Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
379 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.54% | — | Getgrav Dom-sanitizerAI | 1/10/2026 | 1/10/2026 | A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component SVG Sanitization. Such manipulation leads to incomplete blacklist. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Alta (7.5) | 0.29% | — | Gravityexport LiteAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions. | |
| Aplazada | Alta (8.4) | 0.29% | — | Getgrav Grav Plugin DatamanagerAI | 26/9/2026 | 30/9/2026 | The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by… | |
| Aplazada | Alta (8.7) | 0.45% | — | Getgrav Grav Plugin CommentsAI | 26/9/2026 | 28/9/2026 | The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that returns comment data as JSON without any authentication check. The handler branches on isAdmin(), which only indicates that the admin service is registered on the current route rather than that the… | |
| Aplazada | Alta (8.6) | 0.29% | — | Getgrav GravAI | 26/9/2026 | 28/9/2026 | Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Twig has been explicitly enabled — page content authored by a user holding only page-write permission is rendered through a Twig sandbox that allowlists get_cookie(), which returns any cookie sent with… | |
| Aplazada | Alta (8.7) | 0.30% | — | Getgrav Grav CMSAI | 26/9/2026 | 30/9/2026 | Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The access map is gated by a `security@: admin.super` guard that is resolved by the field's exact path, so a submitted flat dot-notation key such as `access.admin.super` (instead of the nested… | |
| Aplazada | Alta (8.7) | 0.44% | — | Getgrav GravAI | 26/9/2026 | 30/9/2026 | Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. In webserver-configs/web.config (IIS), every deny rule (user_sensitive_folders, user_accounts, user_data, user_error_redirect, user_pages, system, vendor, ignore_folders) sets ignoreCase="false" on… | |
| Aplazada | Alta (7.1) | 0.28% | — | Getgrav GravAI | 26/9/2026 | 28/9/2026 | Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is on the sandbox allowlist but is registered without the needs_is_sandboxed guard that print_r, vardump, json_encode, yaml_encode and string carry, and its implementation calls toArray() — or falls… | |
| Aplazada | Media (6.9) | 0.31% | — | Grav-plugin-loginAI | 26/9/2026 | 28/9/2026 | grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challenge to be bypassed for content gated by the authenticated() Twig function or the [authenticated] shortcode. On sites with 2FA enabled, Login::isAuthenticated() checked only the session flag indicating… | |
| Aplazada | Crítica (9.8) | 3.9% | — | Gravityforms Gravity FormsAI | 19/9/2026 | 21/9/2026 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a… | |
| Aplazada | Crítica (9.8) | 0.68% | — | GravitlauncherAI | 17/9/2026 | 24/9/2026 | GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274. FileServerHandler.channelRead0 in… | |
| Aplazada | Alta (8.7) | 0.46% | — | Getgrav GravAI | 17/9/2026 | 19/9/2026 | Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, yaml_encode, string): GravExtension::assertSandboxDumpSafe() determines sandbox state by calling SandboxExtension::isSandboxed() without a Source… | |
| Aplazada | Alta (8.7) | 0.50% | — | Getgrav GravAI | 17/9/2026 | 30/9/2026 | Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the default), the Clockwork profiler endpoint is exposed without authentication: InitializeProcessor::handleDebuggerRequest() intercepts any path containing… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Multi Uploader FOR Gravity FormsAI | 17/9/2026 | 19/9/2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload… | |
| Aplazada | Baja (2) | 0.36% | — | Creolabs GravityAI | 14/9/2026 | 16/9/2026 | A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of the file src/compiler/gravity_parser.c of the component Number Parser. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The exploit is now… | |
| Aplazada | Media (5.5) | 0.64% | — | Creolabs GravityAI | 14/9/2026 | 14/9/2026 | A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the file src/utils/gravity_json.c of the component udp json-parser. Such manipulation leads to integer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may… | |
| Aplazada | Baja (2.1) | 0.47% | — | Creolabs GravityAI | 14/9/2026 | 15/9/2026 | A weakness has been identified in marcobambini Gravity up to 0.9.7. The impacted element is an unknown function of the file src/utils/gravity_json.c of the component JSON parser. This manipulation causes memory corruption. The attack is possible to be carried out remotely. The exploit has been made available to the… | |
| Aplazada | Baja (1.8) | 0.30% | — | Getgrav GravAI | 13/9/2026 | 16/9/2026 | Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content. | |
| Aplazada | Alta (7.2) | 0.51% | — | Repeater Fields FOR Gravity FormsAI | 9/9/2026 | 9/9/2026 | The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (5.1) | 0.41% | — | Getgrav GravAI | 5/9/2026 | 10/9/2026 | Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject arbitrary script by registering malicious assets or injecting attributes, which are rendered unescaped into… | |
| Aplazada | Alta (8.7) | 0.43% | — | Getgrav GravAI | 5/9/2026 | 8/9/2026 | Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header,… | |
| Aplazada | Alta (8.7) | 0.39% | — | Getgrav Grav-plugin-apiAI | 5/9/2026 | 8/9/2026 | grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. A non-super user manager with api.access and api.users.write permissions can… | |
| Aplazada | Alta (8.7) | 0.36% | — | Getgrav Grav-plugin-apiAI | 5/9/2026 | 8/9/2026 | grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control. | |
| Aplazada | Media (6.9) | 0.56% | — | Getgrav Grav Form PluginAI | 5/9/2026 | 18/9/2026 | Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name to trigger save, upload, email, or call… | |
| Aplazada | Alta (7.2) | 0.19% | — | Gravityforms Gravity FormsAI | 5/9/2026 | 8/9/2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… |