Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2630▼ 215 respecto a la semana anterior
Críticas / altas1379▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.54% | — | Wolfcms Wolf CMSAI | 30/7/2026 | 31/7/2026 | Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can exploit the incorrect evaluation of the… | |
| Aplazada | Alta (8.7) | 2.1% | — | Wolfcms Wolf CMSAI | 30/7/2026 | 31/7/2026 | Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the file_manager_mkfile capability can write… | |
| Modificada | Media (6.1) | 0.85% | — | Wolfcms Wolf CMS | 9/6/2022 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in WolfCMS up to 0.8.3.1. It has been rated as problematic. This issue affects some unknown processing of the file /wolfcms/?/admin/user/add of the component User Add. The manipulation of the argument name leads to basic cross site scripting. The attack may be… | |
| Modificada | Media (4.8) | 0.70% | — | Wolfcms Wolf CMS | 19/2/2020 | 16/6/2026 | A cross-site scripting (XSS) vulnerability in Wolf CMS 0.75 and earlier allows remote attackers to inject arbitrary web script or HTML via the setting[admin_email] parameter to admin/setting. | |
| Modificada | Media (4.8) | 1.0% | — | Wolfcms Wolf CMS | 25/4/2019 | 17/6/2026 | WolfCMS v0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/. | |
| Modificada | Media (4.8) | 1.0% | — | Wolfcms Wolf CMS | 25/4/2019 | 17/6/2026 | WolfCMS 0.8.3.1 allows XSS via an SVG file to /?/admin/plugin/file_manager/browse/. | |
| Modificada | Media (6.1) | 0.86% | — | Wolfcms Wolf CMS | 30/3/2019 | 17/6/2026 | Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, which will be executed whenever the affected snippet is loaded. | |
| Modificada | Media (4.8) | 0.66% | — | Wolfcms Wolf CMS | 25/8/2018 | 17/6/2026 | WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter. | |
| Modificada | Media (4.8) | 0.67% | — | Wolfcms Wolf CMS | 10/8/2018 | 17/6/2026 | Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI. | |
| Modificada | Alta (8.8) | 3.5% | — | Lfdycms Lfcms | 25/6/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users for requests that add administrator users via the s parameter, a related issue to CVE-2018-12114. | |
| Modificada | Alta (8.8) | 3.0% | — | Lfdycms Lfcms | 25/6/2018 | 17/6/2026 | A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily. | |
| Modificada | Media (6.5) | 3.0% | — | Wolfcms Wolf CMS | 4/4/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settings by crafting a malicious request. | |
| Modificada | Media (4.8) | 3.2% | — | Wolfcms Wolf CMS | 4/4/2018 | 17/6/2026 | Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL. | |
| Modificada | Media (4.8) | 0.64% | — | Wolfcms Wolf CMS | 13/3/2018 | 17/6/2026 | WolfCMS version version 0.8.3.1 contains a Reflected Cross Site Scripting vulnerability in "Create New File" and "Create New Directory" input box from 'files' Tab that can result in Session Hijacking, Spread Worms,Control the browser remotely. . This attack appear to be exploitable via Attacker can execute the… | |
| Modificada | Media (5.4) | 0.64% | — | Wolfcms Wolf CMS | 13/3/2018 | 17/6/2026 | WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can result in low privilege user can steal the cookie of admin user and compromise the admin account. This attack appear to be exploitable via Need to enter the Javascript code into Layout… | |
| Modificada | Media (4.8) | 0.71% | — | Wolfcms Wolf CMS | 22/2/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Wolf CMS 0.8.3.1 via the page editing feature, as demonstrated by /?/admin/page/edit/3. | |
| Modificada | Media (5.4) | 0.90% | — | Wolfcms Wolf CMS | 8/9/2017 | 17/6/2026 | Wolf CMS 0.8.3.1 allows Cross-Site Scripting (XSS) attacks. The vulnerability exists due to insufficient sanitization of the file name in a "create-file-popup" action, and the directory name in a "create-directory-popup" action, in the HTTP POST method to the "/plugin/file_manager/" script (aka an… | |
| Modificada | Alta (8.8) | 11% | — | Wolfcms Wolf CMS | 14/4/2017 | 17/6/2026 | Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" after originally using the parameter "filename" for uploading a JPEG image. Exploitation requires a registered user who… | |
| Modificada | Alta (8.8) | 11% | — | Wolfcms Wolf CMS | 14/4/2017 | 17/6/2026 | Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a registered user who has access to upload functionality. | |
| Modificada | Media (6.8) | 1.2% | — | Wolfcms Wolf CMS | 1/10/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via the user id number to admin/user/delete; (2) delete pages via the page id number to admin/page/delete; delete the (3)… |