Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3062▲ 584 respecto a la semana anterior
Críticas / altas1459▲ 293 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
2127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | — | — | Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the "Theme to Components" functionality (admin/components.php) via the title parameter. The stored title is… | |
| Aplazada | Alta (7.1) | — | — | Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated user with page-editing rights can store an arbitrary filesystem path in a page's template attribute. On the public front-end, this value is passed unsanitized to… | |
| Aplazada | Alta (8.8) | — | — | Getsimplecms Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is… | |
| Aplazada | Crítica (9.6) | — | — | Getsimplecms Getsimple CMS CEAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a… | |
| Aplazada | Alta (7.5) | — | — | Getsimplecms Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALIDATE_URL) — there is no validation of the request destination. An… | |
| Aplazada | Crítica (9.1) | — | — | Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written… | |
| Aplazada | Crítica (9.1) | — | — | Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and… | |
| Aplazada | Media (6.9) | — | — | Simple-php-router Simple PHP RouterAI | 30/9/2026 | 1/10/2026 | simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. Attackers can spoof X-Forwarded-For, CF-Connecting-IP, or Client-IP headers to impersonate whitelisted… | |
| En análisis | Crítica (9.2) | 0.27% | — | Simple-gitAISimple-git Argv-parserAI | 29/9/2026 | 30/9/2026 | simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits VISUAL from GitEnvKeys, so prepareEnv drops the value before vulnerabilityCheck can classify it as allowUnsafeEditor. A… | |
| En análisis | Crítica (9.2) | 0.27% | — | Simple-gitAI | 29/9/2026 | 30/9/2026 | simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token>.cmd as unsafe configuration. An application that passes attacker-controlled… | |
| En análisis | Alta (8.1) | 0.36% | — | Simple-gitAI | 29/9/2026 | 30/9/2026 | simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option… | |
| En análisis | Alta (8.1) | 0.46% | — | Simple-gitAI | 29/9/2026 | 30/9/2026 | simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The missing include.path… | |
| Aplazada | Alta (8.8) | 0.25% | — | CmsimpleAI | 22/9/2026 | 25/9/2026 | CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because administrator authentication is cookie-only and no CSRF token is enforced, an unauthenticated attacker… | |
| Aplazada | Media (5.3) | 0.42% | — | Really-simple-plugins Really Simple SecurityAI | 18/9/2026 | 18/9/2026 | The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of its own options, allowing unauthenticated attackers to grow that option without bound and to slow the site's handling of missing pages. | |
| Aplazada | Media (5.3) | 0.29% | — | Simple-membership-plugin Simple MembershipAI | 17/9/2026 | 17/9/2026 | Contributor Broken Access Control in Simple Membership <= 4.8.2 versions. | |
| Aplazada | Baja (2.3) | 0.36% | — | Really-simple-plugins Really Simple SecurityAI | 14/9/2026 | 19/9/2026 | Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page update handler. Attackers can submit a… | |
| Aplazada | Alta (7.5) | 0.34% | — | Really-simple-plugins Really Simple SecurityAI | 13/9/2026 | 14/9/2026 | The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator. | |
| Aplazada | Media (5.4) | 0.23% | — | Simple-membership-plugin Simple MembershipAI | 13/9/2026 | 14/9/2026 | The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level. | |
| Aplazada | Media (6.5) | 0.22% | — | Idokd Simple PaymentAI | 11/9/2026 | 11/9/2026 | Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Getsimple CMSAIGetsimple CMS CEAI | 11/9/2026 | 30/9/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security… | |
| Aplazada | Media (6.5) | 0.31% | — | Simple Captcha With Cloudflare TurnstileAI | 11/9/2026 | 11/9/2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | |
| Aplazada | Alta (7.2) | 0.49% | — | Plugin-planet Simple Ajax ChatAI | 11/9/2026 | 11/9/2026 | The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (5.6) | 0.25% | — | Simple Cloudflare TurnstileAI | 10/9/2026 | 10/9/2026 | Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions. | |
| Aplazada | Alta (8.8) | 0.67% | — | CmsimpleAICmsimple CoauthorsAI | 8/9/2026 | 9/9/2026 | A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution by referencing crafted external or uploaded text content through the affected content import feature. | |
| Aplazada | Baja (2.1) | 0.47% | — | Sourcecodester Simple Traffic Offense SystemAI | 7/9/2026 | 11/9/2026 | A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of… |