Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.63% | — | Mogublog Project Mogublog | 1/12/2025 | 25/9/2026 | A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file /networkDisk/unzipFile of the component ZIP File Handler. Such manipulation of the argument fileUrl leads to path traversal. The attack may be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.38% | — | Mogublog Project Mogublog | 1/12/2025 | 25/9/2026 | A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This manipulation of the argument filedatas causes unrestricted upload. The attack may be initiated remotely. The exploit has been made available to the public and could be… | |
| Analizada | Media (5.5) | 0.53% | — | Mogublog Project Mogublog | 1/12/2025 | 25/9/2026 | A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may… | |
| Analizada | Baja (2.9) | 0.47% | — | Mogublog Project Mogublog | 1/12/2025 | 25/9/2026 | A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component Storage Management Endpoint. The manipulation leads to missing authorization. The attack can be initiated remotely. The attack's complexity is rated as high. The… | |
| Analizada | Media (5.1) | 0.34% | — | Forestblog Project Forestblog | 31/3/2025 | 17/6/2026 | A vulnerability was found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this issue is some unknown functionality of the component Friend Link Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.1) | 0.34% | — | Forestblog Project Forestblog | 31/3/2025 | 17/6/2026 | A vulnerability has been found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /search. The manipulation of the argument keywords leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (4.8) | 0.28% | — | Forestblog Project Forestblog | 3/2/2025 | 17/6/2026 | Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function. | |
| Modificada | Media (4.8) | 0.30% | — | Print MY Blog Project Print MY Blog | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Nelson Print My Blog print-my-blog.This issue affects Print My Blog: from n/a through <= 3.27.0. | |
| Analizada | Media (5.3) | 0.37% | — | Toy-blog Project Toy-blog | 1/7/2024 | 17/6/2026 | toy-blog is a headless content management system implementation. Starting in version 0.5.4 and prior to version 0.6.1, articles with private visibility can be read if the reader does not set credentials for the request. Users should upgrade to 0.6.1 or later to receive a patch. No known workarounds are available. | |
| Modificada | Crítica (9.8) | 0.91% | — | Forestblog Project Forestblog | 17/12/2023 | 17/6/2026 | A vulnerability classified as critical has been found in saysky ForestBlog up to 20220630. This affects an unknown part of the file /admin/upload/img of the component Image Upload Handler. The manipulation of the argument filename leads to unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Modificada | Media (4.8) | 0.48% | — | Blog-in-blog Project Blog-in-blog | 31/5/2023 | 17/6/2026 | The Blog-in-Blog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blog_in_blog' shortcode in versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with editor-level and… | |
| Modificada | Alta (7.2) | 1.1% | — | Blog-in-blog Project Blog-in-blog | 31/5/2023 | 17/6/2026 | The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via a shortcode attribute. This allows editor-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to… | |
| Modificada | Media (5.4) | 0.41% | — | Djangoblog Project Djangoblog | 29/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master. | |
| Modificada | Alta (7.8) | 0.97% | — | Mblog Project Mblog | 8/5/2023 | 17/6/2026 | OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected. | |
| Modificada | Media (6.5) | 0.85% | — | Mogublog Project Mogublog | 15/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal. The attack may be initiated remotely. The… | |
| Modificada | Media (4.3) | 0.33% | — | My-blog Project My-blog | 7/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in zhenfeng13 My-Blog. Affected is an unknown function of the file /admin/configurations/userInfo. The manipulation of the argument yourAvatar/yourName/yourEmail leads to cross-site request forgery. It is possible to launch the attack remotely. The… | |
| Modificada | Crítica (9.8) | 4.7% | — | Xipblog Project Xipblog | 27/3/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components. | |
| Modificada | Media (6.1) | 0.36% | — | My-blog Project My-blog | 13/3/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in My-Blog allows attackers to cause a denial of service via the Post function. | |
| Modificada | Crítica (9.8) | 1.6% | — | Javaweb Blog Project Javaweb Blog | 26/1/2023 | 17/6/2026 | An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile. | |
| Modificada | Media (5.4) | 0.39% | — | Javaweb Blog Project Javaweb Blog | 23/1/2023 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability found in Rawchen blog-ssm v1.0 allows attackers to execute arbitrary code via the 'notifyInfo' parameter. | |
| Modificada | Crítica (9.8) | 0.82% | — | Sternenblog Project Sternenblog | 7/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in sternenseemann sternenblog. This issue affects the function blog_index of the file main.c. The manipulation of the argument post_path leads to file inclusion. The attack may be initiated remotely. The complexity of an attack is rather high. The… | |
| Modificada | Media (6.1) | 0.38% | — | Fs-blog Project Fs-blog | 11/12/2022 | 17/6/2026 | A vulnerability was found in zbl1996 FS-Blog and classified as problematic. This issue affects some unknown processing of the component Title Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-215267. | |
| Modificada | Media (6.1) | 0.60% | — | Amasty Blog PRO | 29/11/2022 | 17/6/2026 | The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript code in the short_content and full_content fields, leading to XSS attacks against admin panel users via posts/preview or posts/save. | |
| Modificada | Media (5.4) | 0.51% | — | Amasty Blog PRO | 23/11/2022 | 9/7/2026 | Stored Cross-site Scripting (XSS) exists in the Amasty Blog Pro 2.10.3 and 2.10.4 plugin for Magento 2 because of the duplicate post function. | |
| Modificada | Media (5.4) | 0.51% | — | Amasty Blog PRO | 23/11/2022 | 9/7/2026 | Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality. |