Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 2.2% | — | Magicblack Maccms10AI | 14/9/2026 | 16/9/2026 | A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown functionality of the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html of the component Template Handler. Performing a manipulation results in os command… | |
| Aplazada | Alta (7.5) | 0.75% | — | MaccmsAI | 25/8/2026 | 8/9/2026 | The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Access Control issue. The interface fails to perform any authentication or authorization checks. An unauthenticated remote attacker can send a crafted HTTP GET request with limit and offset parameters to paginate and… | |
| Aplazada | Alta (7.2) | 0.54% | — | Maccms10AI | 5/8/2026 | 26/8/2026 | MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function, register_tick_function, and error_log. | |
| Aplazada | Baja (2.9) | 0.44% | — | Maccms PROAI | 13/7/2026 | 13/7/2026 | A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The attack requires a high level of… | |
| Aplazada | Baja (2) | 0.38% | — | Maccms PROAI | 1/5/2026 | 17/6/2026 | A weakness has been identified in MacCMS Pro up to 2022.1.3. This vulnerability affects the function install of the file /admi.php/admin/addon/add.html of the component Plugin Installation Handler. Executing a manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.37% | — | MaccmsAI | 23/3/2026 | 17/6/2026 | A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This manipulation of the argument order_id causes authorization bypass. It is possible to initiate the… | |
| Aplazada | Media (5.5) | 0.65% | — | MaccmsAI | 23/3/2026 | 17/6/2026 | A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The exploit has been released to the public… | |
| Analizada | Baja (2) | 0.34% | — | Maccms | 14/9/2025 | 17/6/2026 | A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of the argument cjurl leads to server-side request forgery. The attack can be initiated remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.1) | 0.34% | — | Maccms | 14/9/2025 | 17/6/2026 | A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in server-side request forgery. It is possible to initiate the attack remotely. | |
| Analizada | Baja (2) | 0.33% | — | Maccms | 9/9/2025 | 17/6/2026 | A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. | |
| Analizada | Alta (7.3) | 0.37% | — | Maccms | 29/5/2025 | 17/6/2026 | maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings. | |
| Analizada | Media (5.4) | 0.33% | — | Maccms | 27/5/2025 | 17/6/2026 | maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management. | |
| Analizada | Crítica (9.1) | 0.44% | — | Maccms | 28/3/2025 | 17/6/2026 | maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article. | |
| Analizada | Crítica (9.1) | 0.43% | — | Maccms | 28/3/2025 | 17/6/2026 | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature. | |
| Analizada | Crítica (9.1) | 0.44% | — | Maccms | 28/3/2025 | 17/6/2026 | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function. | |
| Analizada | Media (4.8) | 0.25% | — | Maccms | 20/9/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Analizada | Alta (7.3) | 0.92% | — | Maccms | 19/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload. | |
| Modificada | Alta (8.8) | 0.87% | — | Maccms | 1/2/2023 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module. | |
| Modificada | Media (6.1) | 0.50% | — | Maccms | 6/1/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module. | |
| Modificada | Media (6.5) | 0.69% | — | Maccms | 17/8/2022 | 17/6/2026 | maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html. | |
| Modificada | Media (5.4) | 0.43% | — | Maccms | 21/6/2022 | 17/6/2026 | maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. | |
| Modificada | Media (5.4) | 0.43% | — | Maccms | 21/6/2022 | 17/6/2026 | maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. | |
| Modificada | Media (6.1) | 0.64% | — | Maccms | 31/3/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter. | |
| Modificada | Media (6.1) | 0.56% | — | Maccms | 25/3/2022 | 17/6/2026 | Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter. | |
| Modificada | Media (6.1) | 0.56% | — | Maccms | 25/3/2022 | 17/6/2026 | Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter. |