Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.58% | — | Vanillaforums Vanilla Forums | 22/6/2021 | 16/6/2026 | It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher. | |
| Modificada | Media (6.1) | 0.66% | — | Vanillaforums Vanilla Forums | 22/6/2021 | 16/6/2026 | It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side. | |
| Modificada | Media (5.4) | 0.81% | — | Vanillaforums Vanilla Forums | 2/3/2019 | 17/6/2026 | Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum. | |
| Modificada | Media (4.3) | 0.88% | — | Vanillaforums Vanilla Forums | 26/8/2018 | 17/6/2026 | In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of a single user to select multiple Poll Options (e.g., vote for multiple items). | |
| Modificada | Alta (8) | 1.6% | — | Vanillaforums Vanilla Forums | 2/1/2018 | 17/6/2026 | Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access | |
| Modificada | Media (4.3) | 1.8% | — | Vanillaforums VanillaVanillaforums Vanilla Forums | 25/2/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.5) | 1.1% | — | Vanillaforums VanillaVanillaforums Vanilla Forums | 15/11/2012 | 16/6/2026 | The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue. |