Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.67% | — | MojoportalAI | 13/2/2026 | 17/6/2026 | A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file. | |
| Analizada | Media (6.5) | 1.9% | — | Mojoportal | 21/4/2025 | 17/6/2026 | mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey. | |
| Modificada | Media (6.1) | 1.3% | — | Mojoportal | 2/10/2023 | 17/6/2026 | Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.aspx component. | |
| Modificada | Crítica (9.8) | 1.8% | — | Mojoportal | 2/10/2023 | 17/6/2026 | An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component. | |
| Modificada | Crítica (9.8) | 1.8% | — | Mojoportal | 2/10/2023 | 17/6/2026 | File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function. | |
| Modificada | Crítica (9.8) | 1.6% | — | Mojoportal | 2/10/2023 | 17/6/2026 | File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function. | |
| Modificada | Media (4.3) | 0.73% | — | Mojoportal | 9/2/2023 | 17/6/2026 | An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via manipulation of the "s" parameter in /DesignTools/ManageSkin.aspx | |
| Modificada | Media (5.3) | 0.70% | — | Mojoportal | 9/2/2023 | 17/6/2026 | An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled. | |
| Modificada | Media (5.4) | 0.63% | — | Mojoportal | 9/2/2023 | 17/6/2026 | Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Settings component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtCompanyName parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Mojoportal | 9/2/2023 | 17/6/2026 | Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability. | |
| Modificada | Media (6.1) | 32% | — | Mojoportal | 9/2/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ed and tbi parameters. | |
| Modificada | Media (6.5) | 1.2% | — | Mojoportal | 3/10/2022 | 9/7/2026 | mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system. | |
| Modificada | Alta (8.8) | 1.4% | — | Mojoportal | 30/9/2022 | 9/7/2026 | mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PNG file. | |
| Modificada | Media (4.8) | 0.69% | — | Mojoportal | 24/2/2018 | 17/6/2026 | mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. The 'Title' and 'Subtitle' fields of the 'Blog' page are vulnerable. NOTE: The software maintainer disputes this as a vulnerability because the fields claimed to be… | |
| Modificada | Media (4.8) | 0.82% | — | Mojoportal | 2/1/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the "Administrators" or "Content… | |
| Modificada | Media (4.3) | 2.1% | — | Sourcetreesolutions Mojoportal | 20/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Forums/EditPost.aspx in mojoPortal before 2.3.9.8 allows remote attackers to inject arbitrary web script or HTML via the txtSubject parameter. | |
| Modificada | Media (6.8) | 2.5% | — | Sourcetreesolutions Mojoportal | 24/9/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to hijack the authentication of administrators for requests that rename arbitrary files, as demonstrated by causing the user.config file to be moved, leading… | |
| Modificada | Media (4.3) | 3.8% | — | Sourcetreesolutions Mojoportal | 24/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ProfileView.aspx in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to inject arbitrary web script or HTML via the User ID parameter. NOTE: some of these details are obtained from third party information. |