Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.21% | — | Exponent CMSAI | 10/5/2026 | 25/7/2026 | Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to execute arbitrary JavaScript. The… | |
| Modificada | Alta (7.5) | 0.60% | — | Exponentcms Exponent CMS | 17/2/2023 | 17/6/2026 | SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class. | |
| Modificada | Media (5.4) | 3.0% | — | Exponentcms Exponent CMS | 9/2/2022 | 17/6/2026 | Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header when logging in. When an administrator user visits the "User Sessions" tab, the JavaScript will be triggered allowing an attacker to compromise the administrator session. | |
| Modificada | Alta (7.2) | 2.1% | — | Exponentcms Exponent CMS | 9/2/2022 | 17/6/2026 | Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where can be accessed in order to execute commands. | |
| Modificada | Media (4.8) | 2.9% | — | Exponentcms Exponent CMS | 9/2/2022 | 17/6/2026 | Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site Title" and "Site Header" parameters while updating the site settings on "/exponentcms/administration/configure_site" | |
| Modificada | Crítica (9.8) | 1.3% | — | Exponentcms Exponent CMS | 31/12/2020 | 17/6/2026 | Exponent CMS before 2.6.0 has improper input validation in fileController.php. | |
| Modificada | Crítica (9.8) | 1.3% | — | Exponentcms Exponent CMS | 31/12/2020 | 17/6/2026 | Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php. | |
| Modificada | Crítica (9.8) | 1.3% | — | Exponentcms Exponent CMS | 31/12/2020 | 17/6/2026 | Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php. | |
| Modificada | Crítica (9.8) | 1.3% | — | Exponentcms Exponent CMS | 31/12/2020 | 17/6/2026 | Exponent CMS before 2.6.0 has improper input validation in usersController.php. | |
| Modificada | Crítica (9.8) | 1.3% | — | Exponentcms Exponent CMS | 31/12/2020 | 17/6/2026 | Exponent CMS before 2.6.0 has improper input validation in storeController.php. | |
| Modificada | Crítica (9.8) | 2.1% | — | Exponentcms Exponent CMS | 24/5/2019 | 17/6/2026 | Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change_tags. | |
| Modificada | Crítica (9.8) | 1.8% | — | Exponentcms Exponent CMS | 24/5/2019 | 17/6/2026 | Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php. | |
| Modificada | Crítica (9.8) | 2.1% | — | Exponentcms Exponent CMS | 23/5/2019 | 17/6/2026 | Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats. | |
| Modificada | Crítica (9.8) | 1.8% | — | Exponentcms Exponent CMS | 23/5/2019 | 17/6/2026 | Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php. | |
| Modificada | Crítica (9.8) | 2.2% | — | Exponentcms Exponent CMS | 7/3/2018 | 17/6/2026 | Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location." | |
| Modificada | Alta (7.2) | 1.4% | — | Exponentcms Exponent CMS | 4/3/2018 | 17/6/2026 | In Exponent CMS before 2.4.1 Patch #6, certain admin users can elevate their privileges. | |
| Modificada | Media (6.1) | 1.5% | — | Exponentcms Exponent CMS | 28/8/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2. | |
| Modificada | Media (6.1) | 1.1% | — | Exponentcms Exponent CMS | 24/4/2017 | 17/6/2026 | In Exponent CMS before 2.4.1 Patch #5, XSS in elFinder is possible in framework/modules/file/connector/elfinder.php. | |
| Modificada | Crítica (9.8) | 2.1% | — | Exponentcms Exponent CMS | 22/4/2017 | 17/6/2026 | Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php. | |
| Modificada | Crítica (9.8) | 2.2% | — | Exponentcms Exponent CMS | 7/3/2017 | 17/6/2026 | SQL injection vulnerability in framework/modules/filedownloads/controllers/filedownloadController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the fileid parameter. | |
| Modificada | Crítica (9.8) | 3.1% | — | Exponentcms Exponent CMS | 7/3/2017 | 17/6/2026 | SQL injection vulnerability in framework/modules/help/controllers/helpController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter. | |
| Modificada | Crítica (9.8) | 3.3% | — | Exponentcms Exponent CMS | 7/3/2017 | 17/6/2026 | SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter. | |
| Modificada | Crítica (9.8) | 2.5% | — | Exponentcms Exponent CMS | 7/3/2017 | 17/6/2026 | SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter. | |
| Modificada | Crítica (9.8) | 2.6% | — | Exponentcms Exponent CMS | 7/3/2017 | 17/6/2026 | SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Crítica (9.8) | 2.6% | — | Exponentcms Exponent CMS | 7/3/2017 | 17/6/2026 | SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter. |