Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3069▲ 549 respecto a la semana anterior
Críticas / altas1455▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.46%—Bookstackapp BookstackAI15/9/202616/9/2026
BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers can authenticate at one enabled social…
AplazadaBaja (2.1)0.39%—Bookstackapp BookstackAI7/9/20269/9/2026
A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. The manipulation of the argument ID results in improper access controls. The attack…
AplazadaCrítica (9.3)0.47%—Bookstackapp BookstackAI2/9/20268/9/2026
BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed…
AplazadaAlta (8.7)1.00%—Bookstackapp BookstackAI29/8/202631/8/2026
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename…
AplazadaMedia (5.3)0.41%—Bookstackapp BookstackAI24/8/202624/9/2026
BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery API endpoints. Attackers can supply a user avatar's ID to the…
AplazadaMedia (5.5)0.55%—Bookstackapp BookstackAI3/4/202620/7/2026
A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the file app/Exports/ExportFormatter.php of the component Chapter Export Handler. Executing a manipulation of the argument pages can lead to improper access controls. It is possible to launch the attack…
AplazadaAlta (7.5)0.65%—Bookstackapp BookstackAI9/7/202417/6/2026
Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms.
ModificadaMedia (6.5)1.4%—Bookstackapp Bookstack20/11/202317/6/2026
Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.
ModificadaBaja (2.4)0.63%—Bookstackapp Bookstack30/8/202317/6/2026
Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.
ModificadaMedia (5.4)0.77%—Bookstackapp Bookstack24/10/202217/6/2026
Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to inject an arbitrary script.
ModificadaMedia (5.4)0.78%—Bookstackapp Bookstack8/3/202217/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository bookstackapp/bookstack prior to v22.02.3.
ModificadaMedia (6.5)0.71%—Bookstackapp Bookstack6/1/202217/6/2026
bookstack is vulnerable to Improper Access Control
ModificadaCrítica (9.8)27%—Bookstackapp Bookstack15/12/202117/6/2026
bookstack is vulnerable to Improper Access Control
ModificadaMedia (6.8)0.64%—Bookstackapp Bookstack2/12/202117/6/2026
bookstack is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaMedia (4.3)0.93%—Bookstackapp Bookstack30/11/202117/6/2026
bookstack is vulnerable to Improper Access Control
ModificadaMedia (5.7)0.96%—Bookstackapp Bookstack13/11/202117/6/2026
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
ModificadaMedia (6.5)1.2%—Bookstackapp Bookstack5/11/202117/6/2026
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
ModificadaMedia (6.5)0.67%—Bookstackapp Bookstack27/10/202117/6/2026
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
ModificadaMedia (6.5)1.2%—Bookstackapp Bookstack15/10/202117/6/2026
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
ModificadaMedia (5.4)0.58%—Bookstackapp Bookstack6/9/202117/6/2026
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (5.4)0.58%—Bookstackapp Bookstack6/9/202117/6/2026
bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (6.5)0.80%—Bookstackapp Bookstack2/9/202117/6/2026
bookstack is vulnerable to Server-Side Request Forgery (SSRF)
ModificadaMedia (6.4)0.84%—Bookstackapp Bookstack9/12/202017/6/2026
BookStack is a platform for storing and organising information and documentation. In BookStack before version 0.30.5, a user with permissions to edit a page could set certain image URL's to manipulate functionality in the exporting system, which would allow them to make server side requests and/or have access to a…
ModificadaAlta (8.7)1.1%—Bookstackapp Bookstack3/11/202017/6/2026
In BookStack before version 0.30.4, a user with permissions to edit a page could insert JavaScript code through the use of `javascript:` URIs within a link or form which would run, within the context of the current page, when clicked or submitted. Additionally, a user with permissions to edit a page could insert a…
ModificadaAlta (8.7)1.2%—Bookstackapp Bookstack3/11/202017/6/2026
In BookStack before version 0.30.4, a user with permissions to edit a page could add an attached link which would execute untrusted JavaScript code when clicked by a viewer of the page. Dangerous content may remain in the database after this update. If you think this could have been exploited the linked advisory…