Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
866 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.40% | — | Mojoomla WpcrmAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPCRM - CRM for Contact form CF7 & WooCommerce wpcrm allows SQL Injection.This issue affects WPCRM - CRM for Contact form CF7 & WooCommerce: from n/a through <= 3.2.0. | |
| Aplazada | Alta (8.6) | 0.49% | — | Joomla NO Boss CalendarAI | 13/6/2025 | 17/6/2026 | A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability allows remote authenticated users to execute arbitrary SQL commands via the id_module parameter. | |
| Aplazada | Crítica (9.3) | 0.32% | — | JeventsAIJoomlaAI | 12/6/2025 | 17/6/2026 | A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension is vulnerable to SQL injection via publicly accessible actions to list events by date ranges. | |
| Aplazada | Media (6.7) | 0.31% | — | RsmediagalleryAIJoomlaAI | 11/6/2025 | 17/6/2026 | A SQL injection vulnerability in RSMediaGallery! component 1.7.4 - 2.1.7 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript code into text fields or other input… | |
| Aplazada | Alta (8.5) | 0.33% | — | RsticketsAIJoomlaAI | 11/6/2025 | 17/6/2026 | A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was discovered. It allows attackers to perform cross-site scripting (XSS) attacks via sending crafted payload. | |
| Aplazada | Crítica (9.2) | 0.56% | — | Rsform PROAIJoomlaAI | 11/6/2025 | 17/6/2026 | Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs within the submission export feature and requires administrative access to the export feature. | |
| Analizada | Media (6.1) | 0.21% | — | Rsjoomla Rsmail! | 5/6/2025 | 17/6/2026 | A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript code into text fields or other input points,… | |
| Analizada | Media (6.5) | 0.22% | — | Rsjoomla Rsform!blog | 5/6/2025 | 17/6/2026 | A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows authenticated users to inject malicious JavaScript into the plugin's resource. The injected payload is stored by the application and later executed when other users view the affected content. | |
| Aplazada | Media (6.5) | 0.24% | — | Joomla RsmediagalleryAIJoomlaAI | 5/6/2025 | 17/6/2026 | A SQLi vulnerability in RSMediaGallery component 1.7.4 - 2.1.6 for Joomla was discovered. The vulnerability is due to the use of unescaped user-supplied parameters in SQL queries within the dashboard component. This allows an authenticated attacker to inject malicious SQL code through unsanitized input fields, which… | |
| Aplazada | Media (5.4) | 0.44% | — | RsfirewallAIJoomlaAI | 5/6/2025 | 17/6/2026 | A path traversal vulnerability in RSFirewall component 2.9.7 - 3.1.5 for Joomla was discovered. This vulnerability allows authenticated users to read arbitrary files outside the Joomla root directory. The flaw is caused by insufficient sanitization of user-supplied input in file path parameters, allowing attackers to… | |
| Analizada | Media (4.8) | 0.30% | — | Rsjoomla Rsform!pro | 4/6/2025 | 17/6/2026 | A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. The issue arises from the improper handling of the filter[dateFrom] GET parameter, which is reflected unescaped in the administrative backend interface. This allows an authenticated attacker with admin or editor privileges… | |
| Aplazada | Crítica (9.9) | 0.42% | — | Mojoomla Hospital Management SystemAI | 23/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server. This issue affects Hospital Management System: from 47.0(20 through 11. | |
| Aplazada | Alta (8.8) | 0.36% | — | Mojoomla Hospital Management SystemAI | 23/5/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in mojoomla Hospital Management System allows Privilege Escalation. This issue affects Hospital Management System: from 47.0(20 through 11. | |
| Aplazada | Alta (7.1) | 0.28% | — | Mojoomla School ManagementAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla School Management allows Reflected XSS. This issue affects School Management: from n/a through 92.0.0. | |
| Aplazada | Alta (8.5) | 0.33% | — | Mojoomla School ManagementAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 92.0.0. | |
| Aplazada | Crítica (9.9) | 0.42% | — | Mojoomla WpamsAI | 19/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web Shell to a Web Server.This issue affects WPAMS: from n/a through <= 44.0 (17-08-2023). | |
| Aplazada | Crítica (10) | 0.54% | 💥 PoC | Mojoomla WpamsAI | 19/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS apartment-management allows Upload a Web Shell to a Web Server.This issue affects WPAMS: from n/a through <= 44.0 (17-08-2023). | |
| Aplazada | Crítica (9.3) | 0.35% | — | Mojoomla WpamsAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPAMS apartment-management allows SQL Injection.This issue affects WPAMS: from n/a through <= 44.0 (17-08-2023). | |
| Aplazada | Alta (7.1) | 0.22% | — | Mojoomla Hospital Management SystemAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla Hospital Management System hospital-management allows Reflected XSS.This issue affects Hospital Management System: from n/a through <= 47.0(20-11-2023). | |
| Aplazada | Alta (7.1) | 0.22% | — | Mojoomla WpamsAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla WPAMS apartment-management allows Reflected XSS.This issue affects WPAMS: from n/a through <= 44.0 (17-08-2023). | |
| Aplazada | Crítica (9.3) | 0.34% | — | Mojoomla Hospital Management SystemAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital Management System hospital-management allows SQL Injection.This issue affects Hospital Management System: from n/a through <= 47.0(20-11-2023). | |
| Aplazada | Crítica (10) | 0.42% | — | Mojoomla Hospital Management SystemAI | 19/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System hospital-management allows Upload a Web Shell to a Web Server.This issue affects Hospital Management System: from n/a through <= 47.0(20-11-2023). | |
| Aplazada | Alta (8.5) | 0.32% | — | Mojoomla Hospital Management SystemAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital Management System hospital-management allows SQL Injection.This issue affects Hospital Management System: from n/a through <= 47.0(20-11-2023). | |
| Aplazada | Crítica (9.8) | 0.51% | — | Mojoomla WpamsAI | 19/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in mojoomla WPAMS apartment-management allows PHP Local File Inclusion.This issue affects WPAMS: from n/a through <= 44.0. | |
| Aplazada | Alta (8.8) | 0.36% | — | Mojoomla WpamsAI | 19/5/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in mojoomla WPAMS apartment-management allows Privilege Escalation.This issue affects WPAMS: from n/a through <= 44.0 (17-08-2023). |