Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2631▼ 309 respecto a la semana anterior
Críticas / altas1352▲ 90 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.29% | — | Pluxml | 10/3/2026 | 17/6/2026 | If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be automatically recognized for articles, such that an automated script is able to solve this anti-spam mechanism trivially and publish spam comments. The details of captcha… | |
| Analizada | Media (6.1) | 0.22% | — | Pluxml | 10/3/2026 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The application fails to properly sanitize or validate user-supplied input in the "link" field of a comment. An attacker can inject arbitrary JavaScript code using a <script> element.… | |
| Analizada | Media (4.8) | 0.36% | — | Pluxml | 27/2/2026 | 17/6/2026 | PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. The vendor was notified early about this vulnerability, but… | |
| Analizada | Media (5.1) | 0.18% | — | Pluxml | 27/2/2026 | 17/6/2026 | PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. The vendor was notified early about this vulnerability, but didn't respond with the details of… | |
| Analizada | Media (5.1) | 0.17% | — | Pluxml | 27/2/2026 | 17/6/2026 | PluXml CMS is vulnerable to Stored XSS in file uploading functionality. An authenticated attacker can upload an SVG file containing a malicious payload, which will be executed when a victim clicks the link associated with the uploaded image. In version 5.9.0-rc7 clicking the link associated with the uploaded image… | |
| Analizada | Baja (2) | 0.47% | — | Pluxml | 2/1/2026 | 17/6/2026 | A vulnerability was determined in PluXml up to 5.8.22. Affected is the function FileCookieJar::__destruct of the file core/admin/medias.php of the component Media Management Module. Executing a manipulation of the argument File can lead to deserialization. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.59% | — | Pluxml | 22/12/2025 | 17/6/2026 | Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP webshell into a theme file (e.g., home.php). | |
| Aplazada | Crítica (9.1) | 0.90% | — | Pluxml CMSAI | 17/10/2025 | 5/7/2026 | A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). An authenticated administrator user can overwrite this file with arbitrary PHP code via the admin panel, enabling execution… | |
| Aplazada | Crítica (9.8) | 0.86% | — | PluxmlAI | 29/10/2024 | 17/6/2026 | A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers to execute arbitrary code via injecting a crafted payload into a template. | |
| Modificada | Alta (8.8) | 1.3% | — | Pluxml | 25/1/2024 | 17/6/2026 | PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a crafted payload into the Content field. | |
| Modificada | Media (5.4) | 1.2% | — | Pluxml | 1/3/2022 | 9/7/2026 | A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post. | |
| Modificada | Alta (8.8) | 2.7% | — | Pluxml | 1/3/2022 | 9/7/2026 | Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages. | |
| Modificada | Media (5.4) | 0.74% | — | Pluxml | 15/2/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Media (5.4) | 0.75% | — | Pluxml | 15/2/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the author parameter. | |
| Modificada | Media (5.4) | 0.75% | — | Pluxml | 15/2/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content and thumbnail parameters. | |
| Modificada | Media (4.8) | 1.1% | — | Pluxml | 12/8/2021 | 17/6/2026 | PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field. | |
| Modificada | Media (4.8) | 0.76% | — | Pluxml | 12/8/2021 | 17/6/2026 | PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content. | |
| Modificada | Crítica (9.8) | 1.8% | — | Pluxml | 2/10/2020 | 17/6/2026 | class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment. | |
| Modificada | Media (5.4) | 0.64% | — | Pluxml | 1/11/2017 | 17/6/2026 | PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of privileges. | |
| Modificada | Media (4.3) | 1.2% | — | Pluxml | 26/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to file update. | |
| Modificada | Media (5) | 1.2% | — | Pluxml | 26/8/2012 | 16/6/2026 | PluXml before 5.1.6 allows remote attackers to obtain the installation path via the PHPSESSID. | |
| Modificada | Alta (7.5) | 9.8% | — | Pluxml | 26/8/2012 | 16/6/2026 | Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to include and execute arbitrary local files via a ..%2F (encoded dot dot slash) in the default_lang parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Pluxml | 3/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/auth.php in Pluxml 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Alta (7.5) | 8.2% | — | Pluxml | 27/6/2007 | 16/6/2026 | Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute arbitrary PHP code via a .jpg filename. |