Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.42% | — | ShopxoAIBaidu UeditorAI | 24/9/2026 | 24/9/2026 | A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the component Ueditor Upload Interface. The manipulation of the argument path_type results in path traversal. It is possible to launch the attack remotely. The… | |
| Aplazada | Media (5.5) | 0.53% | — | Baidu UeditorAIFeehicmsAI | 7/9/2026 | 28/9/2026 | A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit is… | |
| Aplazada | Media (5.5) | 0.50% | — | Light0011 CMSAIUeditorAI | 4/9/2026 | 4/9/2026 | A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects the function catchimage of the file Public/ueditor/php/controller.php of the component UEditor. This manipulation of the argument source[] causes server-side… | |
| Analizada | Alta (7.3) | 0.39% | — | Ueditor Project Ueditor | 23/4/2025 | 1/10/2026 | Vulnerability in Drupal UEditor - 百度编辑器.This issue affects UEditor - 百度编辑器: *.*. | |
| Aplazada | Crítica (9.8) | 0.97% | — | ProductinfoquickAIUeditorAI | 12/8/2024 | 17/6/2026 | An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploading a crafted PNG file. | |
| Analizada | Media (5.3) | 0.45% | — | Baidu Ueditor | 1/8/2024 | 17/6/2026 | A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor142/php/controller.php?action=catchimage. The manipulation of the argument source[] leads to cross site scripting. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.45% | — | Baidu Ueditor | 1/8/2024 | 17/6/2026 | A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Modificada | Media (5.4) | 0.56% | — | Baidu Ueditor | 28/9/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information. | |
| Modificada | Media (6.1) | 0.64% | — | Baidu Ueditor | 26/9/2017 | 17/6/2026 | UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element. | |
| Modificada | Media (4.3) | 1.1% | — | Ufku Bayburt Bueditor | 24/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the BUEditor module 5.x before 5.x-1.2 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via input to the "plain textarea editor." | |
| Modificada | Media (4.3) | 0.53% | — | Drupal Bueditor | 15/1/2008 | 16/6/2026 | The editor deletion form in BUEditor 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.1, a module for Drupal, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete custom editor interfaces. |