Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
–

70 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.21%—Exponent CMSAI10/5/202625/7/2026
Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to execute arbitrary JavaScript. The…
ModificadaAlta (7.5)0.60%—Exponentcms Exponent CMS17/2/202317/6/2026
SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class.
ModificadaMedia (5.4)3.0%—Exponentcms Exponent CMS9/2/202217/6/2026
Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header when logging in. When an administrator user visits the "User Sessions" tab, the JavaScript will be triggered allowing an attacker to compromise the administrator session.
ModificadaAlta (7.2)2.1%—Exponentcms Exponent CMS9/2/202217/6/2026
Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where can be accessed in order to execute commands.
ModificadaMedia (4.8)2.9%—Exponentcms Exponent CMS9/2/202217/6/2026
Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site Title" and "Site Header" parameters while updating the site settings on "/exponentcms/administration/configure_site"
ModificadaCrítica (9.8)1.3%—Exponentcms Exponent CMS31/12/202017/6/2026
Exponent CMS before 2.6.0 has improper input validation in fileController.php.
ModificadaCrítica (9.8)1.3%—Exponentcms Exponent CMS31/12/202017/6/2026
Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.
ModificadaCrítica (9.8)1.3%—Exponentcms Exponent CMS31/12/202017/6/2026
Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.
ModificadaCrítica (9.8)1.3%—Exponentcms Exponent CMS31/12/202017/6/2026
Exponent CMS before 2.6.0 has improper input validation in usersController.php.
ModificadaCrítica (9.8)1.3%—Exponentcms Exponent CMS31/12/202017/6/2026
Exponent CMS before 2.6.0 has improper input validation in storeController.php.
ModificadaCrítica (9.8)2.1%—Exponentcms Exponent CMS24/5/201917/6/2026
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change_tags.
ModificadaCrítica (9.8)1.8%—Exponentcms Exponent CMS24/5/201917/6/2026
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.
ModificadaCrítica (9.8)2.1%—Exponentcms Exponent CMS23/5/201917/6/2026
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats.
ModificadaCrítica (9.8)1.8%—Exponentcms Exponent CMS23/5/201917/6/2026
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.
ModificadaCrítica (9.8)2.2%—Exponentcms Exponent CMS7/3/201817/6/2026
Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."
ModificadaAlta (7.2)1.4%—Exponentcms Exponent CMS4/3/201817/6/2026
In Exponent CMS before 2.4.1 Patch #6, certain admin users can elevate their privileges.
ModificadaMedia (6.1)1.5%—Exponentcms Exponent CMS28/8/201717/6/2026
Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2.
ModificadaMedia (6.1)1.1%—Exponentcms Exponent CMS24/4/201717/6/2026
In Exponent CMS before 2.4.1 Patch #5, XSS in elFinder is possible in framework/modules/file/connector/elfinder.php.
ModificadaCrítica (9.8)2.1%—Exponentcms Exponent CMS22/4/201717/6/2026
Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.
ModificadaCrítica (9.8)2.2%—Exponentcms Exponent CMS7/3/201717/6/2026
SQL injection vulnerability in framework/modules/filedownloads/controllers/filedownloadController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the fileid parameter.
ModificadaCrítica (9.8)3.1%—Exponentcms Exponent CMS7/3/201717/6/2026
SQL injection vulnerability in framework/modules/help/controllers/helpController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.
ModificadaCrítica (9.8)3.3%—Exponentcms Exponent CMS7/3/201717/6/2026
SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.
ModificadaCrítica (9.8)2.5%—Exponentcms Exponent CMS7/3/201717/6/2026
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter.
ModificadaCrítica (9.8)2.6%—Exponentcms Exponent CMS7/3/201717/6/2026
SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaCrítica (9.8)2.6%—Exponentcms Exponent CMS7/3/201717/6/2026
SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.