Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.84% | — | Html-js Doracms | 9/3/2026 | 17/6/2026 | A security flaw has been discovered in doramart DoraCMS 3.0.x. Impacted is the function createFileBypath of the file /DoraCMS/server/app/router/api/v1.js. Performing a manipulation results in path traversal. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.… | |
| Analizada | Media (5.5) | 0.99% | — | Html-js Doracms | 9/3/2026 | 17/6/2026 | A vulnerability was identified in doramart DoraCMS 3.0.x. This issue affects some unknown processing of the file /api/v1/mail/send of the component Email API. Such manipulation leads to improper authentication. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The… | |
| Aplazada | Media (6.9) | 0.40% | — | Html-js DoracmsAI | 10/2/2026 | 14/7/2026 | DoraCMS version 3.1 and prior contains a server-side request forgery (SSRF) vulnerability in its UEditor remote image fetch functionality. The application accepts user-supplied URLs and performs server-side HTTP or HTTPS requests without sufficient validation or destination restrictions. The implementation does not… | |
| Analizada | Alta (8.8) | 1.1% | — | Html-js Doracms | 19/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in DOraCMS v.2.18 and before allows a remote attacker to execute arbitrary code via the markdown0 function in the /app/public/apidoc/oas3/wrap-components/markdown.jsx endpoint. | |
| Modificada | Crítica (9.8) | 0.62% | — | Html-js Doracms | 29/1/2024 | 17/6/2026 | DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key. | |
| Modificada | Media (5.4) | 0.51% | — | Html-js Doracms | 8/12/2023 | 17/6/2026 | An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image file to the user avatar. | |
| Modificada | Crítica (9.8) | 0.81% | — | Html-js Doracms | 8/12/2023 | 17/6/2026 | DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerability allows attackers to gain access to the application via a bruteforce attack. | |
| Modificada | Crítica (9.8) | 1.5% | — | Html-js Doracms | 17/8/2022 | 17/6/2026 | DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request. | |
| Modificada | Media (4.8) | 0.44% | — | Html-js Doracms | 20/3/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Alta (7.5) | 0.41% | — | Html-js Doracms | 20/5/2021 | 17/6/2026 | Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks. | |
| Modificada | Media (5.4) | 0.79% | — | Html-js Doracms | 6/9/2018 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) discription or (2) comments field, related to users/userAddContent. |