Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Munzir Myshouts-shoutboxAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Munzir Author: Munzir myshouts-shoutbox allows Reflected XSS.This issue affects Author: Munzir: from n/a through <= 0.9.
ModificadaCrítica (9.8)4.9%—WP Live Chat Shoutbox Project WP Live Chat Shoutbox24/4/202317/6/2026
The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
ModificadaMedia (6.1)0.46%—WP Live Chat Shoutbox Project WP Live Chat Shoutbox24/4/202317/6/2026
The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before outputting it back in the Shoutbox, leading to Stored Cross-Site Scripting which could be used against high privilege users such as admins.
ModificadaCrítica (9.8)2.7%—Thekrotek Smart Shoutbox17/2/201817/6/2026
SQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI.
ModificadaMedia (4.3)1.0%—Thomas Mammitzsch VX Xajax Shoutbox9/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in the xaJax Shoutbox (vx_xajax_shoutbox) extension before 1.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)14%—Joomla.batjo COM Shoutbox26/4/201016/6/2026
Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
ModificadaMedia (4.3)1.5%—Plohni Shoutbox20/4/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Plohni Shoutbox 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) input_name and (2) input_text parameters. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.0%—Jonas Renggli Vshoutbox17/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in the vShoutbox (vshoutbox) extension 0.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.5)3.6%—Maniacomputer Mcshoutbox16/10/200916/6/2026
Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in smilies/.
ModificadaMedia (6.8)2.0%—Maniacomputer Mcshoutbox16/10/200916/6/2026
Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
ModificadaMedia (4.3)1.7%—Maniacomputer Mcshoutbox16/10/200916/6/2026
Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter.
ModificadaAlta (7.5)0.97%—Prezmo Small Shoutbox26/2/200916/6/2026
SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.
ModificadaMedia (5)1.2%—Designplace Asp/ms Access Shoutbox9/10/200816/6/2026
ASP/MS Access Shoutbox, probably 1.1 beta, stores db/shoutdb.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.
ModificadaAlta (7.5)2.2%—Phphq Phshoutbox Final27/4/200816/6/2026
phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php.
ModificadaMedia (4.3)1.2%—Simple Machines SMF Shoutbox14/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with "&#", contain the desired script, and end with ";".
ModificadaMedia (4.3)1.1%—Drupal Shoutbox10/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in the Shoutbox module for Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users to inject arbitrary web script or HTML via Shoutbox block messages.
ModificadaMedia (4.3)1.1%—Script-fun Sf-shoutbox14/11/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in main.php in SF-Shoutbox 1.2.1 through 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) nick (aka Name) and (2) shout (aka Shout) parameters.
ModificadaMedia (4.3)1.1%—Dscripting.com D22-shoutbox22/8/200716/6/2026
Cross-site scripting (XSS) vulnerability in D22-Shoutbox for Invision Power Board (IPB or IP.Board) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)2.8%—Mapos Scripts Shoutbox14/8/200716/6/2026
PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.
ModificadaAlta (7.8)1.5%—Toxiclab Shoutbox29/1/200716/6/2026
Toxiclab Shoutbox 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db.mdb.
ModificadaMedia (6.8)1.8%—Knusperleicht Shoutbox23/12/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) sbNick or (2) sbKommentar parameter.
ModificadaAlta (7.5)2.2%—Phpbb Ajax Shoutbox17/10/200616/6/2026
PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
ModificadaMedia (5.1)3.4%—Knusperleicht Shoutbox5/8/200616/6/2026
PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sb_include_path parameter.
ModificadaMedia (5)1.1%—D2-shoutbox10/3/200616/6/2026
SQL injection vulnerability in D2-Shoutbox 4.2 allows remote attackers to execute arbitrary SQL commands via the load parameter, when performing a Shoutbox action through Invision Power Board (IPB).
ModificadaMedia (4.3)1.3%—Unknown Domain Shoutbox8/2/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Unknown Domain Shoutbox 2005.07.21 allow remote attackers to inject arbitrary web script or HTML, possibly via the (1) Handle or (2) Message fields.