - Web Push Notifications Gravitec.net – Web Push Notifications gravitec-net-web-push-notifications allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gravitec.net – Web Push Notifications: from n/a through <= 2.9.17. | |
| Analizada | Media (6.1) | 0.22% | — | Getgrav Grav | 2/12/2025 | 17/6/2026 | Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page content via a Markdown editor. The editor fails to properly sanitize <script> tags, allowing stored XSS payloads to execute when pages are viewed in the admin interface. | |
| Analizada | Media (6.2) | 0.21% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 17/6/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows… | |
| Analizada | Media (6.2) | 0.23% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 17/6/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows… | |
| Analizada | Media (6.8) | 0.21% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 17/6/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/config/site endpoint of the Grav application. This vulnerability allows… | |
| Analizada | Media (6.9) | 0.39% | — | Getgrav Grav | 1/12/2025 | 17/6/2026 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Denial of Service (DoS) vulnerability was identified in the "Languages" submenu of the Grav admin configuration panel (/admin/config/system). Specifically, the Supported parameter fails to properly validate user input. If a malformed value is inserted—such… | |
| Analizada | Media (6.2) | 0.21% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 25/9/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/accounts/groups/Grupo endpoint of the Grav application. This vulnerability… | |
| Analizada | Media (6.2) | 0.21% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 25/9/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows… | |
| Analizada | Media (5.3) | 0.32% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 25/9/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and email disclosure vulnerability exists in Grav. The "Forgot Password" functionality at /admin/forgot leaks information about valid… | |
| Analizada | Media (6.5) | 0.29% | — | Getgrav Grav | 1/12/2025 | 25/9/2026 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, there is an IDOR (Insecure Direct Object Reference) vulnerability in the Grav CMS Admin Panel which allows low-privilege users to access sensitive information from other accounts. Although direct account takeover is not possible, admin email addresses and… | |
| Analizada | Alta (7.2) | 0.41% | — | Getgrav Grav | 1/12/2025 | 25/9/2026 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, users with read access on the user account management section of the admin panel can view the password hashes of all users, including the admin user. This exposure can potentially lead to privilege escalation if an attacker can crack these password hashes.… | |
| Analizada | Media (4.9) | 0.39% | — | Getgrav Grav | 1/12/2025 | 25/9/2026 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A Denial of Service (DoS) vulnerability has been identified in Grav related to the handling of scheduled_at parameters. Specifically, the application fails to properly sanitize input for cron expressions. By manipulating the scheduled_at parameter with a… | |
| Analizada | Media (6.8) | 0.48% | — | Getgrav Grav | 1/12/2025 | 25/9/2026 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated attackers with administrative privileges to read arbitrary files on the underlying server filesystem. This vulnerability arises due to insufficient input sanitization in the… | |
| Analizada | Alta (8.6) | 1.3% | 💥 Exploit | Getgrav Grav | 1/12/2025 | 25/9/2026 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the form is now able to change the functioning of the form through modifying the… | |
| Analizada | Alta (8.5) | 0.45% | — | Getgrav Grav | 1/12/2025 | 25/9/2026 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "Frontmatter" form. This includes Grav user account files (/grav/user/accounts/*.yaml), which store hashed user password, 2FA secret, and the password reset token. This… | |
| Analizada | Alta (8.8) | 0.61% | — | Getgrav Grav | 1/12/2025 | 25/9/2026 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypassing the existing security sandbox. Since the security sandbox does not fully… | |
| Analizada | Alta (7.7) | 0.38% | — | Getgrav Grav | 1/12/2025 | 25/9/2026 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, having a simple form on site can reveal the whole Grav configuration details (including plugin configuration details) by using the correct POST payload to exploit a Server-Side Template (SST) vulnerability. Sensitive information may be contained in the… | |
| Analizada | Alta (7.4) | 0.78% | — | Getgrav Grav | 1/12/2025 | 25/9/2026 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the page frontmatter. By injecting malicious Twig expressions, the user can escalate their privileges to admin or execute arbitrary system commands… | |
| Analizada | Alta (8.8) | 0.32% | — | Getgrav Grav | 1/12/2025 | 25/9/2026 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation when creating users. A user with the create user permission can create a new account using the same username as an existing administrator… |