Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (8.6) | 0.31% | — | Joomshaper Easy StoreAI | 23/9/2026 | 23/9/2026 | Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php hardcoded return true;, bypassing Joomla component-level and asset-level ACL permission checks. Any authenticated backend user could… | |
| En análisis | Alta (7.2) | 0.17% | — | Joomshaper Easy StoreAI | 23/9/2026 | 23/9/2026 | Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF tokens inside the products() action. All other administrative AJAX endpoints (orders, coupons, media, customers,… | |
| En análisis | Alta (8.6) | 0.28% | — | Joomshaper Easy StoreAIJoomlaAI | 23/9/2026 | 25/9/2026 | Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdate) took input IDs and directly concatenated them into raw SQL IN (...) clauses in… | |
| En análisis | Alta (8.6) | 0.28% | — | Joomshaper Easy StoreAI | 23/9/2026 | 25/9/2026 | Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The media deletion endpoint (administrator/index.php?option=com_easystore&task=media.deleteImage) parsed the ids parameter as a comma-separated string and imploded it directly into… | |
| En análisis | Media (5.3) | 0.17% | — | Joomshaper Easy StoreAI | 23/9/2026 | 23/9/2026 | Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 - The product review submission endpoint (index.php?option=com_easystore&task=product.addReview) accepted submissions without verifying an anti-CSRF token (the check had been… | |
| En análisis | Alta (8.2) | 0.33% | — | Joomshaper Easy StoreAI | 23/9/2026 | 23/9/2026 | Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest checkout records solely by supplying an email address. The server returned complete shipping details (full name, phone number,… | |
| Aplazada | Media (6.9) | 0.45% | — | Joomshaper SP Page Builder PROAIJoomlaAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the result returned by the CAPTCHA plugin's onCheckAnswer event was discarded and replaced… | |
| Aplazada | Media (5.1) | 0.39% | — | Joomshaper SP Page BuilderAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not perform authorisation itself, because the relevant checks reside in the com_menus… | |
| Aplazada | Media (6.9) | 0.47% | — | Joomshaper SP Page BuilderAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The folder request parameter replaced the generated date-based destination folder in its entirety and was then passed to Folder::create() and File::upload() without either of the… | |
| Aplazada | Alta (7) | 0.47% | — | Joomshaper SP Page BuilderAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks used by the folder operations in the same controller, and its validation guard… | |
| Aplazada | Media (6.9) | 0.45% | — | Joomshaper SP Page Builder PROAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag from the request rather than from the stored addon configuration. Verification… | |
| Aplazada | Alta (8.6) | 0.37% | — | Joomla SP Page BuilderAIJoomshaper SP Page BuilderAI | 14/9/2026 | 16/9/2026 | Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id] from the request and concatenated it directly into the WHERE view_id = ...… | |
| Aplazada | Media (6.9) | 0.50% | — | Joomshaper SP PropertyAI | 10/9/2026 | 10/9/2026 | Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks. | |
| Aplazada | Media (6.9) | 0.43% | — | Joomshaper SP PropertyAI | 10/9/2026 | 10/9/2026 | Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing potential email manipulation. | |
| Aplazada | Alta (8.6) | 0.44% | — | Joomshaper SP PropertyAI | 10/9/2026 | 10/9/2026 | Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly into HTML without contextual escaping. | |
| Aplazada | Media (6.9) | 0.33% | — | Joomshaper SP PropertyAI | 10/9/2026 | 10/9/2026 | Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file removal actions with arbitrary path strings or upload unverified file types. | |
| Aplazada | Alta (7.1) | 0.21% | — | Joomshaper SP PropertyAI | 10/9/2026 | 10/9/2026 | Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) endpoints processed POST requests without verifying Joomla session anti-CSRF tokens. | |
| Aplazada | Crítica (9.3) | 0.51% | — | Joomshaper SP PropertyAI | 10/9/2026 | 10/9/2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and psize_range_dropdown) by directly concatenating raw… | |
| Aplazada | Media (5.3) | 0.41% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal. | |
| Aplazada | Alta (8.9) | 0.43% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated only file extension and basic size parameters. Non-image files disguised with raster extensions could be uploaded. Added strict MIME verification and GD binary raster… | |
| Aplazada | Alta (8.6) | 0.42% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual escaping, allowing injection of malicious… | |
| Aplazada | Media (5.1) | 0.39% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint save-megamenu-settings failed to enforce item-level and menu-level edit permissions (core.edit on com_menus.item.{id} or core.admin). An authenticated user could submit… | |
| Aplazada | Media (5.1) | 0.39% | — | Joomshaper Helix UltimateAI | 31/8/2026 | 31/8/2026 | Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()` checked whether the user was authorized to edit the article ID passed in the request, but did not verify whether the specified image path (src) belonged to that article. On… | |
| Aplazada | Media (6.3) | 0.42% | — | Joomshaper SP Page BuilderAI | 12/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input. | |
| Aplazada | Media (6.3) | 0.52% | — | Joomshaper SP Page BuilderAI | 12/8/2026 | 26/8/2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name. |