« Volver al listado

Uxper

Uxper Golo: vulnerabilidades y CVE

Uxper Golo tiene 9 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses5
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-28150Alta (8.1)0.47%—20 ago 2026
Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.
CVE-2026-27051Crítica (9.8)0.48%—25 mar 2026
Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0.
CVE-2026-23973Alta (7.1)0.18%—25 mar 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo allows Reflected XSS.This issue affects Golo: from n/a through < 1.7.5.
CVE-2026-23975Alta (7.5)0.45%—22 ene 2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo golo allows PHP Local File Inclusion.This issue affects Golo: from n/a through < 1.7.5.
CVE-2026-23974Media (5.3)0.24%—22 ene 2026
Missing Authorization vulnerability in uxper Golo golo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Golo: from n/a through < 1.7.5.
CVE-2025-54725Crítica (9.8)0.42%—28 ago 2025
Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.This issue affects Golo: from n/a through <= 1.7.0.
CVE-2025-54724Alta (7.1)0.18%—28 ago 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo allows Reflected XSS.This issue affects Golo: from n/a through <= 1.7.1.
CVE-2024-12876Crítica (9.8)0.45%—7 mar 2025
The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.10. This is due to the plugin not properly validating…
CVE-2020-23790Crítica (9.8)1.5%—12 may 2021
An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1005 Data from Local System2
  3. T1059.007 JavaScript2
  4. T1078 Valid Accounts2
  5. T1189 Drive-by Compromise2
  6. T1068 Exploitation for Privilege Escalation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Uxper