Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.37% | — | TestlinkAI | 7/8/2026 | 24/9/2026 | TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege guest accounts, to read arbitrary attachments by supplying an integer attachment ID to the attachmentdownload.php handler without any project or role authorization check.… | |
| Analizada | Alta (8.1) | 0.43% | — | Testlink | 27/9/2024 | 17/6/2026 | TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id parameter to another ID. The application does not carry out a check on the user's… | |
| Analizada | Media (6.1) | 0.35% | — | Testlink | 26/8/2024 | 17/6/2026 | TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name. | |
| Modificada | Alta (7.5) | 0.65% | — | Testlink | 30/12/2023 | 17/6/2026 | TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used. | |
| Modificada | Alta (8.8) | 0.50% | — | Testlink | 20/9/2022 | 17/6/2026 | TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php. | |
| Modificada | Media (5.4) | 0.65% | — | Testlink | 16/9/2022 | 17/6/2026 | TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Testlink | 16/9/2022 | 17/6/2026 | TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php | |
| Modificada | Alta (7.2) | 1.2% | — | Testlink | 16/9/2022 | 17/6/2026 | TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Testlink | 27/4/2020 | 17/6/2026 | In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web site associated with the session. | |
| Modificada | Alta (7.5) | 0.75% | — | Testlink | 27/4/2020 | 17/6/2026 | In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials. | |
| Modificada | Alta (8.8) | 16% | — | Testlink | 3/4/2020 | 17/6/2026 | An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to a… | |
| Modificada | Crítica (9.8) | 1.7% | — | Testlink | 3/4/2020 | 17/6/2026 | A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter. | |
| Modificada | Crítica (9.8) | 2.9% | — | Testlink | 3/4/2020 | 17/6/2026 | A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter. | |
| Modificada | Alta (8.8) | 2.0% | — | Testlink | 5/3/2020 | 17/6/2026 | Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tproject_id parameter to keywordsView.php; the (2) req_spec_id parameter to reqSpecCompareRevisions.php; the (3) requirement_id parameter to reqCompareVersions.php; the (4)… | |
| Modificada | Alta (8.8) | 1.4% | — | Testlink | 10/2/2020 | 17/6/2026 | An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vulnerable to authenticated SQL Injection. | |
| Modificada | Media (6.1) | 0.95% | — | Testlink | 20/1/2020 | 17/6/2026 | TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exists because of an incomplete fix for CVE-2019-19491. | |
| Modificada | Media (6.1) | 0.79% | — | Testlink | 2/12/2019 | 17/6/2026 | TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/tcEdit.php?doAction=doDeleteStep request. | |
| Modificada | Media (5.3) | 0.50% | — | Jenkins Testlink | 7/8/2019 | 17/6/2026 | Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Media (6.1) | 0.91% | — | Testlink | 1/8/2019 | 17/6/2026 | TestLink 1.9.19 has XSS via the error.php message parameter. | |
| Modificada | Media (5.4) | 0.70% | — | Jenkins Testlink | 13/3/2018 | 17/6/2026 | A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and earlier in TestLinkBuildAction/summary.jelly and others that allow an attacker who can control e.g. TestLink report names to have Jenkins serve arbitrary HTML and JavaScript | |
| Modificada | Alta (7.5) | 1.5% | — | Testlink | 5/3/2018 | 17/6/2026 | TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload.php. | |
| Modificada | Alta (7.5) | 6.1% | — | Testlink | 25/2/2018 | 17/6/2026 | install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES data during installation to provide a long, crafted value. | |
| Modificada | Media (6.1) | 0.76% | — | Testlink | 26/9/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML via the (1) selected_end_date or (2) selected_start_date parameter to lib/results/tcCreatedPerUserOnTestProject.php; the (3) containerType parameter to… | |
| Modificada | Crítica (9.8) | 1.6% | — | Testlink | 26/9/2017 | 17/6/2026 | SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php. | |
| Modificada | Media (5) | 2.6% | — | Testlink | 31/10/2014 | 17/6/2026 | lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via unspecified vectors, which reveals the installation path in an error message. |