Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.17% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'first_name' in '/clients/save_contact/'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/tickets/save'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'custom_field_1' in '/estimate_requests/save_estimate_request'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'reply_message' in '/messages/reply'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/events/save'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in'/projects/save'. | |
| Modificada | Media (6.5) | 0.38% | — | Fairsketch Rise Ultimate Project Manager | 3/11/2025 | 5/7/2026 | FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for which they lack view or edit authorization, due to missing authorization checks in the ticketing/commenting API. | |
| Modificada | Alta (8.1) | 1.1% | — | Fairsketch Rise Ultimate Project Manager | 10/10/2025 | 5/7/2026 | Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise.… | |
| Modificada | Media (6.1) | 0.23% | — | Fairsketch Rise Ultimate Project Manager | 29/9/2025 | 5/7/2026 | A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrator to store a JavaScript payload using the file explorer in the admin dashboard when creating new folders. | |
| Analizada | Media (5.3) | 0.48% | — | Fairsketch Rise Ultimate Project Manager | 22/4/2025 | 17/6/2026 | A vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php/team_members/save_profile_image/ of the component Profile Picture Handler. The manipulation of the argument profile_image_file leads to… | |
| Analizada | Media (5.3) | 16% | — | Fairsketch Rise Ultimate Project Manager | 17/9/2024 | 17/6/2026 | A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code of the file /index.php/dashboard/save. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.9) | 0.48% | — | Fairsketch Rise Ultimate Project Manager | 15/1/2024 | 17/6/2026 | A vulnerability classified as problematic was found in CodeCanyon RISE Ultimate Project Manager 3.5.3. This vulnerability affects unknown code of the file /index.php/signin. The manipulation of the argument redirect with the input http://evil.com leads to open redirect. The attack can be initiated remotely. The… | |
| Modificada | Crítica (9.8) | 3.3% | — | Fairsketch Rise Ultimate Project Manager | 23/1/2018 | 17/6/2026 | SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to index.php/knowledge_base/get_article_suggestion/. | |
| Modificada | Media (5.4) | 0.80% | — | Fairsketch Rise Ultimate Project Manager | 12/7/2017 | 17/6/2026 | In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the My Profile section. All input fields are vulnerable. | |
| Modificada | Media (5.4) | 0.66% | — | Fairsketch Rise Ultimate Project Manager | 12/7/2017 | 17/6/2026 | In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the Messaging section. Subject and Message fields are vulnerable. |