Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 74 respecto a la semana anterior
Críticas / altas1464▲ 358 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)89▼ 424 respecto a la semana anterior
421 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.3) | 0.39% | — | Dashbitco Lazy HtmlAI | 25/9/2026 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_html allows mutation XSS via a parse and serialize round-trip of attacker-supplied HTML. LazyHTML.to_html/2 and LazyHTML.Tree.to_html/2 decide whether to escape an element's text from its tag name… | |
| Aplazada | Media (6.1) | 0.17% | — | Xhtml-purifierAI | 24/9/2026 | 30/9/2026 | xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Versions prior to 0.4.3 do not HTML-entity-encode attribute values when serializing its sanitized output. In attributeString() (XHTMLPurifier.js, around line 148) the attribute value is concatenated… | |
| Aplazada | Media (5.3) | 0.39% | — | Ansi2htmlAI | 17/9/2026 | 23/9/2026 | ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling ANSI text input can inject javascript: schemes or terminate href attributes to execute arbitrary scripts in the context of pages… | |
| Aplazada | Media (6.1) | 0.24% | — | Html FormhandlerAI | 8/9/2026 | 10/9/2026 | HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than literals allows attacker-influenced text in an attribute value that can override the… | |
| Aplazada | Media (6.1) | 0.26% | — | Html Formhandler Project Html FormhandlerAI | 8/9/2026 | 10/9/2026 | HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0.410000, the fix for CVE-2026-19872, escaped the equivalent values in the other… | |
| Aplazada | Media (6.1) | 0.33% | — | Html FormhandlerAI | 8/9/2026 | 10/9/2026 | HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Select into a label attribute and the other three into element content. RadioGroup also… | |
| Aplazada | Media (6.1) | 0.26% | — | Html FormhandlerAI | 8/9/2026 | 10/9/2026 | HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message. The wrappers and renderers that emit a form's errors interpolate the error string straight into HTML with no escaping. Two of the library's own messages, no_match and… | |
| Aplazada | Crítica (10) | 0.55% | — | Embed Html5 GameAI | 2/9/2026 | 3/9/2026 | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites. | |
| Aplazada | Media (5.4) | 0.30% | — | Sanitize-htmlAIApostrophecmsAI | 1/9/2026 | 9/9/2026 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not recognize that attributeName selecting… | |
| Aplazada | Alta (7.5) | 0.52% | — | Html FormfuAI | 31/8/2026 | 3/9/2026 | HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. When a Repeatable element has counter_name set, its process method reads the repeat count from the named query string parameter, checks only that it is a positive integer,… | |
| Pendiente de análisis | Alta (7.5) | 0.53% | — | Kaltura Html5libAIKaltura MwembedAI | 25/8/2026 | 3/9/2026 | The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation of the ServiceUrl parameter in mwEmbedLoader.php. This parameter is used as the base URL for a backend request and accepts non‑HTTP schemes such as file://. When an exception or error occurs, the… | |
| Pendiente de análisis | Crítica (9.8) | 1.0% | — | Kaltura Html5libAIKaltura MwembedAI | 25/8/2026 | 3/9/2026 | The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled ServiceUrl, whose response is passed to unserialize(), and the resulting object’s… | |
| Aplazada | Alta (8.7) | 0.49% | — | JusthtmlAI | 23/8/2026 | 26/8/2026 | justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the DOM tree via _find_elements()/_find_element() without a depth bound. An… | |
| Aplazada | Media (5.1) | 0.26% | — | JusthtmlAI | 23/8/2026 | 26/8/2026 | justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements such as <style> and <script>. When a DOM tree is processed by sanitize_dom() using a custom policy that keeps these elements, text nodes inside them are serialized… | |
| Aplazada | Crítica (9.3) | 0.64% | — | JusthtmlAI | 23/8/2026 | 26/8/2026 | justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacters are escaped, characters such as < and > are preserved, so untrusted input… | |
| Aplazada | Crítica (9.3) | 0.59% | — | JusthtmlAI | 23/8/2026 | 26/8/2026 | justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usage rather than the default JustHTML(..., sanitize=True) path for… | |
| Aplazada | Media (5.3) | 0.26% | — | JusthtmlAI | 23/8/2026 | 29/8/2026 | justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blank lines as block boundaries. Attackers can inject blank lines into code or pre element text to break the inline span, causing sanitized HTML to be emitted unescaped and… | |
| Aplazada | Media (5.1) | 0.29% | — | JusthtmlAI | 23/8/2026 | 26/8/2026 | justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler removal in selectedcontent projections. Attackers can inject SVG or MathML elements with event handlers that are cloned and reinserted into output without sanitization, enabling stored or reflected… | |
| Aplazada | Media (5.1) | 0.26% | — | JusthtmlAI | 23/8/2026 | 29/8/2026 | justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve foreign namespaces (SVG/MathML), dangerous content such as HTML integration points (SVG <foreignObject>, MathML <annotation-xml encoding="text/html">) and mutation-XSS… | |
| Aplazada | Media (5.1) | 0.26% | — | JusthtmlAI | 23/8/2026 | 26/8/2026 | justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom SanitizationPolicy that preserves foreign namespaces (e.g., drop_foreign_namespaces=False with allowlisted SVG/MathML elements or raw-text containers such as <style>). Specially… | |
| Aplazada | Media (5.1) | 0.26% | — | JusthtmlAI | 23/8/2026 | 26/8/2026 | justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing attacker-controlled pre content. Attackers can place backticks inside sanitized pre elements to break out of fixed-length code fences, allowing raw HTML to execute when the generated Markdown is… | |
| Aplazada | Crítica (9.3) | 0.59% | — | JusthtmlAI | 23/8/2026 | 26/8/2026 | justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on configuration, an attacker can bypass sanitization to inject… | |
| Aplazada | Alta (8.7) | 0.65% | — | JusthtmlAI | 23/8/2026 | 26/8/2026 | justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run selector matching over very large untrusted documents, construct DOM… | |
| Aplazada | Baja (2.1) | 0.23% | — | Sourcecodester Dynamic Input Field Generator Using Html CSS AND PHPAI | 21/8/2026 | 24/8/2026 | A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. | |
| Pendiente de análisis | Alta (8.2) | 0.30% | — | LxmlAILxml Html CleanAI | 20/8/2026 | 18/9/2026 | lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. content. This vulnerability was fixed in lxml 6.1.1 and lxml_html_clean 0.4.5. |