Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2616▼ 309 respecto a la semana anterior
Críticas / altas1342▲ 71 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
594 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.24% | — | Craftcms FormieAI | 23/9/2026 | 30/9/2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification ID without permission or object-level authorization checks.… | |
| Aplazada | Alta (8.2) | 0.31% | — | Craftcms FormieAI | 23/9/2026 | 30/9/2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous formie/submissions/submit action in SubmissionsController::actionSubmit trusts a client-supplied submissionId when loading an incomplete submission without session binding, ownership validation, or a valid… | |
| Pendiente de análisis | Media (5.3) | 0.43% | — | Solspace FreeformAICraftcms Craft CMSAI | 23/9/2026 | 23/9/2026 | Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted values from public Freeform forms can be evaluated by the isolated Twig renderer when rendered into HTML attributes. An unauthenticated attacker can place Twig expressions in submitted field values,… | |
| Aplazada | Ninguna (0) | 0.44% | — | Kiwitcms Kiwi TcmsAI | 17/9/2026 | 30/9/2026 | Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migrate. The migration command is reentrant, so repeated access reports that no… | |
| Pendiente de análisis | Alta (8.7) | 0.55% | — | Craftcms Craft CMSAI | 16/9/2026 | 22/9/2026 | Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in Cp::elementLabelHtml(). Because Craft/Yii HMAC tokens are not bound to a… | |
| Pendiente de análisis | Alta (8.7) | 0.65% | — | Craftcms Craft CMSAI | 16/9/2026 | 22/9/2026 | Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft… | |
| Pendiente de análisis | Alta (8.2) | 0.41% | — | Craftcms Craft CMSAI | 16/9/2026 | 22/9/2026 | Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP remains available but the configured MySQL endpoint does not. The action… | |
| Pendiente de análisis | Media (5.1) | 0.24% | — | Craftcms Craft CMSAI | 16/9/2026 | 22/9/2026 | Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executes in authenticated Control Panel… | |
| Pendiente de análisis | Media (5.3) | 0.26% | — | Craftcms Craft CMSAI | 16/9/2026 | 22/9/2026 | Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) opens another author's entry in read-only mode, Craft unconditionally grants that… | |
| Aplazada | Baja (2.1) | 0.24% | — | PbootcmsAI | 16/9/2026 | 16/9/2026 | A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User Management. Such manipulation leads to cross-site request forgery. The attack may be… | |
| Aplazada | Baja (2) | 0.35% | — | PbootcmsAI | 16/9/2026 | 18/9/2026 | A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. This manipulation of the argument Title causes cross site scripting. The attack is possible to be carried out remotely.… | |
| Aplazada | Ninguna (0) | 0.42% | — | Kiwitcms Kiwi TcmsAI | 15/9/2026 | 30/9/2026 | Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS middleware send a Content-Security-Policy… | |
| Aplazada | Media (6.1) | 0.35% | — | Kiwi TcmsAI | 15/9/2026 | 30/9/2026 | Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim to an arbitrary external domain. The trusted origin can support… | |
| Aplazada | Alta (8.7) | 0.65% | — | Craftcms Craft CMSAI | 10/9/2026 | 11/9/2026 | A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker. | |
| Aplazada | Media (4.3) | 0.29% | — | PbootcmsAI | 9/9/2026 | 14/9/2026 | SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover. | |
| Aplazada | Media (5.5) | 0.66% | — | InstantcmsAI | 8/9/2026 | 9/9/2026 | InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be… | |
| Aplazada | Baja (3.1) | 0.27% | — | InstantcmsAI | 8/9/2026 | 11/9/2026 | InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redirect, the redirected target URL… | |
| Aplazada | Alta (8.7) | 0.85% | — | Craftcms Craft CMSAI | 8/9/2026 | 10/9/2026 | Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches… | |
| Aplazada | Alta (8.7) | 0.71% | — | Craftcms Craft CMSAI | 8/9/2026 | 8/9/2026 | Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON strings to bypass cleanse validation, then trigger arbitrary object… | |
| Aplazada | Alta (7.1) | 0.31% | — | Craftcms Craft CMSAI | 8/9/2026 | 19/9/2026 | Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does not call requireAdmin() when the targeted user is an administrator, unlike the mirror action… | |
| Aplazada | Baja (2) | 0.40% | — | FluentcmsAI | 7/9/2026 | 9/9/2026 | A vulnerability was found in FluentCMS up to 0.0.5. This affects the function GetAccessible of the file src/Backend/FluentCMS.Services/Permissions/PermissionManager.cs. Performing a manipulation results in missing authorization. It is possible to initiate the attack remotely. The exploit has been made public and could… | |
| Aplazada | Alta (7.1) | 0.51% | — | Craftcms Craft CMSAI | 2/9/2026 | 3/9/2026 | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed sites. The query path… | |
| Aplazada | Alta (8.7) | 0.45% | — | Craftcms Craft CMSAI | 2/9/2026 | 3/9/2026 | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed sites. The query path… | |
| Aplazada | Media (5.3) | 0.28% | — | Craftcms Craft CMSAI | 2/9/2026 | 2/9/2026 | Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-info endpoint with arbitrary folderIds to retrieve asset count and… | |
| Aplazada | Alta (8.7) | 0.44% | — | Craftcms Craft CMSAI | 2/9/2026 | 2/9/2026 | Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a valid reset URL for any admin user and set a new password via… |