Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3069▲ 549 respecto a la semana anterior
Críticas / altas1455▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.46% | — | Bookstackapp BookstackAI | 15/9/2026 | 16/9/2026 | BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers can authenticate at one enabled social… | |
| Aplazada | Baja (2.1) | 0.39% | — | Bookstackapp BookstackAI | 7/9/2026 | 9/9/2026 | A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. The manipulation of the argument ID results in improper access controls. The attack… | |
| Aplazada | Crítica (9.3) | 0.47% | — | Bookstackapp BookstackAI | 2/9/2026 | 8/9/2026 | BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed… | |
| Aplazada | Alta (8.7) | 1.00% | — | Bookstackapp BookstackAI | 29/8/2026 | 31/8/2026 | BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename… | |
| Aplazada | Media (5.3) | 0.41% | — | Bookstackapp BookstackAI | 24/8/2026 | 24/9/2026 | BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery API endpoints. Attackers can supply a user avatar's ID to the… | |
| Aplazada | Media (5.5) | 0.55% | — | Bookstackapp BookstackAI | 3/4/2026 | 20/7/2026 | A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. Executing a manipulation of the argument pages can lead to improper access controls. It is possible to launch the attack… | |
| Aplazada | Alta (7.5) | 0.65% | — | Bookstackapp BookstackAI | 9/7/2024 | 17/6/2026 | Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms. | |
| Modificada | Media (6.5) | 1.4% | — | Bookstackapp Bookstack | 20/11/2023 | 17/6/2026 | Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF. | |
| Modificada | Baja (2.4) | 0.63% | — | Bookstackapp Bookstack | 30/8/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08. | |
| Modificada | Media (5.4) | 0.77% | — | Bookstackapp Bookstack | 24/10/2022 | 17/6/2026 | Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script. | |
| Modificada | Media (5.4) | 0.78% | — | Bookstackapp Bookstack | 8/3/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3. | |
| Modificada | Media (6.5) | 0.71% | — | Bookstackapp Bookstack | 6/1/2022 | 17/6/2026 | bookstack is vulnerable to Improper Access Control | |
| Modificada | Crítica (9.8) | 27% | — | Bookstackapp Bookstack | 15/12/2021 | 17/6/2026 | bookstack is vulnerable to Improper Access Control | |
| Modificada | Media (6.8) | 0.64% | — | Bookstackapp Bookstack | 2/12/2021 | 17/6/2026 | bookstack is vulnerable to Cross-Site Request Forgery (CSRF) | |
| Modificada | Media (4.3) | 0.93% | — | Bookstackapp Bookstack | 30/11/2021 | 17/6/2026 | bookstack is vulnerable to Improper Access Control | |
| Modificada | Media (5.7) | 0.96% | — | Bookstackapp Bookstack | 13/11/2021 | 17/6/2026 | bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type | |
| Modificada | Media (6.5) | 1.2% | — | Bookstackapp Bookstack | 5/11/2021 | 17/6/2026 | bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | |
| Modificada | Media (6.5) | 0.67% | — | Bookstackapp Bookstack | 27/10/2021 | 17/6/2026 | bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type | |
| Modificada | Media (6.5) | 1.2% | — | Bookstackapp Bookstack | 15/10/2021 | 17/6/2026 | bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | |
| Modificada | Media (5.4) | 0.58% | — | Bookstackapp Bookstack | 6/9/2021 | 17/6/2026 | bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (5.4) | 0.58% | — | Bookstackapp Bookstack | 6/9/2021 | 17/6/2026 | bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (6.5) | 0.80% | — | Bookstackapp Bookstack | 2/9/2021 | 17/6/2026 | bookstack is vulnerable to Server-Side Request Forgery (SSRF) | |
| Modificada | Media (6.4) | 0.84% | — | Bookstackapp Bookstack | 9/12/2020 | 17/6/2026 | BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit a page could set certain image URL's to manipulate functionality in the exporting system, which would allow them to make server side requests and/or have access to a… | |
| Modificada | Alta (8.7) | 1.1% | — | Bookstackapp Bookstack | 3/11/2020 | 17/6/2026 | In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current page, when clicked or submitted. Additionally, a user with permissions to edit a page could insert a… | |
| Modificada | Alta (8.7) | 1.2% | — | Bookstackapp Bookstack | 3/11/2020 | 17/6/2026 | In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the page. Dangerous content may remain in the database after this update. If you think this could have been exploited the linked advisory… |