Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2631▼ 309 respecto a la semana anterior
Críticas / altas1352▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.29%—Pluxml10/3/202617/6/2026
If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be automatically recognized for articles, such that an automated script is able to solve this anti-spam mechanism trivially and publish spam comments. The details of captcha…
AnalizadaMedia (6.1)0.22%—Pluxml10/3/202617/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The application fails to properly sanitize or validate user-supplied input in the "link" field of a comment. An attacker can inject arbitrary JavaScript code using a <script> element.…
AnalizadaMedia (4.8)0.36%—Pluxml27/2/202617/6/2026
PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. The vendor was notified early about this vulnerability, but…
AnalizadaMedia (5.1)0.18%—Pluxml27/2/202617/6/2026
PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. The vendor was notified early about this vulnerability, but didn't respond with the details of…
AnalizadaMedia (5.1)0.17%—Pluxml27/2/202617/6/2026
PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious payload, which will be executed when a victim clicks the link associated with the uploaded image. In version 5.9.0-rc7 clicking the link associated with the uploaded image…
AnalizadaBaja (2)0.47%—Pluxml2/1/202617/6/2026
A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the component Media Management Module. Executing a manipulation of the argument File can lead to deserialization. The attack can be launched remotely. The exploit has been…
AnalizadaMedia (6.5)0.59%—Pluxml22/12/202517/6/2026
Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.php).
AplazadaCrítica (9.1)0.90%—Pluxml CMSAI17/10/20255/7/2026
A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). An authenticated administrator user can overwrite this file with arbitrary PHP code via the admin panel, enabling execution…
AplazadaCrítica (9.8)0.86%—PluxmlAI29/10/202417/6/2026
A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers to execute arbitrary code via injecting a crafted payload into a template.
ModificadaAlta (8.8)1.3%—Pluxml25/1/202417/6/2026
PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a crafted payload into the Content field.
ModificadaMedia (5.4)1.2%—Pluxml1/3/20229/7/2026
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.
ModificadaAlta (8.8)2.7%—Pluxml1/3/20229/7/2026
Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.
ModificadaMedia (5.4)0.74%—Pluxml15/2/202217/6/2026
A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML.
ModificadaMedia (5.4)0.75%—Pluxml15/2/202217/6/2026
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the author parameter.
ModificadaMedia (5.4)0.75%—Pluxml15/2/202217/6/2026
A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content and thumbnail parameters.
ModificadaMedia (4.8)1.1%—Pluxml12/8/202117/6/2026
PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.
ModificadaMedia (4.8)0.76%—Pluxml12/8/202117/6/2026
PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.
ModificadaCrítica (9.8)1.8%—Pluxml2/10/202017/6/2026
class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.
ModificadaMedia (5.4)0.64%—Pluxml1/11/201717/6/2026
PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of privileges.
ModificadaMedia (4.3)1.2%—Pluxml26/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to file update.
ModificadaMedia (5)1.2%—Pluxml26/8/201216/6/2026
PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID.
ModificadaAlta (7.5)9.8%—Pluxml26/8/201216/6/2026
Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the default_lang parameter.
ModificadaMedia (4.3)1.9%—Pluxml3/7/200716/6/2026
Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
ModificadaAlta (7.5)8.2%—Pluxml27/6/200716/6/2026
Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg filename.