Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.13% | — | Plugin-planet User Submitted PostsAI | 30/9/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS. This issue affects User Submitted Posts: from n/a through 20260810. | |
| Aplazada | Alta (7) | 0.23% | — | InvoiceplaneAI | 28/9/2026 | 30/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Users::form() performs no object-level authorization check on user_id = 1. A Secondary Administrator (user_type = 1, user_id != 1) can rewrite the Primary Administrator's user_type to 2 (Guest /… | |
| Aplazada | Alta (8.7) | 0.28% | — | InvoiceplaneAI | 28/9/2026 | 30/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an authorization guard to Users::change_password(), was added to address a previous authorization flaw that allowed a secondary administrator (user_type=1, user_id != 1) to directly change the password… | |
| Aplazada | Alta (7.5) | 0.30% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privileges after a role downgrade because Admin_Controller trusts the user_type snapshot stored in an existing session instead of revalidating… | |
| Aplazada | Media (4.8) | 0.22% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and renders them unescaped inside double-quoted value attributes in the invoice mailer form and quote mailer form. An… | |
| Aplazada | Media (4.8) | 0.25% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's User_Controller compares the session user_type value with the required role by using PHP's loose inequality operator. Under a non-standard session backend that returns unexpected scalar… | |
| Aplazada | Media (6.5) | 0.26% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Users::change_password() method accepts a user_id from the URL and updates that account's password without an object-level authorization check. An authenticated secondary administrator can… | |
| Aplazada | Media (5.3) | 0.24% | — | InvoiceplaneAI | 25/9/2026 | 29/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from the URL path directly to the application log without neutralizing CRLF characters. An unauthenticated requester can place forged log… | |
| Aplazada | Media (6.5) | 0.17% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Payments::delete(), Recurring::delete(), and User_clients::delete(). Although the routes require POST, they do not validate… | |
| Aplazada | Media (6.5) | 0.17% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without CSRF token validation. When an authenticated administrator loads attacker-controlled content that requests… | |
| Aplazada | Media (6) | 0.23% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores an administrator-controlled custom_field_table value without validating it against the allowed custom-field table names. Mdl_custom_fields::used() later concatenates that stored value… | |
| Aplazada | Alta (7.5) | 0.46% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Invoices::generate_xml() method appends a database-derived xml_id to the XMLconfigs helper directory and includes the resulting PHP path without validating the identifier. A low-privileged… | |
| Aplazada | Alta (7.5) | 0.33% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POST and validating a CSRF token. When an authenticated administrator loads… | |
| Aplazada | Media (4.9) | 0.28% | — | InvoiceplaneAI | 25/9/2026 | 29/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping EXIF metadata. When an administrator uploads an image through invoice attachments, quote attachments, or another attachment… | |
| Aplazada | Crítica (9.1) | 0.45% | — | InvoiceplaneAI | 25/9/2026 | 28/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an administrator-controlled file-write capability. A malicious PHP file placed in the… | |
| Aplazada | Alta (7.2) | 0.40% | — | InvoiceplaneAI | 25/9/2026 | 29/9/2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for ip_tax_rates in Settings::index() without strict integer validation. A crafted… | |
| Aplazada | Media (6.7) | 0.17% | — | Planet Igs-5225-8p2t4sAI | 18/9/2026 | 22/9/2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses. An attacker who obtains the device configuration file can recover the privileged-mode access password. | |
| Aplazada | Alta (7.5) | 0.58% | — | Planet Igs-5225-8p2t4sAI | 18/9/2026 | 26/9/2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer allows a remote administrator to cause a denial of service or potentially execute… | |
| Aplazada | Alta (7.7) | 0.71% | — | Planet Igs-5225-8p2t4sAI | 18/9/2026 | 22/9/2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer allows a remote authenticated attacker to cause a denial of service or potentially… | |
| Aplazada | Alta (8.4) | 0.18% | — | Planet Igs-5225-8p2t4sAI | 18/9/2026 | 22/9/2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software. An attacker with privileged access to the device can enable this debug mode to execute arbitrary code on the underlying operating system and… | |
| Aplazada | Alta (8.7) | 1.9% | — | Planet Igs-5225-8p2t4sAI | 18/9/2026 | 22/9/2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system() without sufficient filtering, allowing a remote authenticated attacker to execute arbitrary… | |
| Aplazada | Alta (7.2) | 0.49% | — | Plugin-planet Simple Ajax ChatAI | 11/9/2026 | 11/9/2026 | The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (5.3) | 0.34% | — | PlaneAI | 5/9/2026 | 16/9/2026 | Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint. | |
| Analizada | Alta (8.4) | 0.22% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 3/9/2026 | 9/9/2026 | The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon… | |
| Analizada | Alta (7.5) | 0.36% | — | Wso2 API Control PlaneWso2 API Manager | 3/9/2026 | 15/9/2026 | The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to… |