Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.21% | — | Dotnetfoundation Piranha CMS | 22/12/2025 | 5/7/2026 | A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field. | |
| Modificada | Media (6.1) | 0.21% | — | Dotnetfoundation Piranha CMS | 22/12/2025 | 5/7/2026 | A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Excerpt field. | |
| Analizada | Media (6.1) | 0.29% | — | Dotnetfoundation Piranha CMS | 23/10/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrary web scripts or HTML via creating a page and injecting a crafted payload into the Markdown blocks. | |
| Analizada | Media (6.8) | 0.32% | — | Dotnetfoundation Piranha CMS | 26/9/2025 | 17/6/2026 | PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, enabling execution of arbitrary JavaScript in another user s browser. | |
| Analizada | Media (4.7) | 0.46% | — | Dotnetfoundation Piranha CMS | 20/12/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by creating a page via the /manager/pages and then adding a markdown content with the XSS payload. | |
| Analizada | Media (4.7) | 0.51% | — | Dotnetfoundation Piranha CMS | 20/12/2024 | 17/6/2026 | A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media. This PDF can contain malicious JavaScript code, which is executed when a victim user opens or interacts with the PDF in their web browser, leading to a XSS vulnerability. | |
| Modificada | Alta (8.1) | 0.46% | — | Dotnetfoundation Piranha CMS | 16/11/2021 | 17/6/2026 | In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known. | |
| Modificada | Media (5.4) | 0.65% | — | Dotnetfoundation Piranha CMS | 25/10/2021 | 17/6/2026 | In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution. | |
| Modificada | Media (5.8) | 4.0% | 💥 Exploit | Ryan Ohara Piranha | 14/2/2014 | 17/6/2026 | The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request. |