Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.2) | 0.17% | — | AdmidioAI | 4/9/2026 | 9/9/2026 | Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update operations via GET requests without CSRF token validation. Because these are top-level navigations, browsers include SameSite=Lax session cookies.… | |
| Aplazada | Media (5.3) | 0.30% | — | AdmidioAI | 30/8/2026 | 2/9/2026 | Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass profile-level authorization by directly calling the reload_future_memberships endpoint with a victim's… | |
| Aplazada | Alta (8.7) | 0.45% | — | AdmidioAI | 30/8/2026 | 31/8/2026 | Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/announcements.php, disclosing titles, full post text, author names, and… | |
| Aplazada | Baja (2.1) | 0.44% | — | AdmidioAI | 30/8/2026 | 31/8/2026 | Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path traversal segments in archive entry names. Attackers can craft malicious album names containing directory traversal sequences that escape the intended… | |
| Aplazada | Alta (8.7) | 0.56% | — | AdmidioAI | 30/8/2026 | 31/8/2026 | Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dummy UUID in role_list and inject SQL through relation_type_list to… | |
| Aplazada | Media (4.4) | 0.17% | — | AdmidioAI | 12/8/2026 | 9/9/2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment this includes both the active session cookie and the persistent auto-login cookie.… | |
| Aplazada | Media (6.5) | 0.31% | — | AdmidioAI | 12/8/2026 | 9/9/2026 | Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modules/inventory.php`. The same fix was not applied to the sibling `case 'field_delete':` handler, which destroys an entire inventory field definition, cascading to every… | |
| Aplazada | Media (4.3) | 0.13% | — | AdmidioAI | 12/8/2026 | 9/9/2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modules/sso/keys.php` exports a PKCS#12 bundle containing the configured private key and certificate, but the CSRF validation line is commented out. A forged cross-site POST from an administrator session… | |
| Aplazada | Alta (8.1) | 0.35% | — | AdmidioAI | 12/8/2026 | 9/9/2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changing modes by checking that the actor has `hasUploadRight()` on the URL parameter `folder_uuid`. The `move_save` handler then operates on a *separate* URL parameter `file_uuid` and calls… | |
| Aplazada | Media (6.5) | 0.30% | — | AdmidioAI | 12/8/2026 | 9/9/2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_rename_save` shares the same root-cause shape as the cross-folder move bug (`05-documents-cross-folder-move-idor.md`): the top-level rights check at lines 79-89 validates `hasUploadRight()` on the URL… | |
| Aplazada | Media (5.4) | 0.14% | — | AdmidioAI | 12/8/2026 | 9/9/2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm_csrf_token` on every state-changing branch except `enable`. The `enable` case loads the SAML or OIDC client by UUID, calls `$client->enable($enabled)`, and persists the new state with no token… | |
| Aplazada | Media (5.2) | 0.16% | — | AdmidioAI | 12/8/2026 | 9/9/2026 | Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random password for `user_uuid_assigned`, stores its bcrypt hash in `adm_users.usr_password`, and emails the cleartext to that user. Every other state-changing mode in the same file (`assign_member`,… | |
| Aplazada | Media (6.5) | 0.33% | — | AdmidioAI | 12/8/2026 | 9/9/2026 | Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, …) corresponds to a module the actor administers. The follow-up "is this specific category editable by me" check at lines 56-61 is dead code because it compares `$getType`… | |
| Aplazada | Media (6.5) | 0.35% | — | AdmidioAI | 12/8/2026 | 9/9/2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can permanently delete files from folders where they have only view access. The authorization check at the top of `modules/documents-files.php` evaluates upload rights… | |
| Aplazada | Media (5.3) | 0.26% | — | AdmidioAI | 3/8/2026 | 9/9/2026 | Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs and overwrite admin-curated global lists or other users' private lists by supplying… | |
| Aplazada | Alta (7.1) | 0.16% | — | AdmidioAI | 3/8/2026 | 9/9/2026 | Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An attacker can trick an authenticated administrator into visiting a crafted URL to delete or duplicate… | |
| Aplazada | Media (6.9) | 0.38% | — | AdmidioAILightsamlAI | 3/8/2026 | 9/9/2026 | Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. Unauthenticated attackers can inject arbitrary JavaScript through SAML Issuer elements or LightSaml library parameters to execute code in users'… | |
| Aplazada | Alta (8.7) | 0.61% | — | AdmidioAI | 3/8/2026 | 9/9/2026 | Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to validate the login-only configuration state, allowing unauthenticated attackers to read forum topics and posts by directly accessing the… | |
| Aplazada | Media (6.9) | 0.34% | — | AdmidioAI | 3/8/2026 | 9/9/2026 | Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to groups_roles.php handlers to modify that… | |
| Aplazada | Media (6.9) | 0.19% | — | AdmidioAI | 25/5/2026 | 23/7/2026 | Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious HTML forms targeting roles_function.php with parameters like rol_assign_roles, rol_approve_users, and rol_edit_user set… | |
| Aplazada | Media (6.8) | 0.39% | — | AdmidioAI | 7/5/2026 | 17/6/2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_metadata.php validates the resolved IP address but passes the original hostname-based URL to curl_init(), leaving a DNS rebinding TOCTOU window that allows redirecting requests to internal IPs. This… | |
| Aplazada | Media (6.8) | 0.43% | — | AdmidioAI | 7/5/2026 | 17/6/2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modules/sso/index.php/oidc/introspect) always returns {"active": true} for every request, regardless of whether a valid token is provided, whether the token is expired, revoked, or completely fabricated.… | |
| Aplazada | Alta (8.2) | 0.31% | — | AdmidioAI | 7/5/2026 | 17/6/2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO module uses the AssertionConsumerServiceURL value directly from incoming SAML AuthnRequest messages as the destination for the SAML response, without validating it against the registered ACS URL… | |
| Aplazada | Alta (8.2) | 0.22% | — | AdmidioAI | 7/5/2026 | 17/6/2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implementation discards the return value of its validateSignature() method at both call sites (handleSSORequest() line 418 and handleSLORequest() line 613). The method returns error strings on failure rather… | |
| Aplazada | Baja (3.5) | 0.14% | — | AdmidioAI | 7/5/2026 | 17/6/2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio's preferences module (database backup, test email, htaccess generation) fire via GET requests with no CSRF token validation. Because SameSite=Lax cookies travel with top-level GET navigations, an… |