Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
89 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.40% | — | Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the "Theme to Components" functionality (admin/components.php) via the title parameter. The stored title is… | |
| Aplazada | Alta (7.1) | 0.34% | — | Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated user with page-editing rights can store an arbitrary filesystem path in a page's template attribute. On the public front-end, this value is passed unsanitized to… | |
| Aplazada | Alta (8.8) | 0.26% | — | Getsimplecms Getsimple CMSAI | 1/10/2026 | 5/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is… | |
| Aplazada | Crítica (9.6) | 0.22% | — | Getsimplecms Getsimple CMS CEAI | 1/10/2026 | 6/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a… | |
| Aplazada | Alta (7.5) | 0.26% | — | Getsimplecms Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALIDATE_URL) — there is no validation of the request destination. An… | |
| Aplazada | Crítica (9.1) | 0.53% | — | Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written… | |
| Aplazada | Crítica (9.1) | 0.34% | — | Getsimple CMSAI | 1/10/2026 | 5/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Getsimple CMSAIGetsimple CMS CEAI | 11/9/2026 | 30/9/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security… | |
| Aplazada | Media (5.5) | 0.59% | — | Getsimpletool Mcpo-simple-serverAI | 29/4/2026 | 17/6/2026 | A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument detail causes relative path traversal. It is possible to initiate the attack… | |
| Analizada | Alta (8.8) | 0.32% | — | Getsimple-ce Getsimple CMS | 10/3/2026 | 17/6/2026 | GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite the gsconfig.php configuration file with arbitrary PHP code via the gsconfig editor module. The form lacks CSRF protection, enabling a remote… | |
| Modificada | Media (4.8) | 0.39% | — | Getsimple-ce Getsimple CMS | 24/2/2026 | 14/7/2026 | GetSimpleCMS Community Edition (CE) versions prior to 3.3.22 (3.3.16 tested) contains a stored cross-site scripting (XSS) vulnerability in the Theme to Components functionality within components.php. User-supplied input provided to the "slug" field of a component is stored without proper output encoding. While other… | |
| Analizada | Alta (8.8) | 0.54% | — | Getsimple-ce Getsimple CMS | 21/2/2026 | 17/6/2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time of publication. | |
| Analizada | Alta (8.7) | 0.47% | — | Getsimple-ce Getsimple CMS | 21/2/2026 | 17/6/2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess files to restrict access to sensitive directories such as /data/ and /backups/. If Apache AllowOverride is disabled (common in hardened or shared hosting environments), these protections are silently ignored, allowing… | |
| Analizada | Media (6.9) | 0.25% | — | Getsimple-ce Getsimple CMS | 21/2/2026 | 17/6/2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload functionality, but they are not properly sanitized or restricted, allowing an attacker to embed malicious JavaScript. When… | |
| Analizada | Alta (7.1) | 0.17% | — | Getsimple-ce Getsimple CMS | 21/2/2026 | 17/6/2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the administrative file upload endpoint. As a result, an attacker can craft a malicious web page that silently triggers a file upload request from an authenticated victim’s browser. The request is accepted… | |
| Aplazada | Alta (7.8) | 0.19% | — | Streetsidesoftware Vscode-spell-checkerAI | 9/2/2026 | 17/6/2026 | vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as the authoritative trust flag. The value defaults to true (package.json) and is read from workspace configuration each… | |
| Modificada | Media (4.8) | 0.27% | — | Get-simple Getsimplecms | 21/1/2026 | 17/6/2026 | GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin attempts to sanitize user input using htmlspecialchars(), but this can be bypassed by passing dangerous characters as escaped hex bytes. This allows attackers to inject arbitrary client-side code that… | |
| Analizada | Alta (8.5) | 0.27% | — | Get-simple Getsimplecms | 21/1/2026 | 17/6/2026 | GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attackers to inject arbitrary client-side code into administrator browsers. Attackers can craft a malicious website that triggers a cross-site scripting payload to execute remote code on the hosting… | |
| Analizada | Media (5.1) | 0.40% | — | Get-simple Getsimplecms | 21/1/2026 | 17/6/2026 | GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable… | |
| Analizada | Alta (8.6) | 1.3% | — | Get-simple Getsimplecms | 21/1/2026 | 17/6/2026 | GetSimple CMS My SMTP Contact Plugin 1.1.2 contains a PHP code injection vulnerability. An authenticated administrator can inject arbitrary PHP code through plugin configuration parameters, leading to remote code execution on the server. | |
| Aplazada | Alta (8.2) | 0.34% | — | Teknolojik Center Telecommunication Industry Trade CO LTD B2B Netsis PanelAI | 3/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknolojik Center Telecommunication Industry Trade Co. Ltd. B2B - Netsis Panel allows SQL Injection. This issue affects B2B - Netsis Panel: through 20251003. NOTE: The vendor was contacted early about this disclosure… | |
| Analizada | Alta (8.7) | 3.7% | — | Get-simple Getsimplecms | 25/7/2025 | 16/6/2026 | An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated users to upload arbitrary files without proper validation of MIME types or extensions. By uploading a .pht file containing PHP code, an attacker can bypass… | |
| Aplazada | Media (6.5) | 0.49% | — | Etsi Open-source ManoAI | 25/7/2025 | 17/6/2026 | The default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15.x, v.16.x, v.17.x does not impose any restrictions on the authentication attempts performed by the default admin user, allowing a remote attacker to escalate privileges. | |
| Aplazada | Alta (7.1) | 0.34% | — | Etsi OSMAI | 25/7/2025 | 5/7/2026 | An issue in ETSI Open-Source MANO (OSM) 14.0.x before 14.0.3, 15.0.x before 15.0.2, 16.0.0, and 17.0.0 allows a remote authenticated attacker to escalate privileges via the /osm/admin/v1/users component. | |
| Analizada | Alta (8.6) | 0.93% | — | Getsimple-ce Getsimple CMS | 30/5/2025 | 17/6/2026 | GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject arbitrary PHP into a component file and execute it via a crafted query string, resulting in Remote Code Execution (RCE). This issue is set to be patched in… |