Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Munzir Myshouts-shoutboxAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Munzir Author: Munzir myshouts-shoutbox allows Reflected XSS.This issue affects Author: Munzir: from n/a through <= 0.9. | |
| Modificada | Crítica (9.8) | 4.9% | — | WP Live Chat Shoutbox Project WP Live Chat Shoutbox | 24/4/2023 | 17/6/2026 | The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Modificada | Media (6.1) | 0.46% | — | WP Live Chat Shoutbox Project WP Live Chat Shoutbox | 24/4/2023 | 17/6/2026 | The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputting it back in the Shoutbox, leading to Stored Cross-Site Scripting which could be used against high privilege users such as admins. | |
| Modificada | Crítica (9.8) | 2.7% | — | Thekrotek Smart Shoutbox | 17/2/2018 | 17/6/2026 | SQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI. | |
| Modificada | Media (4.3) | 1.0% | — | Thomas Mammitzsch VX Xajax Shoutbox | 9/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the xaJax Shoutbox (vx_xajax_shoutbox) extension before 1.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 14% | — | Joomla.batjo COM Shoutbox | 26/4/2010 | 16/6/2026 | Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Media (4.3) | 1.5% | — | Plohni Shoutbox | 20/4/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Plohni Shoutbox 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) input_name and (2) input_text parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.0% | — | Jonas Renggli Vshoutbox | 17/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the vShoutbox (vshoutbox) extension 0.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 3.6% | — | Maniacomputer Mcshoutbox | 16/10/2009 | 16/6/2026 | Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in smilies/. | |
| Modificada | Media (6.8) | 2.0% | — | Maniacomputer Mcshoutbox | 16/10/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Media (4.3) | 1.7% | — | Maniacomputer Mcshoutbox | 16/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Prezmo Small Shoutbox | 26/2/2009 | 16/6/2026 | SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action. | |
| Modificada | Media (5) | 1.2% | — | Designplace Asp/ms Access Shoutbox | 9/10/2008 | 16/6/2026 | ASP/MS Access Shoutbox, probably 1.1 beta, stores db/shoutdb.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request. | |
| Modificada | Alta (7.5) | 2.2% | — | Phphq Phshoutbox Final | 27/4/2008 | 16/6/2026 | phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php. | |
| Modificada | Media (4.3) | 1.2% | — | Simple Machines SMF Shoutbox | 14/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with "&#", contain the desired script, and end with ";". | |
| Modificada | Media (4.3) | 1.1% | — | Drupal Shoutbox | 10/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Shoutbox module for Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users to inject arbitrary web script or HTML via Shoutbox block messages. | |
| Modificada | Media (4.3) | 1.1% | — | Script-fun Sf-shoutbox | 14/11/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in main.php in SF-Shoutbox 1.2.1 through 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) nick (aka Name) and (2) shout (aka Shout) parameters. | |
| Modificada | Media (4.3) | 1.1% | — | Dscripting.com D22-shoutbox | 22/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in D22-Shoutbox for Invision Power Board (IPB or IP.Board) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 2.8% | — | Mapos Scripts Shoutbox | 14/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. | |
| Modificada | Alta (7.8) | 1.5% | — | Toxiclab Shoutbox | 29/1/2007 | 16/6/2026 | Toxiclab Shoutbox 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db.mdb. | |
| Modificada | Media (6.8) | 1.8% | — | Knusperleicht Shoutbox | 23/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) sbNick or (2) sbKommentar parameter. | |
| Modificada | Alta (7.5) | 2.2% | — | Phpbb Ajax Shoutbox | 17/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Media (5.1) | 3.4% | — | Knusperleicht Shoutbox | 5/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sb_include_path parameter. | |
| Modificada | Media (5) | 1.1% | — | D2-shoutbox | 10/3/2006 | 16/6/2026 | SQL injection vulnerability in D2-Shoutbox 4.2 allows remote attackers to execute arbitrary SQL commands via the load parameter, when performing a Shoutbox action through Invision Power Board (IPB). | |
| Modificada | Media (4.3) | 1.3% | — | Unknown Domain Shoutbox | 8/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Unknown Domain Shoutbox 2005.07.21 allow remote attackers to inject arbitrary web script or HTML, possibly via the (1) Handle or (2) Message fields. |