Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.63% | — | TinymceAIWebkul UnopimAI | 2/9/2026 | 28/9/2026 | UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due to missing file extension and MIME type validation. Attackers can upload a PHP web shell to the public storage disk and execute… | |
| Aplazada | Media (5.1) | 0.30% | — | TinymceAIFit2cloud SqlbotAI | 10/8/2026 | 23/9/2026 | SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can modify dashboard text widget content can inject arbitrary HTML and JavaScript that executes for all users… | |
| Aplazada | Media (4.3) | 0.29% | — | TinymceAI | 23/7/2026 | 23/7/2026 | Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions. | |
| Aplazada | Media (6.4) | 0.23% | — | Tinymce Shortcode AddonAI | 9/6/2026 | 23/7/2026 | The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Attribute in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Analizada | Media (5.4) | 0.42% | — | Tinymce | 28/5/2026 | 17/6/2026 | TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via forged mce:protected comments. Allows attackers to bypass sanitization and inject scripts that execute when content is restored. Impacts users who utilize the protect option. This vulnerability is… | |
| Analizada | Media (5.4) | 0.41% | — | Tinymce | 28/5/2026 | 17/6/2026 | TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in the media plugin. Attackers can inject malicious scripts via crafted data-mce-* attributes, which are executed when content is rendered. Impacts users of TinyMCE with the media plugin enabled. This… | |
| Analizada | Media (5.4) | 0.27% | — | Tinymce | 28/5/2026 | 17/6/2026 | TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by improper SVG namespace scope handling in the sanitizer. A crafted payload using nested elements can bypass attribute sanitization and execute arbitrary JavaScript. This vulnerability is fixed in… | |
| Analizada | Media (5.4) | 0.42% | — | Tinymce | 28/5/2026 | 17/6/2026 | TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via unsanitized data-mce-* attributes (data-mce-href, data-mce-src, data-mce-style). Allows attackers to inject malicious values that override safe attributes during serialization, bypassing validation.… | |
| Aplazada | Media (4.3) | 0.13% | — | Justcoded Just Tinymce Custom StylesAI | 9/12/2025 | 30/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Alex Prokopenko / JustCoded Just TinyMCE Custom Styles just-tinymce-styles allows Cross Site Request Forgery.This issue affects Just TinyMCE Custom Styles: from n/a through <= 1.2.1. | |
| Analizada | Media (6.1) | 0.26% | — | Sfarbota Download Html Tinymce Button | 15/5/2025 | 17/6/2026 | The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Alta (7.1) | 0.30% | — | Willshouse Tinymce-extended-configAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willshouse TinyMCE Extended Config tinymce-extended-config allows Reflected XSS.This issue affects TinyMCE Extended Config: from n/a through <= 0.1.0. | |
| Aplazada | Media (5.4) | 0.22% | — | TinymceAIMovabletype Movable TypeAI | 19/2/2025 | 17/6/2026 | Movable Type contains a stored cross-site scripting vulnerability in the HTML edit mode of MT Block Editor. It is exploitable when TinyMCE6 is used as a rich text editor and an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Alta (7.1) | 0.15% | — | Blackbam Tinymce Advanced Qtranslate FIX Editor ProblemsAI | 13/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Blackbam TinyMCE Advanced qTranslate fix editor problems tinymce-advanced-qtranslate-fix-editor-problems allows Stored XSS.This issue affects TinyMCE Advanced qTranslate fix editor problems: from n/a through <= 1.0.0. | |
| Analizada | Media (5.4) | 0.26% | — | Joshlobe Ultimate Tinymce | 30/10/2024 | 17/6/2026 | The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all versions up to, and including, 5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (6.1) | 0.53% | — | TinymceAI | 19/6/2024 | 17/6/2026 | TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content parsing code. This allowed specially crafted noscript elements containing malicious code to be executed when that content was loaded into the editor. This vulnerability has been patched in TinyMCE… | |
| Aplazada | Media (6.1) | 0.53% | — | TinymceAI | 19/6/2024 | 17/6/2026 | TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content extraction code. When using the `noneditable_regexp` option, specially crafted HTML attributes containing malicious code were able to be executed when content was extracted from the editor. This… | |
| Analizada | Media (6.1) | 0.71% | — | Tinymce | 26/3/2024 | 17/6/2026 | TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG image could be loaded though an `object` or `embed` element and that image could potentially contain a XSS payload. This vulnerability is fixed in 6.8.1… | |
| Analizada | Media (6.1) | 0.71% | — | Tinymce | 26/3/2024 | 17/6/2026 | TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed `iframe` elements containing malicious code to execute when inserted into the editor. These `iframe` elements are restricted in their permissions by same-origin… | |
| Modificada | Alta (8.8) | 0.21% | — | Blackbam Tinymce AND Tinymce Advanced Professsional Formats AND Styles | 21/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in David Stockl TinyMCE and TinyMCE Advanced Professsional Formats and Styles.This issue affects TinyMCE and TinyMCE Advanced Professsional Formats and Styles: from n/a through 1.1.2. | |
| Modificada | Media (6.1) | 1.2% | — | Tinymce | 3/1/2024 | 14/7/2026 | TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser. | |
| Modificada | Media (6.1) | 0.96% | — | Tinymce | 3/1/2024 | 14/7/2026 | TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser. | |
| Modificada | Media (6.1) | 1.1% | — | Tinymce | 3/1/2024 | 14/7/2026 | TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser. | |
| Modificada | Media (6.1) | 0.71% | — | Tinymce | 15/11/2023 | 17/6/2026 | TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo/redo functionality and other APIs and plugins. Text nodes within specific parents are not escaped upon serialization according to the HTML standard. If such text nodes contain a… | |
| Modificada | Media (6.1) | 0.60% | — | Tinymce | 19/10/2023 | 17/6/2026 | TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s Notification Manager API. The vulnerability exploits TinyMCE's unfiltered notification system, which is used in error handling. The conditions for this exploit requires carefully crafted malicious content… | |
| Modificada | Media (6.1) | 0.62% | — | Tinymce | 19/10/2023 | 17/6/2026 | TinyMCE is an open source rich text editor. A mutation cross-site scripting (mXSS) vulnerability was discovered in TinyMCE’s core undo and redo functionality. When a carefully-crafted HTML snippet passes the XSS sanitisation layer, it is manipulated as a string by internal trimming functions before being stored in the… |