Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.45%—ElggAI22/7/202622/7/2026
Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
ModificadaMedia (5.4)0.70%—Elgg24/12/202117/6/2026
elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaAlta (7.5)1.6%—Elgg3/12/202117/6/2026
elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
ModificadaMedia (5.9)0.80%—Elgg1/12/202117/6/2026
elgg is vulnerable to Authorization Bypass Through User-Controlled Key
ModificadaCrítica (9.8)1.5%—Elgg12/11/201916/6/2026
Elgg through 1.7.10 has a SQL injection vulnerability
ModificadaMedia (6.1)1.1%—Elgg12/11/201916/6/2026
Elgg through 1.7.10 has XSS
ModificadaMedia (6.1)1.2%—Elgg8/4/201917/6/2026
Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.
ModificadaMedia (4.3)1.5%—Elgg2/2/201416/6/2026
Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inject arbitrary web script or HTML via the params[twitter_username] parameter to action/widgets/save.
ModificadaMedia (4.3)1.2%—Elgg23/5/201316/6/2026
engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.
ModificadaMedia (6.8)1.3%—Elgg23/5/201316/6/2026
engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to create arbitrary accounts.
ModificadaMedia (4.3)1.2%—Elgg23/5/201316/6/2026
Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the view parameter to index.php. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)1.3%—Elgg23/9/201116/6/2026
Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by vendors/simpletest/test/visual_test.php and certain other files.
ModificadaMedia (4.3)2.8%—Curveriderhq Elgg10/9/200916/6/2026
Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parameter. NOTE: some of these details are obtained from third party information.