Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.26% | — | Drupal Canvas Project Drupal Canvas | 10/7/2026 | 21/7/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1. | |
| Analizada | Media (6.1) | 0.26% | — | Drupal Canvas Project Drupal Canvas | 10/7/2026 | 21/7/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1. | |
| Aplazada | Media (6.4) | 0.35% | — | CanvasAI | 13/6/2026 | 23/7/2026 | The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary… | |
| Analizada | Alta (8) | 0.81% | — | Microsoft Live Share Canvas | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5) | 0.27% | — | Drupal Canvas Project Drupal Canvas | 25/3/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue affects Drupal Canvas: from 0.0.0 before 1.1.1. | |
| Aplazada | Media (4.6) | 0.43% | — | TaskcanvasAI | 11/2/2026 | 17/6/2026 | TaskCanvas 1.4.0 contains a denial of service vulnerability in the registration code input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the registration field to trigger an application crash. | |
| Analizada | Media (4.8) | 0.16% | — | Drupal Canvas Project Drupal Canvas | 4/2/2026 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Drupal Canvas allows Forceful Browsing.This issue affects Drupal Canvas: from 0.0.0 before 1.0.4. | |
| Aplazada | Media (4.3) | 0.14% | — | Jory Hogeveen Off-canvas-sidebarsAI | 27/10/2025 | 30/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jory Hogeveen Off-Canvas Sidebars & Menus (Slidebars) off-canvas-sidebars allows Cross Site Request Forgery.This issue affects Off-Canvas Sidebars & Menus (Slidebars): from n/a through <= 0.5.8.5. | |
| Aplazada | Alta (7.1) | 0.26% | — | Jory Hogeveen Off-canvas-sidebarsAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jory Hogeveen Off-Canvas Sidebars & Menus (Slidebars) off-canvas-sidebars allows Reflected XSS.This issue affects Off-Canvas Sidebars & Menus (Slidebars): from n/a through <= 0.5.8.4. | |
| Aplazada | Media (5.4) | 0.45% | — | Pietro Mobile APP CanvasAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in pietro Mobile App Canvas mobile-app allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mobile App Canvas: from n/a through <= 3.8.2. | |
| Aplazada | Media (6.5) | 0.36% | — | Jory Hogeveen OFF Canvas SidebarsAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jory Hogeveen Off-Canvas Sidebars & Menus (Slidebars) off-canvas-sidebars allows DOM-Based XSS.This issue affects Off-Canvas Sidebars & Menus (Slidebars): from n/a through <= 0.5.8.2. | |
| Analizada | Media (6.1) | 0.33% | — | Canvasflow | 31/1/2025 | 17/6/2026 | The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (8.1) | 1.0% | — | Live2dwebcanvasAI | 31/1/2025 | 17/6/2026 | The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ClearFiles() function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on… | |
| Analizada | Media (5.3) | 0.35% | — | Responsive AND Off-canvas Menu Project Responsive AND Off-canvas Menu | 9/1/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affects Responsive and off-canvas menu: from 0.0.0 before 4.4.4. | |
| Aplazada | Media (5.4) | 0.48% | — | Virtuellwerk Canvasio3d-lightAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in virtuellwerk canvasio3D Light canvasio3d-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects canvasio3D Light: from n/a through <= 2.5.0. | |
| Aplazada | Crítica (9.9) | 0.82% | — | Virtuellwerk Canvasio3d LightAI | 14/5/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Thomas Scholl canvasio3D Light.This issue affects canvasio3D Light: from n/a through 2.5.0. | |
| Aplazada | Media (6.5) | 0.35% | — | Jory Hogeveen Off-canvas Sidebars AND MenusAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jory Hogeveen Off-Canvas Sidebars & Menus (Slidebars) allows Stored XSS.This issue affects Off-Canvas Sidebars & Menus (Slidebars): from n/a through 0.5.8.1. | |
| Modificada | Media (6.1) | 0.33% | — | Virtuellwerk Canvasio3d Light | 18/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Thomas Scholl canvasio3D Light plugin <= 2.4.6 versions. | |
| Modificada | Media (6.5) | 0.87% | — | Instructure Canvas Learning Management Service | 26/1/2023 | 17/6/2026 | Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url). | |
| Modificada | Crítica (9.8) | 0.63% | — | Pacman-canvas Project Pacman-canvas | 19/12/2022 | 17/6/2026 | A vulnerability classified as critical has been found in pacman-canvas up to 1.0.5. Affected is the function addHighscore of the file data/db-handler.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. Upgrading to version 1.0.6 is able to address this issue. The name of the… | |
| Modificada | Crítica (9.8) | 1.6% | — | Molie Instructure Canvas Linking Tool Project Molie Instructure Canvas Linking Tool | 14/3/2022 | 17/6/2026 | The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, leading to an SQL Injection | |
| Modificada | Media (6.1) | 0.83% | — | Molie Instructure Canvas Linking Tool Project Molie Instructure Canvas Linking Tool | 14/3/2022 | 17/6/2026 | The MOLIE WordPress plugin through 0.5 does not escape the course_id parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (5.8) | 6.5% | — | Instructure Canvas Learning Management Service | 21/8/2020 | 17/6/2026 | Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains. | |
| Modificada | Alta (8.8) | 2.3% | — | Automattic Canvas | 20/7/2020 | 17/6/2026 | A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a user-provided image. | |
| Modificada | Media (6.1) | 0.81% | — | Synaptivemedical Clearcanvas | 7/2/2020 | 17/6/2026 | Synaptive Medical ClearCanvas ImageServer 3.0 Alpha allows XSS (and HTML injection) via the Default.aspx UserName parameter. NOTE: the issues/227 reference does not imply that the affected product can be downloaded from GitHub. It was simply a convenient location for a public bug report. |