Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 115 respecto a la semana anterior
Críticas / altas1419▲ 175 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
185 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.24% | — | PubliccmsAI | 25/9/2026 | 29/9/2026 | A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContentAdminController of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/controller/admin/sys/SysUserAdminController.java of the component exportExcel/exportData. This manipulation of… | |
| Aplazada | Alta (7.1) | 0.25% | — | IdccmsAI | 21/9/2026 | 22/9/2026 | idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php. | |
| Aplazada | Baja (2) | 2.2% | — | Magicblack Maccms10AI | 14/9/2026 | 16/9/2026 | A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown functionality of the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html of the component Template Handler. Performing a manipulation results in os command… | |
| Aplazada | Alta (7.5) | 0.75% | — | MaccmsAI | 25/8/2026 | 8/9/2026 | The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Access Control issue. The interface fails to perform any authentication or authorization checks. An unauthenticated remote attacker can send a crafted HTTP GET request with limit and offset parameters to paginate and… | |
| Aplazada | Alta (7.2) | 0.54% | — | Maccms10AI | 5/8/2026 | 26/8/2026 | MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function, register_tick_function, and error_log. | |
| Aplazada | Baja (2.9) | 0.44% | — | Maccms PROAI | 13/7/2026 | 13/7/2026 | A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The attack requires a high level of… | |
| Aplazada | Media (6.1) | 0.25% | — | PubliccmsAI | 15/6/2026 | 17/6/2026 | PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module. | |
| Aplazada | Baja (2.1) | 0.39% | — | PubliccmsAI | 17/5/2026 | 17/6/2026 | A flaw has been found in Sanluan PublicCMS 5.202506.d. The impacted element is the function execute of the file publiccms-core/src/main/java/com/publiccms/views/directive/tools/TemplateResultDirective.java of the component templateResult API. This manipulation of the argument templateContent causes improper… | |
| Aplazada | Media (5.5) | 0.46% | — | PubliccmsAI | 17/5/2026 | 17/6/2026 | A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the argument privatefile_key results in use of hard-coded cryptographic key . The… | |
| Aplazada | Media (5.5) | 0.55% | — | PubliccmsAI | 17/5/2026 | 17/6/2026 | A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeOrderController.java of the component Trade Payment… | |
| Aplazada | Media (5.5) | 0.68% | — | PubliccmsAI | 17/5/2026 | 17/6/2026 | A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/directive/trade/TradeAddressListDirective.java of the component Trade Address Query Handler. Executing a manipulation of the argument userId/id can lead… | |
| Aplazada | Baja (2) | 0.38% | — | Maccms PROAI | 1/5/2026 | 17/6/2026 | A weakness has been identified in MacCMS Pro up to 2022.1.3. This vulnerability affects the function install of the file /admi.php/admin/addon/add.html of the component Plugin Installation Handler. Executing a manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Media (5.3) | 0.46% | — | PubliccmsAI | 21/4/2026 | 17/6/2026 | A vulnerability was identified in Sanluan PublicCMS up to 6.202506.d. Affected by this vulnerability is the function ZipSecureFile.setMinflateRatio of the file common/src/main/java/com/publiccms/common/tools/DocToHtmlUtils.java. Such manipulation leads to resource consumption. It is possible to launch the attack… | |
| Aplazada | Media (5.3) | 0.23% | — | PubliccmsAI | 21/4/2026 | 17/6/2026 | A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file core/src/main/java/com/publiccms/controller/admin/LoginAdminController.java of the component Failed Login Handler. This manipulation of the argument errorPassword causes cleartext storage in a file or… | |
| Aplazada | Baja (2) | 0.41% | — | Apache FreemarkerAIPubliccmsAI | 9/4/2026 | 17/6/2026 | A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFreemarkerView.doRender of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/common/base/AbstractFreemarkerView.java of the component FreeMarker Template Handler. Such manipulation… | |
| Aplazada | Baja (2.1) | 0.37% | — | MaccmsAI | 23/3/2026 | 17/6/2026 | A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This manipulation of the argument order_id causes authorization bypass. It is possible to initiate the… | |
| Aplazada | Media (5.5) | 0.65% | — | MaccmsAI | 23/3/2026 | 17/6/2026 | A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The exploit has been released to the public… | |
| Analizada | Alta (8.7) | 0.36% | — | Publiccms | 27/2/2026 | 17/6/2026 | PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system and views it, the embedded JavaScript payload can be triggered,… | |
| Analizada | Baja (2.1) | 0.88% | — | Publiccms | 27/2/2026 | 17/6/2026 | A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the component Template Cache Generation. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the… | |
| Analizada | Baja (1.3) | 0.34% | — | Publiccms | 6/2/2026 | 17/6/2026 | A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function Paid of the file publiccms-parent/publiccms-trade/src/main/java/com/publiccms/logic/service/trade/TradePaymentService.java of the component Trade Payment Handler. The manipulation of the argument… | |
| Analizada | Baja (2.1) | 0.43% | — | Publiccms | 18/1/2026 | 17/6/2026 | A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeAddressController.java of the component Trade Address Deletion Endpoint. Performing a manipulation of the argument ids results in improper… | |
| Analizada | Baja (2) | 0.71% | — | Publiccms | 18/1/2026 | 17/6/2026 | A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/publiccms/controller/admin/sys/TaskTemplateAdminController.java of the component Task Template Management Handler. Such manipulation of the argument path leads to path traversal. The attack can be… | |
| Analizada | Media (5.4) | 0.17% | — | Publiccms | 22/12/2025 | 17/6/2026 | PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module. | |
| Analizada | Alta (8.8) | 0.18% | — | Publiccms | 1/12/2025 | 17/6/2026 | PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController. | |
| Analizada | Alta (7.5) | 0.45% | — | Publiccms | 1/12/2025 | 17/6/2026 | PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method. |