Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.30% | — | October CMSAI | 28/9/2026 | 28/9/2026 | A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be… | |
| Aplazada | Media (5.5) | 0.30% | — | OctobercmsAI | 28/9/2026 | 28/9/2026 | A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery. The attack may be performed from remote. The… | |
| Aplazada | Baja (3.3) | 0.24% | — | October CMSAI | 14/9/2026 | 30/9/2026 | October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, the backend `SessionMaker` trait stored widget session state as `base64(serialize(...))` and consumed it with `unserialize()` without an `allowed_classes` restriction. Any code path that could write to… | |
| Aplazada | Baja (3.3) | 0.27% | — | October CMSAI | 14/9/2026 | 30/9/2026 | October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. The Laravel session store was exposed to Twig with unrestricted method access, and… | |
| Aplazada | Baja (3.3) | 0.23% | — | Octobercms OctoberAI | 21/4/2026 | 17/6/2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission checks for asset and blueprint file operations were not enforced in the CMS and Tailor editor extensions. This only affects backend users who were explicitly granted editor access but had… | |
| Aplazada | Baja (3.1) | 0.23% | — | Octobercms OctoberAI | 21/4/2026 | 17/6/2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Scripting (XSS) vulnerability was identified in the backend DataTable widget where a query parameter was rendered without proper output escaping. This vulnerability is fixed in 3.7.16 and 4.1.16. | |
| Aplazada | Media (6.6) | 0.39% | — | Octobercms OctoberAI | 21/4/2026 | 17/6/2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identified in the Twig sandbox security policy that allowed database write operations when cms.safe_mode is enabled. Backend users with Developer permissions could use Twig template markup to execute insert,… | |
| Aplazada | Media (4.9) | 0.42% | — | Octobercms OctoberAI | 21/4/2026 | 17/6/2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information disclosure vulnerability was identified in the handling of CSS preprocessor files. Backend users with Editor permissions could craft .less, .sass, or .scss files that leverage the compiler's import… | |
| Analizada | Media (4.8) | 0.22% | — | Octobercms October | 14/4/2026 | 25/7/2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the SVG sanitization logic. The regex pattern used to strip event handler attributes (such as onclick or onload) could be bypassed using a crafted payload that… | |
| Analizada | Media (4.9) | 0.33% | — | Octobercms October | 14/4/2026 | 25/7/2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports ${} syntax for environment variable interpolation, attackers with Editor access… | |
| Analizada | Media (5.1) | 0.20% | — | Octobercms October | 14/4/2026 | 17/6/2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the Event Log mail preview feature. When viewing logged mail messages, HTML content was rendered in an iframe without proper sandboxing, allowing JavaScript… | |
| Analizada | Media (5.1) | 0.25% | — | Octobercms October | 14/4/2026 | 17/6/2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulnerability in the Backend Editor Settings. The Markup Classes fields (used for paragraph styles, inline styles, table styles, etc.) did not sanitize input to valid CSS class… | |
| Analizada | Media (6.8) | 0.40% | — | Octobercms October | 14/4/2026 | 17/6/2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature (CMS_SAFE_MODE). Certain methods on the collect() helper were not properly restricted, allowing authenticated users with… | |
| Analizada | Media (4.8) | 0.27% | — | Octobercms October | 10/1/2026 | 17/6/2026 | October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerabilities was identified in October CMS backend configuration forms. A user with the Customize Backend Styles permission could inject malicious HTML/JS into the stylesheet input at… | |
| Analizada | Media (4.8) | 0.27% | — | Octobercms October | 10/1/2026 | 17/6/2026 | October is a Content Management System (CMS) and web platform. Prior to versions 3.7.13 and 4.0.12, a cross-site scripting (XSS) vulnerability was identified in October CMS backend configuration forms. A user with the Global Editor Settings permission could inject malicious HTML/JS into the stylesheet input at Markup… | |
| Analizada | Baja (1.1) | 0.38% | — | Octobercms October | 5/5/2025 | 17/6/2026 | October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authenticated administrators with sites that have the `media.clean_vectors` configuration enabled. This configuration will sanitize SVG files uploaded using the media manager. This vulnerability allows an… | |
| Analizada | Media (4.7) | 0.51% | — | Octobercms October | 2/10/2024 | 17/6/2026 | October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through the website, it could lead to a Cross-Site Scripting (XSS) attack or execute arbitrary code via a crafted JavaScript to the target. | |
| Analizada | Media (5.4) | 0.24% | — | Octobercms October | 16/8/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to execute arbitrary web scripts or HTML via a crafted payload into the Comments section. | |
| Analizada | Media (5.4) | 0.26% | — | Octobercms October | 26/6/2024 | 17/6/2026 | October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped HTML to be reflected back. There is no impact since this vulnerability cannot be exploited through normal browser interactions. This unescaped… | |
| Modificada | Media (4.8) | 0.27% | — | Octobercms October | 26/6/2024 | 17/6/2026 | October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema. The resolver for the page finder link schema (`october://`) allowed external links, therefore allowing an open redirect… | |
| Modificada | Alta (7.8) | 0.36% | — | Octobercms October | 8/2/2024 | 17/6/2026 | Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3 | |
| Modificada | Crítica (9.1) | 0.87% | — | Octobercms October | 1/12/2023 | 17/6/2026 | October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitted to provide PHP code to be executed by the CMS due to… | |
| Modificada | Media (4.9) | 0.51% | — | Octobercms October | 1/12/2023 | 17/6/2026 | October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitted to provide PHP code to be executed by the CMS due to… | |
| Modificada | Media (5.4) | 0.41% | — | Octobercms October | 29/11/2023 | 17/6/2026 | October is a Content Management System (CMS) and web platform to assist with development workflow. A user with access to the media manager that stores SVG files could create a stored XSS attack against themselves and any other user with access to the media manager when SVG files are supported. This issue has been… | |
| Modificada | Media (5.4) | 0.48% | — | Octobercms October | 28/9/2023 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability in installation of October v.3.4.16 allows an attacker to execute arbitrary web scripts via a crafted payload injected into the dbhost field. |