Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.34% | — | Oretnom23 Simple Forum/discussion System | 22/9/2025 | 17/6/2026 | A security flaw has been discovered in SourceCodester Simple Forum Discussion System 1.0. This affects an unknown function of the file /ajax.php?action=save_category. The manipulation of the argument Description results in sql injection. The attack can be executed remotely. The exploit has been released to the public… | |
| Analizada | Media (5.5) | 0.42% | — | Oretnom23 Simple Forum/discussion System | 8/9/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of the file /admin_class.php?action=login. Performing manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be… | |
| Analizada | Baja (2.1) | 0.56% | — | Fabian Simple Forum | 29/6/2025 | 17/6/2026 | A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. This vulnerability affects unknown code of the file /forum_downloadfile.php. The manipulation of the argument filename leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Baja (2.1) | 0.40% | — | Fabian Simple Forum | 29/6/2025 | 17/6/2026 | A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /forum1.php. The manipulation of the argument File leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Baja (2) | 0.34% | — | Fabian Simple Forum | 29/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in code-projects Simple Forum 1.0. Affected is an unknown function of the file /forum_edit1.php. The manipulation of the argument text leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Baja (2.1) | 0.37% | — | Fabian Simple Forum | 29/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of the file /forum1.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Baja (2.1) | 0.41% | — | Fabian Simple Forum | 29/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Simple Forum 1.0. This vulnerability affects unknown code of the file /forum_edit.php. The manipulation of the argument iii leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Simple Forum | 29/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Simple Forum 1.0. This affects an unknown part of the file /forum_viewfile.php. The manipulation of the argument Name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.5) | 0.49% | — | Fabian Simple Forum | 29/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple Forum 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /register1.php. The manipulation of the argument User leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.49% | — | Fabian Simple Forum | 29/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple Forum 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /signin.php. The manipulation of the argument User leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.75% | — | Oretnom23 Simple Forum/discussion System | 20/9/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument page leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.8) | 0.54% | — | Oretnom23 Simple Forum Website | 6/9/2024 | 17/6/2026 | Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=. | |
| Analizada | Media (6.9) | 0.49% | — | Oretnom23 Simple Forum Website | 19/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Forum Website 1.0. This affects an unknown part of the file /registration.php of the component Signup Page. The manipulation of the argument username leads to cross site scripting. It is possible to initiate the attack remotely.… | |
| Modificada | Media (6.1) | 0.36% | — | Simplephpscripts Simple Forum PHP | 7/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SimplePHPscripts Simple Forum PHP 2.7. This issue affects some unknown processing of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated… | |
| Modificada | Crítica (9.8) | 1.2% | — | Oretnom23 Simple Forum/discussion System | 21/12/2021 | 17/6/2026 | Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability. | |
| Modificada | Alta (7.5) | 2.8% | — | Yellowswordfish Simple Forum | 24/8/2009 | 16/6/2026 | SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect. | |
| Modificada | Media (6.8) | 2.4% | — | Drennansoft MY Simple Forum | 16/12/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in My Simple Forum 3.0 and 4.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter. | |
| Modificada | Alta (7.5) | 7.3% | — | Lovecms THE Simple Forum | 2/12/2008 | 16/6/2026 | The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to change the administrator password via a direct request to modules/simpleforum/admin/index.php. | |
| Modificada | Media (5) | 2.7% | — | Gerd Tentler Simple Forum | 1/2/2008 | 16/6/2026 | Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Gerd Tentler Simple Forum | 1/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) open and (2) date_show parameters. | |
| Modificada | Alta (7.5) | 1.1% | — | THE WEB Drivers Simple Forum | 8/11/2006 | 16/6/2026 | SQL injection vulnerability in message_details.php in The Web Drivers Simple Forum, dated 20060318, allows remote attackers to execute arbitrary SQL commands via the id parameter. |