Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.85% | — | B2evolution CMSAI | 17/9/2026 | 23/9/2026 | b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to… | |
| Aplazada | Alta (8.7) | 0.64% | — | Evolution CMSAI | 10/5/2026 | 25/7/2026 | Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitrary system commands by injecting PHP code into module parameters. Attackers can send POST requests to /manager/index.php with malicious PHP code in the 'post' parameter… | |
| Modificada | Media (5.2) | 0.47% | — | Evolution CMS | 19/10/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected into the cmsadmin, cmsadminemail, cmspassword and cmspasswordconfim parameters | |
| Modificada | Media (6.1) | 0.59% | — | Evolution CMS | 19/10/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in evolution evo v.3.2.3 allows a local attacker to execute arbitrary code via a crafted payload injected uid parameter. | |
| Modificada | Alta (7.2) | 1.1% | — | B2evolution CMS | 3/1/2023 | 17/6/2026 | In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it." | |
| Modificada | Crítica (9.8) | 1.9% | — | B2evolution CMS | 6/12/2021 | 17/6/2026 | b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input. | |
| Modificada | Alta (8.8) | 0.55% | — | B2evolution CMS | 6/12/2021 | 17/6/2026 | b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges. | |
| Modificada | Media (5.4) | 0.50% | — | Evolution CMS | 26/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Evolution CMS 2.0.2 via the Document Manager feature. | |
| Modificada | Media (6.1) | 4.5% | — | B2evolution CMS | 9/2/2021 | 17/6/2026 | Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter. | |
| Modificada | Media (5.4) | 1.2% | — | Modx Evolution CMS | 15/8/2019 | 17/6/2026 | Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel. | |
| Modificada | Media (5.4) | 0.57% | — | Modx Evolution CMS | 28/12/2018 | 17/6/2026 | Evolution CMS 1.4.x allows XSS via the manager/ search parameter. | |
| Modificada | Media (5.4) | 0.57% | — | Modx Evolution CMS | 28/12/2018 | 17/6/2026 | Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI. | |
| Modificada | Media (6.8) | 1.9% | — | Phoenix Evolution CMS | 29/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Phoenix Evolution CMS (PECMS) allow remote attackers to inject arbitrary web script or HTML via the (1) mod or (2) action parameters in index.php, or the (3) pageid parameter in modules/pageedit/index.php. NOTE: the provenance of this information is unknown; the… |