Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2630▼ 215 respecto a la semana anterior
Críticas / altas1379▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.24% | — | Getgrav Grav-plugin-admin2AI | 4/9/2026 | 8/9/2026 | Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into translation templates before parsing the result as markdown. Grav's server-side username… | |
| Aplazada | Alta (8.7) | 0.36% | — | Getgrav Grav-plugin-admin2AIGetgrav GravAI | 11/7/2026 | 13/7/2026 | The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This object is returned in every unauthenticated response and discloses the server URL, API prefix, admin base path, runtime… | |
| Aplazada | Alta (8.7) | 0.36% | — | Getgrav Grav-plugin-adminAI | 10/7/2026 | 10/7/2026 | grav-plugin-admin is an HTML user interface that provides a way to configure Grav and create and modify pages. In 1.10.52 and earlier, an authenticated attacker with admin.users permission can change the password of any user account, including the super administrator, by sending a direct POST request to… | |
| Aplazada | Media (6.2) | 0.43% | — | Getgrav Grav-plugin-adminAI | 11/5/2026 | 17/6/2026 | grav-plugin-admin is the admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.10.49.5, the application fails to properly validate and sanitize user input in the data[header][title] parameter. As a result, attackers can craft a… | |
| Analizada | Media (6.2) | 0.21% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 17/6/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows… | |
| Analizada | Media (6.2) | 0.23% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 17/6/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows… | |
| Analizada | Media (6.8) | 0.21% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 17/6/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/config/site endpoint of the Grav application. This vulnerability allows… | |
| Analizada | Media (6.2) | 0.21% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 25/9/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/accounts/groups/Grupo endpoint of the Grav application. This vulnerability… | |
| Analizada | Media (6.2) | 0.21% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 25/9/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the /admin/pages/[page] endpoint of the Grav application. This vulnerability allows… | |
| Analizada | Media (5.3) | 0.32% | — | Getgrav Grav-plugin-admin | 1/12/2025 | 25/9/2026 | This admin plugin for Grav is an HTML user interface that provides a convenient way to configure Grav and easily create and modify pages. Prior to 1.11.0-beta.1, a user enumeration and email disclosure vulnerability exists in Grav. The "Forgot Password" functionality at /admin/forgot leaks information about valid… | |
| Modificada | Media (5.4) | 1.4% | — | Getgrav Grav-plugin-admin | 19/11/2021 | 17/6/2026 | grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (5.4) | 1.6% | — | Getgrav Grav-plugin-admin | 27/9/2021 | 17/6/2026 | grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames | |
| Modificada | Crítica (9.8) | 81% | — | Getgrav Grav-plugin-admin | 7/4/2021 | 17/6/2026 | Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versions 1.10.7 and earlier, an unauthenticated user can execute some methods of administrator controller without needing any credentials. Particular method execution will result in arbitrary YAML file… |