Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.73% | — | Gibbonedu GibbonAI | 25/9/2026 | 28/9/2026 | A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlock of the file modules/Planner/units_add_blockAjax.php of the component Unit Planner. The manipulation of the argument gibbonUnitBlockID/mode leads to missing authentication. The attack is possible to be… | |
| Aplazada | Media (6.9) | 0.39% | — | GibbonAI | 9/5/2026 | 24/7/2026 | Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction results in deletion of the file and a DOS condition. Successful exploitation requires Teacher or higher privileges. Exploitation could result in… | |
| Aplazada | Alta (8.9) | 0.40% | — | GibbonAI | 9/5/2026 | 24/7/2026 | Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user provided .zip as PHP. Successful exploitation requires Teacher or higher privileges. Exploitation could result in compromise of the… | |
| Aplazada | Alta (7) | 0.38% | — | Gibsonedu GibbonAI | 9/5/2026 | 24/7/2026 | Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/GibbonEdu/core/blob/c431e25fdc874adece5d2dc7e408e9aa2d1abadb/modules/Tracking/graphing.php#L145 feature. Successful exploitation requires Teacher or higher privileges.… | |
| Analizada | Alta (8.8) | 0.18% | — | Gibbonedu Gibbon | 27/5/2025 | 17/6/2026 | Gibbon before 29.0.00 allows CSRF. | |
| Analizada | Baja (3.5) | 0.61% | — | Gibbonedu Gibbon | 21/11/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain sensitive information via the email parameter found in /Gibbon/modules/User Admin/user_manage_editProcess.php. | |
| Analizada | Media (6.1) | 0.84% | — | Gibbonedu Gibbon | 10/9/2024 | 17/6/2026 | cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the library_manage_catalog_editProcess.php component. | |
| Analizada | Crítica (9.8) | 26% | — | Gibbonedu Gibbon | 3/4/2024 | 17/6/2026 | Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization. | |
| Analizada | Alta (8.8) | 51% | — | Gibbonedu Gibbon | 23/3/2024 | 17/6/2026 | Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI. | |
| Modificada | Media (6.1) | 0.50% | — | Gibbonedu Gibbon | 14/11/2023 | 17/6/2026 | GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS. The imageAsLinks parameter must be set to Y to return HTML code. The filename attribute of the bodyfile1 parameter is reflected in the response. | |
| Modificada | Alta (7.2) | 1.2% | — | Gibbonedu Gibbon | 14/11/2023 | 17/6/2026 | GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname (and extension). This allows creation of PHP files outside of the uploads directory, directly in… | |
| Modificada | Media (5.4) | 0.46% | — | Gibbonedu Gibbon | 14/11/2023 | 17/6/2026 | GibbonEdu Gibbon version 25.0.0 allows HTML Injection via an IFRAME element to the Messager component. | |
| Modificada | Crítica (9.8) | 63% | — | Gibbonedu Gibbon | 14/11/2023 | 17/6/2026 | GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img parameter is expected to be a base64 encoded image. If the path parameter is set, the defined path… | |
| Modificada | Media (6.1) | 1.9% | — | Gibbonedu Gibbon | 29/6/2023 | 17/6/2026 | Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code. | |
| Modificada | Crítica (9.8) | 47% | — | Gibbonedu Gibbon | 29/6/2023 | 17/6/2026 | Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response. | |
| Modificada | Alta (8.8) | 0.92% | — | Gibbonedu Gibbon | 25/5/2022 | 9/7/2026 | Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation. | |
| Modificada | Crítica (9.8) | 1.6% | — | Gibbon Project Gibbon | 25/4/2022 | 17/6/2026 | Gibbon v3.4.4 and below allows attackers to execute a Server-Side Request Forgery (SSRF) via a crafted URL. | |
| Modificada | Media (5.4) | 0.62% | — | Gibbonedu Gibbon | 3/2/2022 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitrary web scripts or HTML via a crafted payload insterted into the name, category, description parameters. | |
| Modificada | Media (4.8) | 0.86% | — | Gibbonedu Gibbon | 28/1/2022 | 17/6/2026 | Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting (XSS) vulnerability, that allows attackers to inject arbitrary script via name parameters. | |
| Modificada | Media (5.4) | 0.74% | — | Gibbonedu Gibbon | 13/9/2021 | 17/6/2026 | Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component. | |
| Modificada | Media (6.1) | 2.3% | — | Gibbonedu Gibbon | 3/9/2021 | 17/6/2026 | A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents to index.php). |