Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.44% | — | Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context in which the tag is used. Joomla's string… | |
| Aplazada | Alta (7.5) | 0.42% | — | Regularlabs Articles AnywhereAIJoomlaAI | 14/9/2026 | 16/9/2026 | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover. In affected versions, those options become real HTML event attributes without checking the article author's trust… | |
| Aplazada | Media (6) | 0.21% | — | Aotuman Grab Wechat ArticlesAI | 18/8/2026 | 20/8/2026 | Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI | 23/7/2026 | 28/7/2026 | Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it… | |
| Aplazada | Alta (7.5) | 0.43% | — | Regularlabs Articles AnywhereAIRegularlabs Users AnywhereAI | 23/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF,… | |
| Aplazada | Media (6.5) | 0.42% | — | Regularlabs Users AnywhereAIRegularlabs Articles AnywhereAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details. | |
| Aplazada | Crítica (9.1) | 0.43% | — | Regularlabs Articles AnywhereAIRegularlabs Modules AnywhereAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the… | |
| Aplazada | Alta (8.2) | 0.50% | 💥 PoC | Date Menu OF News ArticlesAI | 19/5/2026 | 17/6/2026 | The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news articles" plugin to be in use and the… | |
| Aplazada | Crítica (9.8) | 0.39% | — | Joomla Articles CalendarAIJoomlaAI | 18/7/2025 | 17/6/2026 | A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Joomla Articles Good SearchAI | 18/7/2025 | 17/6/2026 | A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands. | |
| Aplazada | Media (5.4) | 0.18% | — | Wikimedia Mediawiki Related Articles ExtensionAI | 7/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - RelatedArticles Extension allows Stored XSS.This issue affects Mediawiki - RelatedArticles Extension: from 1.43.X before 1.43.2. | |
| Aplazada | Media (6.5) | 0.32% | — | Erik Saulnier News ArticlesAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erik Saulnier News Articles news-articles allows Stored XSS.This issue affects News Articles: from n/a through <= 1.0.0. | |
| Modificada | Media (6.1) | 0.33% | — | Dj-extensions Dj-helpfularticles | 9/7/2024 | 17/6/2026 | XSS vulnerability in DJ-HelpfulArticles component for Joomla. | |
| Modificada | Media (6.5) | 0.53% | — | Pdf24 Articles TO PDF Project Pdf24 Articles TO PDF | 20/6/2022 | 17/6/2026 | The PDF24 Articles To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (6.5) | 0.53% | — | Pdf24 Articles TO PDF Project Pdf24 Articles TO PDF | 20/6/2022 | 17/6/2026 | The PDF24 Article To PDF WordPress plugin through 4.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Alta (7.5) | 1.4% | — | News-articles Project News-articles | 26/6/2018 | 17/6/2026 | ventrian News-Articles version NewsArticles.00.09.11 contains a XML External Entity (XXE) vulnerability in News-Articles/API/MetaWebLog/Handler.ashx.vb that can result in Attacker can read any file in the server or use smbrelay attack to access to server.. | |
| Modificada | Crítica (9.8) | 2.1% | 💥 Exploit | Yourarticlesdirectory Article Directory Script | 29/10/2017 | 17/6/2026 | Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Smart Related Articles Project Smart Related Articles | 13/4/2017 | 17/6/2026 | The "Smart related articles" extension 1.1 for Joomla! has SQL injection in dialog.php (attacker must use search_cats variable in POST method to exploit this vulnerability). | |
| Modificada | Media (5.3) | 0.72% | — | Smart Related Articles Project Smart Related Articles | 13/4/2017 | 17/6/2026 | The "Smart related articles" extension 1.1 for Joomla! does not prevent direct requests to dialog.php (there is a missing _JEXEC check). | |
| Modificada | Media (6.1) | 0.85% | — | Smart Related Articles Project Smart Related Articles | 13/4/2017 | 17/6/2026 | The "Smart related articles" extension 1.1 for Joomla! has XSS in dialog.php (n_art,type in GET Method). | |
| Modificada | Media (6.5) | 3.4% | 💥 Exploit | Kalptaru Infotech Stararticles | 25/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile photo, then accessing it via a direct request to the file in authorphoto/. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Kalptaru Infotech Stararticles | 25/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbitrary SQL commands via (1) the subcatid parameter to article.list.php; or the artid parameter to (2) article.print.php, (3) article.comments.php, (4) article.publisher.php, or (5)… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Edgephp Ezarticles | 24/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in articles.php in EDGEPHP EZArticles allows remote attackers to inject arbitrary web script or HTML via the title parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Yourarticlesdirectory Your Articles Directory | 27/6/2009 | 16/6/2026 | SQL injection vulnerability in yad-admin/login.php in Your Article Directory allows remote attackers to execute arbitrary SQL commands via the txtAdminEmail parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Yourarticlesdirectory Your Articles Directory | 27/6/2009 | 16/6/2026 | SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL commands via the id parameter. |