Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 306 respecto a la semana anterior
Críticas / altas1347▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.37% | — | CodeigniterAICi4-cms-erp Ci4msAI | 20/7/2026 | 21/7/2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page content but persists the raw, un-purified POST value into the database. The public renderer for pages (`Home::index()` →… | |
| Aplazada | Media (6.5) | 0.48% | — | CodeigniterAICi4-cms-erp Ci4msAI | 20/7/2026 | 21/7/2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write operations (`saveFile`, `createFile`), but two destructive endpoints — `deleteFileOrFolder` and… | |
| Aplazada | Media (5.4) | 0.24% | — | Codeigniter 4AICi4-cms-erp Ci4msAI | 20/7/2026 | 21/7/2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` validation rule used to sanitize blog post bodies relies on by-reference mutation (`?string &$str`), but CodeIgniter 4's validator passes a local copy of the value, so the sanitized text is silently… | |
| Aplazada | Media (5.3) | 0.36% | — | Ci4-cms-erp Ci4msAI | 7/5/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0 to before version 0.31.8.0, the auth filter has the deactivated/banned user check commented out. This issue has been patched in version 0.31.8.0. | |
| Aplazada | Media (6.9) | 0.43% | — | CodeigniterAICi4-cms-erp Ci4msAI | 7/5/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.31.1.0 to before version 0.31.8.0, the deleteProcess() action accepts a POST parameter tables[] containing arbitrary table names. These are passed directly to… | |
| Aplazada | Alta (8.6) | 0.68% | — | CodeigniterAICi4-cms-erp Ci4msAI | 7/5/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0.0 to before version 0.31.7.0, a theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution… | |
| Aplazada | Crítica (9.4) | 0.72% | — | CodeigniterAICi4-cms-erp Ci4msAI | 7/5/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.5.0, ci4ms Theme::upload extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the theme create… | |
| Aplazada | Crítica (9.4) | 0.72% | — | Codeigniter 4AICi4-cms-erp Ci4msAI | 7/5/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.5.0, ci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup… | |
| Aplazada | Crítica (9.1) | 0.56% | — | CodeigniterAICi4-cms-erp Ci4msAI | 7/5/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In version 0.31.4.0, an attacker can achieve Full Account Takeover & Privilege Escalation via Stored DOM XSS in backup module filename field manipulated via a sql file that… | |
| Analizada | Crítica (9.8) | 0.51% | — | Ci4-cms-erp Ci4ms | 8/4/2026 | 24/7/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Install::index() controller reads the host POST parameter without any validation and passes it directly into updateEnvSettings(), which writes it into the… | |
| Analizada | Alta (8.1) | 0.40% | — | Ci4-cms-erp Ci4ms | 8/4/2026 | 24/7/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the install route guard in ci4ms relies solely on a volatile cache check (cache('settings')) combined with .env file existence to block post-installation… | |
| Analizada | Media (4.8) | 0.25% | — | Ci4-cms-erp Ci4ms | 8/4/2026 | 24/7/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Pages module does not apply the html_purify validation rule to content fields during create and update operations, while the Blog module does. Page… | |
| Analizada | Media (4.8) | 0.25% | — | Ci4-cms-erp Ci4ms | 8/4/2026 | 20/7/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the blacklist (ban) note parameter in UserController::ajax_blackList_post() is stored in the database without sanitization and rendered into an HTML data-note… | |
| Analizada | Media (4.8) | 0.24% | — | Ci4-cms-erp Ci4ms | 8/4/2026 | 24/7/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, the Google Maps iframe setting (cMap field) in compInfosPost() sanitizes input using strip_tags() with an <iframe> allowlist and regex-based removal of on\w+… | |
| Analizada | Alta (7.2) | 0.49% | — | Ci4-cms-erp Ci4ms | 8/4/2026 | 24/7/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.4.0, This vulnerability is fixed in 0.31.4.0. | |
| Analizada | Crítica (9) | 0.56% | — | Ci4-cms-erp Ci4ms | 6/4/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 0.31.2.0, the application fails to properly sanitize user-controlled input within System Settings – Company Information. Several administrative configuration fields… | |
| Analizada | Crítica (9.4) | 0.45% | — | Ci4-cms-erp Ci4ms | 6/4/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to 31.0.0.0, the application fails to properly sanitize user-controlled input when users update their profile name (e.g., full name / username). An attacker can inject a… | |
| Analizada | Alta (8.8) | 0.65% | — | Ci4-cms-erp Ci4ms | 1/4/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to immediately revoke active user sessions when an account is deactivated. Due to a logic flaw in the backend design, account… | |
| Analizada | Crítica (9) | 0.56% | — | Ci4-cms-erp Ci4ms | 1/4/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, a Stored Cross-Site Scripting (Stored XSS) vulnerability exists in the backend user management functionality. The application fails to properly… | |
| Modificada | Alta (8.8) | 0.65% | — | Ci4-cms-erp Ci4ms | 1/4/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to immediately revoke active user sessions when an account is deleted. Due to a logic flaw in the backend design, account state… | |
| Analizada | Crítica (9) | 0.46% | — | Ci4-cms-erp Ci4ms | 1/4/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when creating or editing blog categories. An attacker can inject a malicious… | |
| Analizada | Crítica (9) | 0.39% | — | Ci4-cms-erp Ci4ms | 1/4/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when creating or editing blog posts. An attacker can inject a malicious JavaScript… | |
| Analizada | Crítica (9) | 0.39% | — | Ci4-cms-erp Ci4ms | 1/4/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when creating or editing blog posts within the Categories section. An attacker can… | |
| Analizada | Crítica (9) | 0.39% | — | Ci4-cms-erp Ci4ms | 1/4/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input within the Page Management functionality when creating or editing pages. Multiple… | |
| Analizada | Crítica (9) | 0.39% | — | Ci4-cms-erp Ci4ms | 1/4/2026 | 17/6/2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input when adding Posts to navigation menus through the Menu Management functionality.… |