Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.53% | — | MermaidAI | 6/8/2026 | 8/9/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high CPU usage and freeze the rendering webpage or JavaScript process for long periods… | |
| Pendiente de análisis | Baja (2.4) | 0.35% | — | MermaidAI | 6/8/2026 | 8/9/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid's configuration setters (mermaid.initialize, mermaidAPI.setConfig, and mermaidAPI.updateSiteConfig) merge caller-supplied configuration into Mermaid's internal config using the… | |
| Pendiente de análisis | Media (6.5) | 0.50% | — | MermaidAI | 6/8/2026 | 8/9/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Architecture Diagrams are vulnerable to prototype pollution when a diagram defines a group with an id of __proto__. Because the group id is used directly as an object… | |
| Pendiente de análisis | Media (5.3) | 0.58% | — | MermaidAI | 6/8/2026 | 8/9/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisRangeData function when configuring an X-Axis with invalid parameters. Because each… | |
| Pendiente de análisis | Media (5.3) | 0.60% | — | MermaidAI | 6/8/2026 | 8/9/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied class or id names. An attacker who can supply diagram text can inject arbitrary… | |
| Modificada | Media (5.3) | 0.55% | — | Mermaid Project Mermaid | 29/5/2026 | 21/7/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows injecting CSS that applies outside of the Mermaid diagram via the fontFamily, themeCSS, and altFontFamily configuration options. The injected CSS… | |
| Analizada | Media (5.3) | 0.53% | — | Mermaid Project Mermaid | 29/5/2026 | 21/7/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, there is a denial-of-service attack when rendering gantt charts, if they use the excludes attribute to exclude all dates. mermaid.parse is unaffected, unless you then call the… | |
| Aplazada | Media (5.3) | 0.52% | — | MermaidAI | 22/5/2026 | 23/7/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configuration. Specifically, the classDef directive in Mermaid state diagrams permits DOM… | |
| Aplazada | Media (5.3) | 0.60% | — | MermaidAI | 22/5/2026 | 23/7/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitization. The state diagram (and any other diagram type that routes user-controlled style… | |
| Aplazada | Media (5.3) | 0.69% | — | Beautiful-mermaidAI | 13/2/2026 | 14/7/2026 | beautiful-mermaid versions prior to 0.1.3 contain an SVG attribute injection issue that can lead to cross-site scripting (XSS) when rendering attacker-controlled Mermaid diagrams. User-controlled values from Mermaid style and classDef directives are interpolated into SVG attribute values without proper escaping,… | |
| Aplazada | Media (5.3) | 0.76% | — | MermaidAI | 19/8/2025 | 17/6/2026 | Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 10.9.0-rc.1 to 11.9.0, user supplied input for sequence diagram labels is passed to innerHTML during calculation of… | |
| Analizada | Media (5.1) | 0.38% | — | Mermaid Project Mermaid | 19/8/2025 | 17/6/2026 | Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. In the default configuration of mermaid 11.9.0 and earlier, user supplied input for architecture diagram icons is passed to the d3 html() method, creating a… | |
| Aplazada | Media (6.5) | 0.24% | — | Terryl WP MermaidAI | 1/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry L. WP Mermaid wp-mermaid allows Stored XSS.This issue affects WP Mermaid: from n/a through <= 1.0.2. | |
| Modificada | Media (5.4) | 0.47% | — | Discourse Mermaid | 4/1/2023 | 17/6/2026 | Discourse Mermaid (discourse-mermaid-theme-component) allows users of Discourse, open-source forum software, to create graphs using the Mermaid syntax. Users of discourse-mermaid-theme-component version 1.0.0 who can create posts are able to inject arbitrary HTML on that post. The issue has been fixed on the `main`… | |
| Modificada | Alta (7.8) | 0.40% | — | Mdx-mermaid Project Mdx-mermaid | 29/8/2022 | 17/6/2026 | mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection in versions less than 1.3.0 and 2.0.0-rc1. Modify any mermaid code blocks with arbitrary code and it will execute when the component is loaded by MDXjs. This vulnerability was patched in version(s)… | |
| Modificada | Media (6.1) | 0.91% | — | Mermaid Project Mermaid | 28/6/2022 | 17/6/2026 | Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. An attacker is able to inject arbitrary `CSS` into the generated graph allowing them to change the styling of elements outside of the generated graph, and… | |
| Modificada | Media (5.4) | 0.91% | — | Mermaid Project Mermaid | 30/12/2021 | 17/6/2026 | Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascript code at diagram readers' machines. Users should upgrade to version 8.13.8 to receive a patch.… | |
| Modificada | Media (6.1) | 1.0% | — | Mermaid Project Mermaid | 27/6/2021 | 17/6/2026 | Mermaid before 8.11.0 allows XSS when the antiscript feature is used. | |
| Modificada | Alta (7.5) | 1.3% | — | Php-nuke Mermaid Module | 1/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in formdisp.php in the Mermaid 1.2 module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the module_name parameter. |