Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.59% | — | Damasac Thaipalliative LTEAI | 11/6/2026 | 17/6/2026 | SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49). The parameters are concatenated directly into SQL queries without sanitization or… | |
| Aplazada | Media (6.1) | 0.31% | — | Damasac Thaipalliative LTEAI | 5/6/2026 | 17/6/2026 | Multiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thaipalliative_lte through version 3.0 allow remote attackers to inject arbitrary web script or HTML via the idFormMain parameter (line 24), the id parameter (lines 25, 75), and the ptid_key parameter (lines 26, 42) in /substudy/ezform.php. User… | |
| Aplazada | Media (5.3) | 0.54% | — | Masa CMSAI | 6/5/2026 | 17/6/2026 | Masa CMS is affected by an Open Redirect vulnerability due to improper handling of scheme-relative URLs. The application incorrectly interprets paths beginning with double slashes (//) as internal paths, failing to validate the redirect target before processing. The application treats these values as internal paths… | |
| Aplazada | Alta (7.1) | 0.22% | — | Masacms Masa CMSAI | 6/5/2026 | 17/6/2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the createBundle method in `csettings.cfc` does not properly validate anti-CSRF tokens for site bundle creation requests. An attacker can craft a malicious webpage or link that, when visited by a logged-in administrator,… | |
| Aplazada | Alta (8.7) | 0.21% | — | Masa CMSAI | 6/5/2026 | 17/6/2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the `cTrash.restore` function does not properly validate anti-CSRF tokens for content restoration requests. An attacker can trick a logged-in administrator to submit a forged request that restores deleted items from the trash… | |
| Aplazada | Alta (7.2) | 0.21% | — | Masa CMSAI | 6/5/2026 | 17/6/2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cTrash.empty function does not validate anti-CSRF tokens for trash management requests. An attacker can induce a logged-in administrator to submit a forged request that empties the trash and permanently deletes all deleted… | |
| Aplazada | Alta (7.1) | 0.21% | — | Masacms Masa CMSAI | 6/5/2026 | 17/6/2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress function does not properly validate anti-CSRF tokens for user address management operations. An attacker can induce a logged-in administrator to submit a forged request that adds, modifies, or deletes… | |
| Aplazada | Crítica (9.3) | 0.54% | — | Masa CMSAI | 5/5/2026 | 24/7/2026 | Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7.5.2, the unauthenticated JSON API accepts an altTable parameter that is stored via the setAltTable() method without validation or sanitization. This value is injected… | |
| Aplazada | Crítica (9.3) | 0.66% | — | Masa CMSAI | 5/5/2026 | 24/7/2026 | Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7.5.2, a SQL injection vulnerability exists in the beanFeed.cfc component within the getQuery function's handling of the sortDirection parameter. The parameter value is… | |
| Aplazada | Crítica (9.3) | 0.51% | — | Masa CMSAI | 5/5/2026 | 24/7/2026 | Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exists in the beanFeed.cfc component within the getQuery function's processing of the sortBy parameter. The application fails to properly sanitize or parameterize this input before incorporating it into… | |
| Analizada | Media (6.1) | 0.25% | — | Masacms | 12/12/2025 | 17/6/2026 | Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0-alpha.1 through 7.4.8 and 7.5.0 through 7.5.1 are vulnerable to XSS when an unsanitized value of the ajax URL query parameter is directly included within the <head> section of the HTML page. An… | |
| Analizada | Alta (7.5) | 0.36% | — | Masacms | 3/12/2025 | 26/9/2026 | Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a /tag/ declaration, the CMS will render the page regardless of group restrictions. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6. | |
| Analizada | Alta (8.8) | 0.20% | — | Masacms | 3/12/2025 | 26/9/2026 | Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, and 7.4.6. | |
| Analizada | Crítica (9.8) | 12% | — | Masacms | 3/12/2025 | 26/9/2026 | Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input via the criteria parameter. This input is subsequently evaluated by… | |
| Aplazada | Crítica (9.8) | 77% | — | Masa CMSAI | 11/8/2025 | 17/6/2026 | MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue. | |
| Aplazada | Media (6.5) | 0.32% | — | Masashi Takizawa Multi-day Booking CalendarAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Masashi Takizawa Multi-day Booking Calendar multi-day-booking-calendar allows DOM-Based XSS.This issue affects Multi-day Booking Calendar: from n/a through <= 1.0.1. | |
| Modificada | Alta (8.2) | 0.58% | — | Linecorp Uomasa Saiji NEW | 25/10/2023 | 17/6/2026 | The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | |
| Modificada | Crítica (9.8) | 6.3% | — | Masacms | 1/2/2023 | 17/6/2026 | A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request. | |
| Modificada | Alta (7.5) | 4.7% | — | Masacms | 5/5/2022 | 17/6/2026 | MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/. | |
| Modificada | Media (6.9) | 0.28% | — | Masahiko Watanabe Apsaly | 25/10/2010 | 16/6/2026 | Untrusted search path vulnerability in Apsaly before 3.74 allows local users to gain privileges via a Trojan horse executable file in the current working directory. | |
| Modificada | Alta (7.5) | 1.0% | — | Masa2el Music City | 23/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in MASA2EL Music City 1.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a singer action. |