Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.45% | — | ElggAI | 22/7/2026 | 22/7/2026 | Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. | |
| Modificada | Media (5.4) | 0.70% | — | Elgg | 24/12/2021 | 17/6/2026 | elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Alta (7.5) | 1.6% | — | Elgg | 3/12/2021 | 17/6/2026 | elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor | |
| Modificada | Media (5.9) | 0.80% | — | Elgg | 1/12/2021 | 17/6/2026 | elgg is vulnerable to Authorization Bypass Through User-Controlled Key | |
| Modificada | Crítica (9.8) | 1.5% | — | Elgg | 12/11/2019 | 16/6/2026 | Elgg through 1.7.10 has a SQL injection vulnerability | |
| Modificada | Media (6.1) | 1.1% | — | Elgg | 12/11/2019 | 16/6/2026 | Elgg through 1.7.10 has XSS | |
| Modificada | Media (6.1) | 1.2% | — | Elgg | 8/4/2019 | 17/6/2026 | Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect. | |
| Modificada | Media (4.3) | 1.5% | — | Elgg | 2/2/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inject arbitrary web script or HTML via the params[twitter_username] parameter to action/widgets/save. | |
| Modificada | Media (4.3) | 1.2% | — | Elgg | 23/5/2013 | 16/6/2026 | engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors. | |
| Modificada | Media (6.8) | 1.3% | — | Elgg | 23/5/2013 | 16/6/2026 | engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to create arbitrary accounts. | |
| Modificada | Media (4.3) | 1.2% | — | Elgg | 23/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the view parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 1.3% | — | Elgg | 23/9/2011 | 16/6/2026 | Elgg 1.7.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by vendors/simpletest/test/visual_test.php and certain other files. | |
| Modificada | Media (4.3) | 2.8% | — | Curveriderhq Elgg | 10/9/2009 | 16/6/2026 | Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parameter. NOTE: some of these details are obtained from third party information. |