Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.37% | — | Gazellepw GazelleposterwallAI | 25/8/2026 | 31/8/2026 | GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 suffers from a Broken access control vulnerability in the IP lock manager, which allows remote authenticated users to add, modify, or delete IP lock entries for arbitrary accounts via tools.php?action=iplock. | |
| Aplazada | Media (5.4) | 0.36% | — | Gazellepw GazelleposterwallAI | 25/8/2026 | 31/8/2026 | A Stored XSS vulnerability in the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via a crafted subtitle filename, which is stored during upload and later rendered in /subtitles.php?action=delete. | |
| Aplazada | Media (6.1) | 0.40% | — | Gazellepw GazelleposterwallAI | 25/8/2026 | 31/8/2026 | A Stored XSS vulnerability in forum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote attackers to inject arbitrary JavaScript via the c parameter in /forums.php?action=ajax_get_jf which is later rendered in the data-tooltip attribute in… | |
| Aplazada | Media (4.3) | 0.34% | — | Gazellepw GazelleposterwallAI | 25/8/2026 | 31/8/2026 | A Broken access control vulnerability in the API user endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a normal user-created API token. | |
| Aplazada | Media (5.4) | 0.36% | — | Gazellepw GazelleposterwallAI | 25/8/2026 | 31/8/2026 | A Stored XSS vulnerability in the custom bonus title feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the title parameter in /bonus.php and /user.php?action=staff_tool. | |
| Aplazada | Media (5.4) | 0.31% | — | Gazellepw GazelleposterwallAI | 25/8/2026 | 31/8/2026 | A SQL injection vulnerability in the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users with users_mod privileges to execute arbitrary SQL commands via the tagid or type parameter in a crafted POST request to tools.php?action=manage_tags. | |
| Aplazada | Media (5.4) | 0.36% | — | Gazellepw GazelleposterwallAI | 25/8/2026 | 31/8/2026 | A Stored XSS vulnerability in the donor avatar mouse-over text feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the avatar_mouse_over_text parameter, which is stored and later rendered in avatar tooltip. |