Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.31% | — | ExtendifyAI | 1/10/2026 | 1/10/2026 | The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Baja (2) | 0.36% | — | Langgenius DifyAI | 3/9/2026 | 3/9/2026 | A vulnerability was identified in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace of the file web/app/(shareLayout)/webapp-signin/components/mail-and-password-auth.tsx of the component WebApp Sign-In. Such manipulation of the argument redirect_url leads to cross site scripting.… | |
| Aplazada | Baja (2.1) | 0.50% | — | Langgenius DifyAI | 3/9/2026 | 3/9/2026 | A vulnerability was determined in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(shareLayout)/components/splash.tsx of the component Splash Layout. This manipulation of the argument redirect_url causes cross site scripting. The attack is possible to be carried out remotely. The… | |
| Aplazada | Alta (8.8) | 0.42% | — | FedifyAI | 6/8/2026 | 18/9/2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1, 2.2, and 2.3 maintenance lines, getNodeInfo() follows an attacker-controlled links[].href value from /.well-known/nodeinfo without scheme, redirect, or private-address… | |
| Aplazada | Baja (2.1) | 0.39% | — | Langgenius DifyAIPocoo Jinja2AI | 3/8/2026 | 12/8/2026 | A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the component Jinja2 Handler. The manipulation results in improper neutralization of special elements used in a template engine.… | |
| Pendiente de análisis | Media (5.4) | 0.29% | — | DifyAI | 29/7/2026 | 30/7/2026 | Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The… | |
| Aplazada | Media (5) | 0.36% | — | ShortcodifyAI | 28/7/2026 | 28/7/2026 | The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject… | |
| Analizada | Alta (8.7) | 0.50% | — | Dify | 10/7/2026 | 17/7/2026 | Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search parameters to the search_by_full_text method without escaping or parameterization. Attackers can inject malicious SQL through the search… | |
| Aplazada | Media (6.5) | 0.44% | — | Addify TAX Exempt FOR WoocommerceAI | 2/7/2026 | 28/7/2026 | Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5. | |
| Aplazada | Media (5.3) | 0.29% | — | Xtendify WofficeAI | 1/7/2026 | 1/7/2026 | Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33. | |
| Aplazada | Alta (7.1) | 0.25% | — | Astoundify JobifyAI | 29/6/2026 | 29/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions. | |
| Aplazada | Alta (8.6) | 0.42% | — | FedifyAI | 10/6/2026 | 21/7/2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validation before runtime document and media fetching. However, the IPv4 validation logic present starting in version 0.11.2 and… | |
| Aplazada | Alta (7) | 0.25% | — | FedifyAI | 10/6/2026 | 23/7/2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to restructure a JSON-LD document that would change how Fedify interprets it without changing its Linked Data Signature,… | |
| Modificada | Alta (8.2) | 0.57% | — | Dify | 18/5/2026 | 22/6/2026 | Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file's UUID. Attackers can access the /console/api/files/{file_id}/preview… | |
| Modificada | Crítica (9.3) | 1.9% | — | Dify | 18/5/2026 | 22/6/2026 | Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in… | |
| Modificada | Crítica (9.3) | 0.60% | — | Dify | 18/5/2026 | 22/6/2026 | Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. Attackers can exploit missing tenant ownership checks in the trace configuration endpoints to redirect all messages… | |
| Modificada | Media (6) | 0.47% | — | Langgenius Dify | 5/5/2026 | 24/7/2026 | Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files array of a chat-messages request. Attackers can exploit insufficient permission… | |
| Analizada | Media (6.9) | 0.34% | — | Langgenius Dify | 4/5/2026 | 17/6/2026 | Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/files/upload, which requires authentication through the application API, is also vulnerable. This issue has been patched… | |
| Analizada | Media (5.3) | 0.27% | — | Dify | 20/4/2026 | 17/6/2026 | Dify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/<appId>/conversations/<conversationId>` has poor authorization checking and allows any Dify-authenticated user to delete someone else's chat history. Version 1.13.1 patches the issue. | |
| Aplazada | Baja (2) | 0.33% | — | Langgenius DifyAI | 20/4/2026 | 17/6/2026 | A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/app/components/base/image-uploader/image-preview.tsx of the component ImagePreview. The manipulation of the argument filename leads to cross site scripting. The attack may be initiated remotely. The… | |
| Aplazada | Baja (2.1) | 0.35% | — | Langgenius DifyAI | 20/4/2026 | 17/6/2026 | A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundle of the file api/core/tools/utils/parser.py of the component ApiBasedToolSchemaParser. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be… | |
| Aplazada | Baja (2.1) | 0.35% | — | Langgenius DifyAI | 20/4/2026 | 17/6/2026 | A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provider_remote_schema of the file api/services/tools/api_tools_manage_service.py of the component ApiToolManageService. Performing a manipulation of the argument url results in server-side request… | |
| Analizada | Alta (7.5) | 0.66% | — | Fedify/fedifyFedify/vocab-runtime | 6/4/2026 | 17/6/2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote document loader and authenticated document loader without enforcing a maximum redirect count or visited-URL loop detection.… | |
| Aplazada | Alta (7.1) | 0.26% | — | Astoundify ListifyAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify Listify listify allows Reflected XSS.This issue affects Listify: from n/a through <= 3.2.5. | |
| Analizada | Media (5.1) | 0.23% | — | Dify | 3/3/2026 | 17/6/2026 | Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occurs because Dify’s default Mermaid configuration uses securityLevel: loose, which allows potentially unsafe content to execute. This vulnerability is… |