Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.57% | — | SmartyAI | 31/8/2026 | 8/9/2026 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and src/FunctionHandler/Fetch.php used Security::isTrustedUri() to validate only the… | |
| Aplazada | Media (6.9) | 0.51% | — | SmartyAI | 7/8/2026 | 9/9/2026 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chains can be referenced from a template, allowing a php://filter-wrapped… | |
| Aplazada | Media (6.9) | 0.53% | — | SmartyAI | 7/8/2026 | 9/9/2026 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating that a requested path lies within a configured secure directory. An attacker able… | |
| Aplazada | Media (6.5) | 0.16% | — | Smartypants SP Project AND Document ManagerAI | 17/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Smartypants SP Project & Document Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Project & Document Manager: from n/a through 4.70. | |
| Modificada | Media (6.5) | 0.57% | — | Smartypantsplugins SP Project & Document Manager | 9/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.71. | |
| Aplazada | Alta (7.3) | 0.51% | — | SmartyAI | 28/5/2024 | 17/6/2026 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code by choosing a malicious file name for an extends-tag. Sites that cannot fully trust template authors should update asap. All users are advised… | |
| Analizada | Media (6.5) | 0.52% | — | Smartypantsplugins SP Project & Document Manager | 15/5/2024 | 17/6/2026 | The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user | |
| Analizada | Media (6.5) | 0.43% | — | Smartypantsplugins SP Project & Document Manager | 15/5/2024 | 17/6/2026 | The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user | |
| Aplazada | Media (6.3) | 0.35% | — | Smartypants SP Project AND Document ManagerAI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.69. | |
| Aplazada | Alta (7.6) | 0.49% | — | Smartypants SP Project AND Document ManagerAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager : from n/a through 4.71. | |
| Modificada | Alta (8.8) | 0.54% | — | Smartypantsplugins SP Project & Document Manager | 28/2/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.69. | |
| Modificada | Alta (8.8) | 0.72% | — | Smartypantsplugins SP Project & Document Manager | 3/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affects SP Project & Document Manager: from n/a through 4.67. | |
| Modificada | Alta (8.8) | 0.24% | — | Presspage Smarty FOR Wordpress | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressPage Entertainment Inc. Smarty for WordPress plugin <= 3.1.35 versions. | |
| Modificada | Media (4.8) | 0.42% | — | Smarty | 29/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PressPage Entertainment Inc. Smarty for WordPress plugin <= 3.1.35 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Smartypantsplugins SP Project & Document Manager | 10/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smartypants SP Project & Document Manager plugin <= 4.67 versions. | |
| Modificada | Alta (8.8) | 0.73% | — | Smartypantsplugins SP Project & Document Manager | 30/6/2023 | 17/6/2026 | The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for… | |
| Modificada | Media (6.1) | 1.0% | — | SmartyFedoraproject Fedora | 28/3/2023 | 17/6/2026 | Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web… | |
| Modificada | Media (5.4) | 1.1% | — | SmartyDebian Linux | 15/9/2022 | 17/6/2026 | In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user. | |
| Modificada | Media (6.1) | 0.62% | — | Smartypantsplugins SP Project & Document Manager | 22/8/2022 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress | |
| Modificada | Media (6.5) | 0.97% | — | Smartypantsplugins SP Project & Document Manager | 25/7/2022 | 17/6/2026 | The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files. | |
| Modificada | Alta (8.8) | 4.9% | — | SmartyDebian LinuxFedoraproject Fedora | 24/5/2022 | 17/6/2026 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name. Sites that cannot fully trust template authors should upgrade to… | |
| Modificada | Alta (8.8) | 1.7% | — | Smartypantsplugins SP Project & Document Manager | 25/4/2022 | 17/6/2026 | The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows… | |
| Modificada | Alta (8.8) | 1.9% | — | SmartyDebian LinuxFedoraproject Fedora | 10/1/2022 | 17/6/2026 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a malicious math string. If a math string was passed through as user provided data to the math function,… | |
| Modificada | Alta (8.8) | 2.2% | — | SmartyDebian LinuxFedoraproject Fedora | 10/1/2022 | 17/6/2026 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.3, template authors could run restricted static php methods. Users should upgrade to version 3.1.43 or 4.0.3 to receive a patch. | |
| Modificada | Alta (7.5) | 1.8% | — | Smartypantsplugins SP Rental Manager | 9/9/2021 | 17/6/2026 | The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shortcodes.php file which allows attackers to retrieve information contained in a site's database, in versions up to and including 1.5.3. |