Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.44% | — | Phoca GuestbookAI | 23/7/2026 | 24/7/2026 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability. | |
| Aplazada | Alta (8.8) | 0.27% | — | MGB Opensource GuestbookAI | 30/5/2026 | 22/7/2026 | MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to email.php with crafted SQL payloads in the 'id' parameter to extract sensitive… | |
| Aplazada | Media (5.1) | 0.19% | — | Advanced GuestbookAI | 10/5/2026 | 20/7/2026 | Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interface that allows authenticated attackers to inject malicious scripts by manipulating the s_emotion parameter. Attackers can submit POST requests to admin.php with JavaScript code in the s_emotion field,… | |
| Aplazada | Media (5.1) | 0.36% | — | Jlex GuestbookAI | 15/12/2025 | 17/6/2026 | JLex GuestBook 1.6.4 contains a reflected cross-site scripting vulnerability in the 'q' URL parameter that allows attackers to inject malicious scripts. Attackers can craft malicious links with XSS payloads to steal session tokens or execute arbitrary JavaScript in victims' browsers. | |
| Analizada | Alta (7.2) | 0.40% | — | Phpversion VX Guestbook | 4/9/2025 | 17/6/2026 | An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious SQL payloads via the "word" POST parameter in the words.php admin panel. | |
| Aplazada | Media (6.1) | 0.22% | — | Gwolle GuestbookAI | 10/7/2025 | 17/6/2026 | The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gwolle_gb_content’ parameter in all versions up to, and including, 4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (7.1) | 0.39% | — | Jamrizzi Technologies Rizzi GuestbookAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JamRizzi Technologies Rizzi Guestbook rizzi-guestbook allows Reflected XSS.This issue affects Rizzi Guestbook: from n/a through <= 4.0.1. | |
| Aplazada | Alta (7.1) | 0.26% | — | Marcel POL Gwolle GuestbookAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcel Pol Gwolle Guestbook gwolle-gb allows Reflected XSS.This issue affects Gwolle Guestbook: from n/a through <= 4.7.1. | |
| Modificada | Media (6.1) | 0.39% | — | Simplephpscripts Guestbook Script | 30/6/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts GuestBook Script 2.2. It has been classified as problematic. This affects an unknown part of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is recommended to… | |
| Modificada | Media (6.1) | 0.36% | — | Simple Guestbook Management System Project Simple Guestbook Management System | 6/4/2023 | 9/7/2026 | Sourcecodester Simple Guestbook Management System version 1 is vulnerable to Cross Site Scripting (XSS) via Name, Referrer, Location, and Comments. | |
| Modificada | Crítica (9.8) | 0.72% | — | Piwigo Guestbook | 6/1/2023 | 17/6/2026 | A vulnerability was found in Piwigo-Guest-Book up to 1.3.0. It has been declared as critical. This vulnerability affects unknown code of the file include/guestbook.inc.php of the component Navigation Bar. The manipulation of the argument start leads to sql injection. Upgrading to version 1.3.1 is able to address this… | |
| Modificada | Media (4.8) | 0.50% | — | Comment Guestbook Project Comment Guestbook | 30/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress. | |
| Modificada | Media (6.1) | 0.73% | — | Gwolle Guestbook Project Gwolle Guestbook | 23/6/2022 | 17/6/2026 | A vulnerability was found in Gwolle Guestbook Plugin 1.7.4. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting. The attack may be initiated remotely. | |
| Modificada | Media (6.1) | 0.80% | — | Gwolle Guestbook Project Gwolle Guestbook | 27/12/2021 | 17/6/2026 | The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin page | |
| Modificada | Media (5.4) | 0.70% | — | Syguestbook A5 Project Syguestbook A5 | 18/7/2019 | 17/6/2026 | index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment. | |
| Modificada | Alta (8.8) | 0.67% | — | Syguestbook A5 Project Syguestbook A5 | 18/7/2019 | 17/6/2026 | SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=update admin password change. | |
| Modificada | Media (5.4) | 0.70% | — | Syguestbook A5 Project Syguestbook A5 | 18/7/2019 | 17/6/2026 | SyGuestBook A5 Version 1.2 allows stored XSS because the isValidData function in include/functions.php does not properly block XSS payloads, as demonstrated by a crafted use of the onerror attribute of an IMG element. | |
| Modificada | Media (6.1) | 1.2% | — | Gwolle Guestbook Project Gwolle Guestbook | 2/10/2018 | 17/6/2026 | XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via the PATH_INFO to wp-admin/index.php | |
| Modificada | Crítica (9) | 37% | — | Gwolle Guestbook Project Gwolle Guestbook | 11/9/2017 | 17/6/2026 | PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and… | |
| Modificada | Media (4.3) | 0.93% | — | Shiromuku Guestbook | 7/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Mrs. Shiromuku Perl CGI shiromuku(u1)GUESTBOOK 1.62 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.7% | — | Mavili Guestbook Project Mavili Guestbook | 4/10/2012 | 16/6/2026 | Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) edit.asp, (2) delete.asp, or (3) approve.asp. | |
| Modificada | Media (5) | 1.5% | — | Mavili Guestbook Project Mavili Guestbook | 4/10/2012 | 16/6/2026 | Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attackers to read the database via a direct request. | |
| Modificada | Alta (7.5) | 1.3% | — | Mavili Guestbook Project Mavili Guestbook | 4/10/2012 | 16/6/2026 | SQL injection vulnerability in edit.asp in Mavili Guestbook, as released in November 2007, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Mavili Guestbook Project Mavili Guestbook | 4/10/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Mavili Guestbook, as released in November 2007, allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) approve.asp, (2) delete.asp, (3) edit.asp, or (4) edit2.asp. | |
| Modificada | Media (4.3) | 1.4% | — | Dnelubin Gelinsguestbook | 23/9/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in action/add-submit.php in Ggb Guestbook 0.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url or (2) message parameter. |