Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▲ 67 respecto a la semana anterior
Críticas / altas1456▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)92▼ 421 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.23% | — | Creatorsofcode SimplephpAI | 27/5/2026 | 5/7/2026 | A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload. | |
| Analizada | Media (5.1) | 0.33% | — | Simplephpscripts Simple CMS PHP | 1/2/2026 | 17/6/2026 | Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request to execute arbitrary scripts and potentially hijack user sessions or perform phishing attacks. | |
| Analizada | Alta (8.6) | 0.57% | — | Simplephpscripts Simple CMS PHP | 1/2/2026 | 17/6/2026 | Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. Attackers can exploit unvalidated input parameters in the admin.php file to compromise the database management system and web application. | |
| Analizada | Media (5.1) | 0.33% | — | Simplephpscripts Simple CMS PHP | 1/2/2026 | 17/6/2026 | Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote attackers to inject malicious script code. Attackers can exploit the newUser and editUser modules to inject persistent scripts that execute on user list preview, potentially leading to session hijacking… | |
| Modificada | Media (6.1) | 0.36% | — | Simplephpscripts Newsletter Script PHP | 7/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SimplePHPscripts NewsLetter Script PHP 2.4. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of… | |
| Modificada | Media (6.1) | 0.36% | — | Simplephpscripts Simple Forum PHP | 7/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SimplePHPscripts Simple Forum PHP 2.7. This issue affects some unknown processing of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated… | |
| Modificada | Media (5.4) | 0.36% | — | Simplephpscripts Photo Gallery PHP | 7/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SimplePHPscripts Photo Gallery PHP 2.0. This vulnerability affects unknown code of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. VDB-233290 is the identifier… | |
| Modificada | Media (6.1) | 0.36% | — | Simplephpscripts News Script PHP PRO | 7/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SimplePHPscripts News Script PHP Pro 2.4. This affects an unknown part of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-233289… | |
| Modificada | Media (6.1) | 0.36% | — | Simplephpscripts Funeral Script PHP | 7/7/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts Funeral Script PHP 3.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The… | |
| Modificada | Media (6.1) | 0.36% | — | Simplephpscripts FAQ Script PHP | 7/7/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts FAQ Script PHP 2.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The… | |
| Modificada | Media (6.1) | 0.39% | — | Simplephpscripts Guestbook Script | 30/6/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts GuestBook Script 2.2. It has been classified as problematic. This affects an unknown part of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is recommended to… | |
| Modificada | Media (6.1) | 0.39% | — | Simplephpscripts Event Script | 30/6/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts Event Script 2.1 and classified as problematic. Affected by this issue is some unknown functionality of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. It is recommended to… | |
| Modificada | Media (6.1) | 0.39% | — | Simplephpscripts Simple Blog | 30/6/2023 | 17/6/2026 | A vulnerability has been found in SimplePHPscripts Simple Blog 3.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. It is… | |
| Modificada | Media (6.1) | 0.50% | — | Simplephpscripts Classified ADS Script PHP | 29/6/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file user.php of the component HTTP POST Request Handler. The manipulation of the argument title leads to cross site scripting. The attack can… | |
| Modificada | Media (6.1) | 0.50% | — | Simplephpscripts Classified ADS Script PHP | 29/6/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation of the argument p leads to cross site scripting. It is possible to launch the attack… | |
| Modificada | Alta (7.5) | 2.7% | — | Carsten Wulff Simplephpweb | 10/9/2009 | 16/6/2026 | admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via unknown vectors. NOTE: some of these details are obtained from third party information. |