Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 13 respecto a la semana anterior
Críticas / altas1452▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.22%—Pagekit CMSAI21/9/202624/9/2026
Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitted to the public login endpoint (POST /user/authenticate).
AplazadaAlta (8.7)0.69%—Pagekit CMSAI26/6/202614/7/2026
Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to missing authorization checks in UserApiController::saveAction(). Attackers can assign themselves a…
AplazadaBaja (2)0.38%—PagekitAI25/4/202617/6/2026
A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipulation of the argument url leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit is publicly available…
AplazadaBaja (2)0.41%—Pagekit CMSAI20/4/202617/6/2026
A weakness has been identified in Pagekit CMS up to 1.0.18. This issue affects the function evaluate of the file app/modules/view/src/PhpEngine.php of the component StringStorage Template Handler. This manipulation causes improper neutralization of directives in dynamically evaluated code. Remote exploitation of the…
AnalizadaCrítica (9.8)0.50%—Pagekit17/12/202517/6/2026
An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
AnalizadaCrítica (9.9)0.53%—Pagekit17/12/202517/6/2026
An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary code via uploading a crafted PHP file.
AnalizadaMedia (4.7)0.39%—Pagekit1/10/202417/6/2026
Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.
ModificadaAlta (7.8)0.56%—Pagekit28/8/202317/6/2026
An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateController.php
ModificadaCrítica (9.8)18%—Pagekit20/9/202217/6/2026
A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files
ModificadaMedia (6.1)0.58%—Pagekit29/8/202217/6/2026
A cross-site scripting (XSS) vulnerability in Pagekit CMS v1.0.18 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Markdown text box under /blog/post/edit.
ModificadaCrítica (9.8)1.5%—Pagekit1/4/202217/6/2026
pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.
ModificadaMedia (5.4)0.54%—Pagekit16/6/202117/6/2026
In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malicious scripts. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/exp.svg" that will point to…
ModificadaAlta (8.8)0.76%—Pagekit22/11/201917/6/2026
A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a request.
ModificadaMedia (5.3)1.1%—Pagekit21/9/201917/6/2026
The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a valid user account is entered, which might make it easier for attackers to enumerate accounts.
ModificadaMedia (6.1)0.96%—Pagekit18/7/201817/6/2026
Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.
ModificadaMedia (4.8)3.2%—Pagekit2/6/201817/6/2026
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on…
ModificadaAlta (7.5)7.0%—Pagekit25/1/201717/6/2026
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered using this exploit. The SecureLayer7 ID is SL7_PGKT_01.
ModificadaMedia (6.8)1.3%—Yootheme Pagekit14/10/201417/6/2026
Open redirect vulnerability in YOOtheme Pagekit CMS 0.8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to index.php/user/logout.
ModificadaMedia (4.3)0.99%—Yootheme Pagekit14/10/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in YOOtheme Pagekit CMS 0.8.7 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP Referer header to index.php/user or (2) PATH_INFO to index.php.