Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.35% | — | Mcgill Loris | 9/4/2026 | 17/6/2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, the redirect parameter upon login to LORIS was not validating the value of the redirect as being within LORIS, which could be used… | |
| Analizada | Alta (8.6) | 0.38% | — | Mcgill Loris | 8/4/2026 | 24/7/2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 24.0.0 to before 27.0.3 and 28.0.1, an incorrect order of operations in the FilesDownloadHandler could result in an attacker escaping the intended download… | |
| Analizada | Media (5.4) | 0.22% | — | Mcgill Loris | 8/4/2026 | 24/7/2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 15.10 to before 27.0.3 and 28.0.1, there is a potential for a cross-site scripting attack in the survey_accounts module if a user provides an invalid visit… | |
| Analizada | Media (4.3) | 0.30% | — | Mcgill Loris | 8/4/2026 | 24/7/2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, an endpoint in the publication module was incorrectly trusting the baseURL submitted by a user's POST request rather… | |
| Analizada | Media (5.4) | 0.27% | — | Mcgill Loris | 8/4/2026 | 24/7/2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and 28.0.1, the help_editor module of LORIS did not properly sanitize some user supplied variables which could result in a reflected… | |
| Analizada | Media (6.5) | 0.27% | — | Mcgill Loris | 8/4/2026 | 24/7/2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 21.0.0 to before 27.0.3 and 28.0.1, while the document_repository frontend was restricting file access, the backend endpoint was not correctly verifying… | |
| Analizada | Media (6.5) | 0.27% | — | Mcgill Loris | 8/4/2026 | 24/7/2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 16.1.0 to before 27.0.3 and 28.0.1, While the frontend of the media module filters files that the user should not have access to, the backend was not… | |
| Analizada | Alta (7.5) | 0.42% | — | Mcgill Loris | 8/4/2026 | 24/7/2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From 20.0.0 to before 27.0.3 and 28.0.1, a bug in the static file router can allow an attacker to traverse outside of the intended directory, allowing… | |
| Analizada | Alta (7.5) | 0.41% | — | Mcgill Loris | 8/4/2026 | 24/7/2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to 27.0.3 and 28.0.1, a SQL injection has been identified in some code sections for the MRI feedback popup window of the imaging browser. Attackers can… | |
| Aplazada | Media (6.1) | 0.27% | — | Floristpress FOR WOOAI | 26/3/2026 | 17/6/2026 | The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'noresults' parameter in all versions up to, and including, 7.8.2 due to insufficient input sanitization and output escaping on the user supplied 'noresults'… | |
| Analizada | Media (6.5) | 0.52% | — | Mcgill Loris | 25/2/2026 | 17/6/2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Starting in version 24.0.0 and prior to versions 26.0.5, 27.0.2, and 28.0.0, an authenticated user with the appropriate authorization can read configuration… | |
| Analizada | Alta (8.8) | 1.1% | — | Mcgill Loris | 25/2/2026 | 17/6/2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. Prior to versions 26.0.5, 27.0.2, and 28.0.0, an authenticated user with sufficient privileges can exploit a path traversal vulnerability to upload a malicious… | |
| Aplazada | Alta (7.1) | 0.35% | — | Bakkbone Australia FloristpressAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BAKKBONE Australia FloristPress bakkbone-florist-companion allows Reflected XSS.This issue affects FloristPress: from n/a through <= 7.2.0. | |
| Aplazada | Media (5.4) | 0.36% | — | Bakkbone Australia FloristpressAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in BAKKBONE Australia FloristPress bakkbone-florist-companion.This issue affects FloristPress: from n/a through <= 7.3.0. | |
| Aplazada | Media (4.3) | 0.39% | — | Bakkbone Australia FloristpressAI | 6/12/2024 | 17/6/2026 | Missing Authorization vulnerability in BAKKBONE Australia FloristPress bakkbone-florist-companion allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FloristPress: from n/a through <= 7.3.0. | |
| Aplazada | Media (6.4) | 0.27% | — | Floristone Flower DeliveryAI | 4/12/2024 | 17/6/2026 | The Flower Delivery by Florist One plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'flower-delivery' shortcode in all versions up to, and including, 3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Crítica (9.8) | 0.62% | — | Lisayazilim Florist Site | 13/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisa Software Florist Site allows SQL Injection. This issue affects Florist Site: before 3.0. | |
| Modificada | Media (4.8) | 0.59% | — | Floristone Flower Delivery | 27/6/2022 | 17/6/2026 | The Flower Delivery by Florist One WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setups) | |
| Modificada | Media (4.3) | 0.84% | — | Loris Hotel Reservation System | 14/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.cgi in Loris Hotel Reservation System 3.01 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the hotel_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (4.3) | 2.0% | — | Caloris Planitia Technologies WEB Quiz PRO | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Caloris Planitia Online Quiz System (aka Web Quiz pro), possibly 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) exam parameter in prequiz.asp or (2) msg parameter in student.asp. | |
| Modificada | Baja (2.6) | 2.0% | — | Caloris Planitia Technologies E-school Management System | 28/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in default.asp in Caloris Planitia E-School Management System 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter. |