Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
401.075 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.37% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. Attackers can send requests to endpoints like api/ci/update_config and api/archives to overwrite configuration and list,… | |
| Aplazada | Media (5.1) | 0.17% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in formatters/wakka.php that allows users who can edit pages or post comments to inject event handlers by placing quotes in markdown image URLs. Attackers can store a crafted markdown image whose src breaks out of the attribute to add an onerror… | |
| Aplazada | Media (5.1) | 0.17% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the field parameter of the mail handler. Attackers can craft links whose field value breaks out of the ajax-mail-form action attribute to execute JavaScript in victims' browsers. | |
| Aplazada | Alta (8.8) | 0.29% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to the Bazar abonnements sync action. Attackers can target internal hosts or cloud metadata endpoints and chain attacker-controlled… | |
| Aplazada | Alta (8.3) | 0.25% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending signed Follow activities to the public forms actor inbox route. Attackers sign requests with their own keyId while supplying internal actor URLs in the body, reaching… | |
| Aplazada | Alta (8.8) | 0.31% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. Attackers with page-write access (unauthenticated on default installs) can embed a nuagetag tag ending in a backslash to break quote parity and inject a… | |
| Aplazada | Media (5.1) | 0.17% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file extension and never calls HtmlPurifierService::cleanFile, so SVG files are stored verbatim and served inline as image/svg+xml. Authenticated users can submit entries via POST… | |
| Aplazada | Alta (8.7) | 0.39% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into SQL REGEXP/LIKE clauses in actions/newtextsearch.php without escaping. Anonymous attackers can plant a malicious option id in an anonymously editable Bazar list and use… | |
| Aplazada | Media (6.9) | 0.39% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a server-side request forgery vulnerability in WebfingerService that allows unauthenticated attackers to trigger HTTPS requests to internal hosts. Attackers can POST a crafted actor_handle with a numeric host and port to the abonnements view to probe internal HTTPS services and ports. | |
| Aplazada | Alta (8.3) | 0.32% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a server-side request forgery vulnerability in validateKeyIdUrl() that allows unauthenticated attackers to bypass the SSRF guard using 6to4, NAT64, or IPv4-compatible IPv6 addresses. Attackers can send a crafted Signature keyId to the public actor inbox route to reach cloud metadata,… | |
| Aplazada | Alta (8.8) | 0.28% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into a raw tags.value IN (...) clause. Unauthenticated attackers on default installs can save filtertags markup in a page with a trailing-backslash… | |
| Aplazada | Alta (7.2) | 0.30% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclService::updateRequestWithACL, where a stored username is concatenated unescaped into a read-ACL LIKE clause. Attackers can self-register an account name containing a double-quote payload, then load non-admin ACL-filtered listings to read… | |
| Aplazada | Media (6.9) | 0.37% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to read restricted page content via the recentchangesrssplus RSS action. Attackers can request the xml method of a page hosting the action to retrieve 500-character body excerpts of every latest page, including… | |
| Aplazada | Media (6.9) | 0.40% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php formatter due to an O(n^2) markdown-link regex. Unauthenticated attackers can submit a small crafted body of bracket characters to the page-edit preview endpoint to pin PHP-FPM workers and saturate the pool. | |
| Aplazada | Media (5.3) | 0.11% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the admintag action that allows attackers to delete tag associations by luring administrators to crafted GET links. Attackers can supply a wide id range in the delete_tag parameter via top-level navigation, carrying the SameSite=Lax admin… | |
| Aplazada | Media (5.3) | 0.11% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the filemanager page handler, which deletes page attachments on GET requests without validating a CSRF token. Attackers can lure a logged-in page owner or administrator into a top-level GET navigation with do=del, erase, or emptytrash,… | |
| Aplazada | Media (5.3) | 0.13% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attackers to restore old page revisions through GET requests lacking CSRF token validation. Attackers can lure write-capable users into a top-level navigation with the restoreRevisionId parameter, silently… | |
| Aplazada | Alta (8.2) | 0.27% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a missing authorization flaw in the pointimage action (tools/attach/actions/pointimage.php), which saves content to an attacker-chosen page with write ACL checks bypassed. Unauthenticated attackers can POST pagetag, title, and description fields to any page rendering {{pointimage}} to… | |
| Aplazada | Alta (8.3) | 0.28% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via the Bazar entry-creation flow. Attackers can submit a crafted entry with an attacker-controlled id_fiche matching an existing… | |
| Aplazada | Alta (7.2) | 0.16% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET request carrying a jsonp_callback parameter without checking a CSRF token. Attackers can lure a logged-in administrator or page owner to a crafted link to delete arbitrary… | |
| Aplazada | Alta (7.1) | 0.13% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete installed packages via unprotected GET requests. Attackers can lure a logged-in administrator to a crafted link with action=delete and a package parameter to remove extensions like… | |
| Aplazada | Media (6.9) | 0.43% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through the wiki's SMTP server. Attackers can POST an XMLHttpRequest to the mail handler without field or type parameters, supplying arbitrary recipient, sender, subject and body… | |
| Aplazada | Alta (8.8) | 0.40% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to… | |
| Aplazada | Alta (7.1) | 0.27% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a… | |
| Aplazada | Alta (7.2) | 0.36% | — | YeswikiAI | 2/10/2026 | 2/10/2026 | YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the… |