Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2)2.2%—Magicblack Maccms10AI14/9/202616/9/2026
A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown functionality of the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html of the component Template Handler. Performing a manipulation results in os command…
AplazadaAlta (7.5)0.75%—MaccmsAI25/8/20268/9/2026
The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Access Control issue. The interface fails to perform any authentication or authorization checks. An unauthenticated remote attacker can send a crafted HTTP GET request with limit and offset parameters to paginate and…
AplazadaAlta (7.2)0.54%—Maccms10AI5/8/202626/8/2026
MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function, register_tick_function, and error_log.
AplazadaBaja (2.9)0.44%—Maccms PROAI13/7/202613/7/2026
A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The attack requires a high level of…
AplazadaBaja (2)0.38%—Maccms PROAI1/5/202617/6/2026
A weakness has been identified in MacCMS Pro up to 2022.1.3. This vulnerability affects the function install of the file /admi.php/admin/addon/add.html of the component Plugin Installation Handler. Executing a manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit has been…
AplazadaBaja (2.1)0.37%—MaccmsAI23/3/202617/6/2026
A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This manipulation of the argument order_id causes authorization bypass. It is possible to initiate the…
AplazadaMedia (5.5)0.65%—MaccmsAI23/3/202617/6/2026
A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The exploit has been released to the public…
AnalizadaBaja (2)0.34%—Maccms14/9/202517/6/2026
A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of the argument cjurl leads to server-side request forgery. The attack can be initiated remotely. The exploit is publicly available and might be used.
AnalizadaMedia (5.1)0.34%—Maccms14/9/202517/6/2026
A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in server-side request forgery. It is possible to initiate the attack remotely.
AnalizadaBaja (2)0.33%—Maccms9/9/202517/6/2026
A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
AnalizadaAlta (7.3)0.37%—Maccms29/5/202517/6/2026
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
AnalizadaMedia (5.4)0.33%—Maccms27/5/202517/6/2026
maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.
AnalizadaCrítica (9.1)0.44%—Maccms28/3/202517/6/2026
maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.
AnalizadaCrítica (9.1)0.43%—Maccms28/3/202517/6/2026
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.
AnalizadaCrítica (9.1)0.44%—Maccms28/3/202517/6/2026
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.
AnalizadaMedia (4.8)0.25%—Maccms20/9/202417/6/2026
A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
AnalizadaAlta (7.3)0.92%—Maccms19/4/202417/6/2026
Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.
ModificadaAlta (8.8)0.87%—Maccms1/2/202317/6/2026
A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module.
ModificadaMedia (6.1)0.50%—Maccms6/1/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.
ModificadaMedia (6.5)0.69%—Maccms17/8/202217/6/2026
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.
ModificadaMedia (5.4)0.43%—Maccms21/6/202217/6/2026
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
ModificadaMedia (5.4)0.43%—Maccms21/6/202217/6/2026
maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
ModificadaMedia (6.1)0.64%—Maccms31/3/202217/6/2026
Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.
ModificadaMedia (6.1)0.56%—Maccms25/3/202217/6/2026
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter.
ModificadaMedia (6.1)0.56%—Maccms25/3/202217/6/2026
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.