Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
202 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.26% | — | KindeditorAISem-cms SemcmsAI | 23/9/2026 | 24/9/2026 | A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEditor Upload Interface. This manipulation of the argument imgFile causes cross site scripting. The attack may be initiated remotely. The exploit has been published… | |
| Aplazada | Sin puntuar | 0.19% | — | McmsAI | 22/9/2026 | 24/9/2026 | MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature. | |
| Pendiente de análisis | Alta (8.7) | 0.31% | — | McmsAI | 22/9/2026 | 23/9/2026 | MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS). The article content field `contentDetails` is excluded from the global XSS filter. | |
| Pendiente de análisis | Crítica (9.8) | 0.41% | — | McmsAI | 22/9/2026 | 25/9/2026 | MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/verify.do). | |
| Aplazada | Alta (7.2) | 0.50% | — | YzmcmsAI | 28/8/2026 | 3/9/2026 | A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category.class.php, where the user-controlled parentid parameter is concatenated directly into a FIND_IN_SET() SQL clause without proper sanitization. This allows an… | |
| Aplazada | Crítica (9.8) | 0.50% | — | McmsAI | 26/8/2026 | 1/9/2026 | The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through FreeMarker ${size} without being parameterized and bound. The built-in SqlInjectionUtil employs regular expression blacklist filtering, yet… | |
| Aplazada | Media (5.5) | 0.48% | — | Mingsoft McmsAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (5.5) | 0.48% | — | Mingsoft McmsAI | 9/8/2026 | 13/8/2026 | A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was… | |
| Aplazada | Media (5.5) | 0.41% | — | Mingsoft McmsAI | 9/8/2026 | 12/8/2026 | A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Alta (7.5) | 0.52% | — | McmsAI | 17/7/2026 | 23/7/2026 | An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter. | |
| Aplazada | Baja (2.1) | 0.45% | — | YzmcmsAI | 9/7/2026 | 9/7/2026 | A security vulnerability has been detected in YzmCMS up to 7.5. Affected is the function get_url of the file /yzmphp/yzmphp.php of the component Header Handler. The manipulation of the argument HTTP_HOST leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and… | |
| Aplazada | Baja (2.9) | 0.37% | — | YzmcmsAI | 29/6/2026 | 29/6/2026 | A vulnerability was determined in YzmCMS up to 7.5. This affects an unknown function of the file /application/install/index.php. Executing a manipulation of the argument siteurl can lead to sql injection. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is… | |
| Aplazada | Media (6.3) | 0.15% | — | Sem-cms SemcmsAI | 9/6/2026 | 23/7/2026 | SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php. | |
| Aplazada | Alta (7.5) | 0.39% | — | Sem-cms SemcmsAI | 9/6/2026 | 23/7/2026 | SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php. | |
| Aplazada | Baja (2.1) | 0.32% | — | Mingsoft McmsAI | 27/3/2026 | 17/6/2026 | A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Aplazada | Media (5.5) | 0.47% | — | Mingsoft McmsAI | 27/3/2026 | 17/6/2026 | A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead to server-side request forgery. It is possible to launch the attack… | |
| Analizada | Media (6.1) | 0.25% | — | Yzmcms | 26/3/2026 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the /index/login.html component of YZMCMS v7.4 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referrer value in the request header. | |
| Analizada | Baja (2) | 0.55% | — | Mingsoft Mcms | 18/2/2026 | 17/6/2026 | A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published… | |
| Analizada | Baja (2.1) | 0.38% | — | Sem-cms Semcms | 29/1/2026 | 17/6/2026 | A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_Info.php. The manipulation of the argument searchml leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was… | |
| Modificada | Crítica (9.3) | 0.47% | — | Thedigitalcraft Atomcms | 22/12/2025 | 17/6/2026 | Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks. | |
| Modificada | Media (6.1) | 0.20% | — | Mingsoft Mcms | 23/10/2025 | 5/7/2026 | A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload. | |
| Analizada | Crítica (9.8) | 0.64% | — | Mingsoft Mcms | 17/10/2025 | 17/6/2026 | A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering. | |
| Modificada | Media (6.5) | 0.26% | — | Mingsoft Mcms | 10/10/2025 | 5/7/2026 | An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Analizada | Media (6.5) | 0.33% | — | Formcms | 30/9/2025 | 17/6/2026 | An improper access control vulnerability in FormCms v0.5.4 in the /api/schemas/history/[schemaId] endpoint allows unauthenticated attackers to access historical schema data if a valid schemaId is known or guessed. | |
| Modificada | Media (6.1) | 0.20% | — | Yzmcms | 23/9/2025 | 5/7/2026 | Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page. |