Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.35% | — | Ghost ActivitypubAI | 24/6/2026 | 25/6/2026 | @tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection on posts shared by a maliciously customised ActivityPub server. This vulnerability is fixed in 3.1.0. | |
| Analizada | Alta (7.5) | 0.44% | — | Automattic Activitypub | 8/4/2026 | 24/7/2026 | The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated users to access drafts/scheduled/pending posts | |
| Aplazada | Media (6.5) | 0.38% | — | Activitypub-federation-rustAIJoin-lemmy LemmyAI | 27/3/2026 | 17/6/2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in `activitypub-federation-rust` (`src/utils.rs`) does not check for `Ipv4Addr::UNSPECIFIED` (0.0.0.0). An unauthenticated attacker controlling a remote domain can point it to 0.0.0.0, bypass the SSRF… | |
| Aplazada | Alta (7.7) | 0.42% | — | Activitypub FederationAIPict-rsAIJoin-lemmy LemmyAI | 6/3/2026 | 17/6/2026 | Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. Prior to version 0.19.16, the GET /api/v4/image/{filename} endpoint is vulnerable to unauthenticated SSRF through parameter… | |
| Aplazada | Media (4) | 0.42% | — | Activitypub FederationAIJoin-lemmy LemmyAI | 10/2/2025 | 17/6/2026 | Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. This vulnerability, which is present in versions 0.6.2 and prior of activitypub_federation and versions 0.19.8 and prior of… | |
| Aplazada | Media (6.5) | 0.35% | — | Automattic ActivitypubAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Matthias Pfefferle & Automattic ActivityPub.This issue affects ActivityPub: from n/a through 1.0.5. | |
| Modificada | Media (5.4) | 0.48% | — | Automattic Activitypub | 16/10/2023 | 17/6/2026 | The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role of Contributor and above to perform Stored XSS attacks | |
| Modificada | Media (5.4) | 0.50% | — | Automattic Activitypub | 16/10/2023 | 17/6/2026 | The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.3) | 0.56% | — | Automattic Activitypub | 16/10/2023 | 17/6/2026 | The ActivityPub WordPress plugin before 1.0.0 does not ensure that post contents to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the content of arbitrary post (such as draft and private) via an IDOR vector. Password protected posts are not affected… | |
| Modificada | Media (4.3) | 0.56% | — | Automattic Activitypub | 16/10/2023 | 17/6/2026 | The ActivityPub WordPress plugin before 1.0.0 does not ensure that post titles to be displayed are public and belong to the plugin, allowing any authenticated user, such as subscriber to retrieve the title of arbitrary post (such as draft and private) via an IDOR vector |