Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.50% | 💥 PoC | Easycms | 8/3/2026 | 17/6/2026 | A security flaw has been discovered in EasyCMS up to 1.6. The impacted element is an unknown function of the file /RbacuserAction.class.php of the component Request Parameter Handler. The manipulation of the argument _order results in sql injection. The attack can be launched remotely. The exploit has been released to… | |
| Analizada | Baja (2.1) | 0.50% | — | Easycms | 8/3/2026 | 17/6/2026 | A vulnerability was identified in EasyCMS up to 1.6. The affected element is an unknown function of the file /RbacnodeAction.class.php of the component Request Parameter Handler. The manipulation of the argument _order leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and… | |
| Analizada | Media (5.5) | 0.48% | — | Easycms | 18/1/2026 | 17/6/2026 | A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.php. Such manipulation of the argument _order leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about… | |
| Modificada | Crítica (9.8) | 1.2% | — | Easycms | 16/2/2022 | 17/6/2026 | EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement. | |
| Modificada | Alta (8.8) | 0.60% | — | Easycms | 1/2/2021 | 17/6/2026 | A CSRF vulnerability was discovered in EasyCMS v1.6 that can add an admin account through index.php?s=/admin/rbacuser/insert/navTabId/rbacuser/callbackType/closeCurrent, then post username=***&password=***. | |
| Modificada | Alta (8.8) | 0.52% | — | Easycms | 15/1/2019 | 17/6/2026 | An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/callbackType/closeCurrent URI. | |
| Modificada | Media (6.1) | 0.64% | — | Easycms | 17/9/2018 | 17/6/2026 | App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter, a related issue to CVE-2018-9173. | |
| Modificada | Media (4.8) | 0.55% | — | Easycms | 10/9/2018 | 17/6/2026 | EasyCMS 1.5 allows XSS via the index.php?s=/admin/fields/update/navTabId/listfields/callbackType/closeCurrent content field. | |
| Modificada | Media (6.1) | 0.71% | — | Easycms | 9/9/2018 | 17/6/2026 | The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via an onhashchange event. | |
| Modificada | Alta (8.8) | 0.52% | — | Easycms | 2/9/2018 | 17/6/2026 | An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/admin/rbacuser/update/navTabId/listusers/callbackType/closeCurrent. | |
| Modificada | Media (6.5) | 0.45% | — | Easycms | 29/6/2018 | 17/6/2026 | EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users. | |
| Modificada | Media (5.4) | 0.53% | — | Easycms Project Easycms | 28/4/2018 | 17/6/2026 | EasyCMS 1.3 is prone to Stored XSS when posting an article; four fields are affected: title, keyword, abstract, and content, as demonstrated by the /admin/index/index.html#listarticle URI. | |
| Modificada | Media (6.1) | 0.67% | — | Easycms | 25/4/2018 | 17/6/2026 | EasyCMS 1.3 has XSS via the s POST parameter (aka a search box value) in an index.php?s=/index/search/index.html request. |