Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
202 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.45% | — | YIIAICraftcms Craft CMSAI | 27/8/2026 | 28/8/2026 | The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities. | |
| Aplazada | Alta (8.7) | 1.0% | — | Craftcms Craft CMSAI | 24/8/2026 | 28/8/2026 | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding,… | |
| Aplazada | Crítica (9.8) | 1.3% | — | Verbb FormieAICraftcms Craft CMSAI | 19/8/2026 | 10/9/2026 | Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Value to Craft's Twig rendering layer during front-end form rendering. An… | |
| Aplazada | Media (5.1) | 0.26% | — | Craftcms Craft CMSAI | 12/8/2026 | 31/8/2026 | Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that executes in the browser of any… | |
| Aplazada | Alta (7.1) | 0.46% | — | Craftcms Craft CMSAI | 12/8/2026 | 31/8/2026 | Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password including administrators by exploiting the unprotected newPassword… | |
| Aplazada | Crítica (9.3) | 0.27% | — | Craftcms Craft CMSAI | 11/8/2026 | 28/8/2026 | Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify that group's category structure — reordering and re-parenting categories — via the… | |
| Aplazada | Media (6.9) | 0.24% | — | Craftcms Craft CMSAI | 11/8/2026 | 8/9/2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<Volume>Asset mutation, which fetches an attacker-supplied URL server-side. The anti-SSRF validation is incomplete: validateIp() does not cover CGNAT (100.64.0.0/10) or… | |
| Aplazada | Media (6.9) | 0.20% | — | Craftcms Craft CMSAI | 11/8/2026 | 26/8/2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContained function of the Local file system class. The order of operations validates the path before normalization, so normalization could invalidate prior validation… | |
| Aplazada | Alta (7.1) | 0.39% | — | Craftcms Craft CMSAI | 11/8/2026 | 28/8/2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in the elementId parameter) into Twig templates before rendering, even when the Twig sandbox is enabled. An authenticated attacker with control panel access can render a… | |
| Aplazada | Alta (8.7) | 0.79% | — | Craftcms Craft CMSAI | 11/8/2026 | 8/9/2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft marks the ElementInterface as safe (via the AllowedInSandbox attribute) and the sandbox allowlisting extends to the entire class hierarchy… | |
| Aplazada | Alta (7.1) | 0.39% | — | Craftcms Craft CMSAI | 11/8/2026 | 28/8/2026 | Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create additional authenticated sessions for victim accounts. | |
| Aplazada | Alta (8.7) | 0.38% | — | Craftcms Craft CMSAI | 11/8/2026 | 8/9/2026 | Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entry blocklist that does not include SplFileObject, allowing an authenticated administrator (with allowAdminChanges=true) to configure a… | |
| Aplazada | Alta (8.7) | 0.80% | — | Craftcms Craft CMSAI | 11/8/2026 | 26/8/2026 | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses the outer request-controlled condition array via Component::cleanseConfig(), but… | |
| Aplazada | Media (5.3) | 0.39% | — | Craftcms Craft CMSAI | 6/7/2026 | 6/7/2026 | A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData of the file src/controllers/ChartsController.php of the component Charts Endpoint. This manipulation of the argument userGroupId causes improper authorization. The attack is possible to be carried… | |
| Aplazada | Media (5.3) | 0.39% | — | Craftcms Craft CMSAI | 6/7/2026 | 6/7/2026 | A vulnerability was detected in Craft CMS up to 4.18.0.1. Affected is the function actionReorderSets of the file src/controllers/GlobalsController.php of the component reorder-sets Endpoint. The manipulation results in authorization bypass. The attack can be executed remotely. Upgrading to version 4.18.1 is able to… | |
| Aplazada | Media (4.9) | 0.35% | — | Craftcms Craft CMSAI | 2/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a conflicting destination folder without destination delete permission. Function… | |
| Aplazada | Alta (8.7) | 0.41% | — | Craftcms Craft CMSAI | 2/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with the ability to edit entries can execute unsandboxed Twig code via the HTTP Referrer header, potentially leading to authenticated RCE. The issue happens when a user is saving entries. Strings for a… | |
| Aplazada | Media (6) | 0.40% | — | Craftcms Craft CMSAI | 2/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 and above, prior to 5.10.0, the dataUrl() Twig function is included in Craft’s Twig sandbox allowlist, allowing any control panel user granted the utility:system-messages permission to embed a… | |
| Aplazada | Media (6.9) | 0.46% | — | Craftcms Craft CMSAI | 2/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forgery (SSRF) and Arbitrary JavaScript Injection through the /actions/app/resource-js endpoint. By exploiting the default permissive… | |
| Aplazada | Media (6) | 0.40% | — | Craftcms Craft CMSAI | 2/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::actionMoveToSection() endpoint gates the destination section only by viewEntries:$section->uid rather than requiring saveEntries permission (the source entry is separately checked via… | |
| Aplazada | Alta (7.6) | 0.36% | — | Craftcms Craft CMSAI | 2/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). IN versions 5.0.0-RC1 and above prior to 5.9.21, theEntriesController::actionSaveEntry() performs entry-edit permission checks before request-controlled author changes are applied to the model, allowing for authorship spoofing. The subsequent author mutation path accepts… | |
| Aplazada | Alta (7.4) | 0.46% | — | Craftcms CMSAI | 1/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15, an attacker with only a GitHub account can plant a JavaScript payload in a craftcms/cms issue title. When a Craft admin uses the CraftSupport widget’s "Give feedback" screen and types a search term that… | |
| Aplazada | Media (5.3) | 0.36% | — | Craftcms Craft CMSAI | 1/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain an authorization issue in the AssetsController::actionReplaceFile that can delete a source asset without source delete permission by supplying both assetId and sourceAssetId.… | |
| Aplazada | Media (5.9) | 0.41% | — | Craftcms Craft CMSAI | 1/7/2026 | 2/7/2026 | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22, an author-level control panel user can store a malicious JavaScript payload in an entry title. When an admin, or any control panel user with saveEntries for the same Structure section, drags another entry under the poisoned entry in… | |
| Aplazada | Alta (7.1) | 0.49% | — | Craftcms Craft CMSAI | 21/6/2026 | 23/6/2026 | Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowing local file read… |