Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.42%—ShopxoAIBaidu UeditorAI24/9/202624/9/2026
A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the component Ueditor Upload Interface. The manipulation of the argument path_type results in path traversal. It is possible to launch the attack remotely. The…
AplazadaMedia (5.5)0.53%—Baidu UeditorAIFeehicmsAI7/9/202628/9/2026
A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit is…
AplazadaMedia (5.5)0.50%—Light0011 CMSAIUeditorAI4/9/20264/9/2026
A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects the function catchimage of the file Public/ueditor/php/controller.php of the component UEditor. This manipulation of the argument source[] causes server-side…
AnalizadaAlta (7.3)0.39%—Ueditor Project Ueditor23/4/20251/10/2026
Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*.
AplazadaCrítica (9.8)0.97%—ProductinfoquickAIUeditorAI12/8/202417/6/2026
An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
AnalizadaMedia (5.3)0.45%—Baidu Ueditor1/8/202417/6/2026
A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor142/php/controller.php?action=catchimage. The manipulation of the argument source[] leads to cross site scripting. The attack can be initiated remotely. The exploit has…
AnalizadaMedia (5.3)0.45%—Baidu Ueditor1/8/202417/6/2026
A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The…
ModificadaMedia (5.4)0.56%—Baidu Ueditor28/9/202117/6/2026
Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information.
ModificadaMedia (6.1)0.64%—Baidu Ueditor26/9/201717/6/2026
UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element.
ModificadaMedia (4.3)1.1%—Ufku Bayburt Bueditor24/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in the BUEditor module 5.x before 5.x-1.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via input to the "plain textarea editor."
ModificadaMedia (4.3)0.53%—Drupal Bueditor15/1/200816/6/2026
The editor deletion form in BUEditor 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.1, a module for Drupal, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete custom editor interfaces.