Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 55 respecto a la semana anterior
Críticas / altas1422▲ 195 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.25% | — | Lightcms Project Lightcms | 26/3/2026 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referer value in the request header. | |
| Modificada | Media (5.4) | 0.33% | — | Lightcms Project Lightcms | 29/1/2024 | 17/6/2026 | LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field. | |
| Modificada | Crítica (9.8) | 1.3% | — | Lightcms Project Lightcms | 22/3/2023 | 17/6/2026 | LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function. | |
| Modificada | Media (4.8) | 0.52% | — | Lightcms Project Lightcms | 27/6/2022 | 9/7/2026 | A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file. | |
| Modificada | Crítica (9.8) | 2.4% | — | Lightcms Project Lightcms | 15/4/2021 | 17/6/2026 | LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading of external images. | |
| Modificada | Media (5.4) | 7.2% | — | Lightcms Project Lightcms | 24/2/2021 | 17/6/2026 | A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords. | |
| Modificada | Media (5) | 3.9% | — | Twilightcms Twilight CMS | 9/9/2013 | 16/6/2026 | Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote attackers to read arbitrary files via a ..%5c (dot dot encoded backslash) in a GET request. | |
| Modificada | Media (4.3) | 1.2% | — | Twilightcms Twilight CMS | 9/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Twilight CMS 5.17 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the gallery/ page. | |
| Modificada | Media (4.3) | 3.0% | — | Twilightcms Twilight CMS | 4/11/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the default URI in news/ in Twilight CMS before 4.1 allows remote attackers to inject arbitrary web script or HTML via the calendar parameter. NOTE: some of these details are obtained from third party information. |