Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Allenthusiast Reviewpost PHP PRO | 10/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in showproduct.php in ReviewPost Pro vB3 allows remote attackers to inject arbitrary web script or HTML via the date parameter. | |
| Modificada | Alta (7.5) | 3.0% | — | ALL Enthusiast INC Reviewpost PHP PRO | 19/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in All Enthusiast ReviewPost 2.5 allows remote attackers to execute arbitrary PHP code via a URL in the RP_PATH parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Photopost Reviewpost PHP PRO | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) si parameter to showcat.php, (2) cat or (3) page parameter to showproduct.php, or (4) report parameter to reportproduct.php. | |
| Modificada | Alta (7.5) | 2.7% | — | Photopost Reviewpost PHP PRO | 2/5/2005 | 16/6/2026 | ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended restrictions. | |
| Modificada | Alta (7.5) | 1.2% | — | Photopost Reviewpost PHP PRO | 3/1/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php. | |
| Modificada | Alta (7.5) | 1.2% | — | ALL Enthusiast INC Reviewpost PHP PRO | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in ReviewPost PHP Pro allow remote attackers to execute arbitrary SQL commands via the (1) product parameter to showproduct.php or (2) cat parameter to showcat.php. |