Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.55% | — | EtherpadAI | 19/8/2026 | 9/9/2026 | Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without HTML attribute escaping. A pad editor can place an attacker-controlled value into the attribute pool… | |
| Aplazada | Crítica (9.9) | 0.46% | — | EtherpadAI | 19/8/2026 | 9/9/2026 | Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredClaims with the admin claim. This check requires only that the claim exists, while src/node/security/OAuth2Provider.ts… | |
| Aplazada | Media (6.8) | 0.44% | — | EtherpadAI | 19/8/2026 | 9/9/2026 | Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and exposes it through GET /tokenTransfer/{uuid}. Although the record includes createdAt, the transfer has no… | |
| Aplazada | Media (6.1) | 0.58% | — | EtherpadAI | 19/8/2026 | 9/9/2026 | Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admin without sanitization, Vary: x-proxy-path, or Cache-Control: private, no-store. A… | |
| Aplazada | Media (4.2) | 0.14% | — | EtherpadAI | 19/8/2026 | 9/9/2026 | Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared world-writable temporary directory, a local unprivileged attacker who predicts a… | |
| Aplazada | Crítica (9.6) | 0.47% | — | EtherpadAI | 19/8/2026 | 9/9/2026 | Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attribute before assigning the generated markup to node.innerHTML. ImportEtherpad.setPadRaw in… | |
| Modificada | Alta (8.8) | 2.1% | — | Etherpad | 9/12/2021 | 17/6/2026 | Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file that, when imported, might allow the attacker to gain admin privileges for the Etherpad instance. This, in turn, can be used to install a malicious Etherpad plugin that can execute arbitrary code… | |
| Modificada | Alta (7.2) | 2.2% | — | Etherpad | 21/7/2021 | 17/6/2026 | An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source. | |
| Modificada | Media (6.1) | 1.3% | — | Etherpad | 19/7/2021 | 17/6/2026 | A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary JavaScript or HTML by importing a crafted pad. | |
| Modificada | Alta (7.5) | 1.1% | — | Etherpad | 28/4/2021 | 17/6/2026 | Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check. | |
| Modificada | Alta (7.5) | 1.0% | — | Etherpad Ueberdb | 28/4/2021 | 17/6/2026 | In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names. | |
| Modificada | Media (6.5) | 0.64% | — | Etherpad | 28/4/2021 | 17/6/2026 | Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backend supported by Etherpad. | |
| Modificada | Alta (7.5) | 1.1% | — | Etherpad | 28/4/2021 | 17/6/2026 | Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import endpoint would crash the instance. | |
| Modificada | Alta (7.5) | 1.1% | — | Etherpad | 28/4/2021 | 17/6/2026 | In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance). | |
| Modificada | Alta (7.5) | 2.3% | — | Etherpad | 13/2/2020 | 17/6/2026 | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files with permissions of the user running the service via a .. (dot dot) in the path parameter of HTTP API requests. NOTE: This vulnerability is due to an incomplete fix to CVE-2015-3297. | |
| Modificada | Media (6.1) | 0.68% | — | Etherpad | 19/10/2019 | 17/6/2026 | templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer. | |
| Modificada | Crítica (9.8) | 13% | — | Etherpad Lite | 29/4/2018 | 17/6/2026 | Etherpad Lite before 1.6.4 is exploitable for admin access. | |
| Modificada | Alta (8.1) | 1.6% | — | Etherpad | 7/4/2018 | 17/6/2026 | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document database (DirtyDB, CouchDB, MongoDB, or RethinkDB). | |
| Modificada | Crítica (9.8) | 2.0% | — | Etherpad | 7/4/2018 | 17/6/2026 | Etherpad 1.6.3 before 1.6.4 allows an attacker to execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.2% | — | Etherpad | 7/4/2018 | 17/6/2026 | Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names. | |
| Modificada | Crítica (9.8) | 2.3% | — | Etherpad | 8/2/2018 | 17/6/2026 | node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions. | |
| Modificada | Media (6.1) | 0.88% | — | Etherpad Lite | 8/2/2018 | 17/6/2026 | static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href. | |
| Modificada | Alta (7.5) | 2.3% | — | Etherpad | 12/1/2018 | 17/6/2026 | node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper substring check when exporting a padID. | |
| Modificada | Alta (7.5) | 2.3% | — | Etherpad | 7/9/2017 | 17/6/2026 | Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1. | |
| Modificada | Alta (7.5) | 5.0% | — | Etherpad | 7/7/2017 | 17/6/2026 | Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.1 through 1.5.2 allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests. |