Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 13 respecto a la semana anterior
Críticas / altas1452▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.7) | 0.17% | — | Geeeeeeeek Dingfanzu | 8/9/2025 | 17/6/2026 | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addShop | |
| Analizada | Crítica (9.8) | 0.64% | — | Geeeeeeeek Dingfanzu | 15/4/2025 | 17/6/2026 | A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter. | |
| Aplazada | Media (5.3) | 0.31% | — | Dingfanzu CMSAI | 21/2/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in dingfanzu CMS up to 20250210. Affected is an unknown function of the file /ajax/loadShopInfo.php. The manipulation of the argument shopId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Alta (7.1) | 0.20% | — | DingfanzucmsAI | 15/1/2025 | 17/6/2026 | SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering the content correctly at the "checkOrder.php" shopId module. | |
| Analizada | Crítica (9.3) | 0.26% | — | Timgreen Dingfanzu CMS | 8/11/2024 | 17/6/2026 | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addAdmin. | |
| Analizada | Media (6.3) | 0.18% | — | Timgreen Dingfanzu CMS | 28/10/2024 | 17/6/2026 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17 | |
| Analizada | Media (6.3) | 0.18% | — | Timgreen Dingfanzu CMS | 28/10/2024 | 17/6/2026 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=17 | |
| Analizada | Media (6.1) | 0.28% | — | Timgreen Dingfanzu CMS | 16/10/2024 | 17/6/2026 | dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component doAdminAction.php which allows a remote attacker to execute arbitrary code | |
| Aplazada | Media (5.3) | 0.32% | — | Dingfanzu CMSAI | 27/9/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected by this issue is some unknown functionality of the file saveNewPwd.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (4.7) | 0.21% | — | Timgreen Dingfanzu CMS | 25/9/2024 | 17/6/2026 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31 | |
| Analizada | Media (6.3) | 0.19% | — | Timgreen Dingfanzu CMS | 25/9/2024 | 17/6/2026 | dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate | |
| Analizada | Media (5.3) | 0.49% | — | Gitapp Dingfanzu | 22/9/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected is an unknown function of the file scripts/order.js of the component Order Checkout. The manipulation of the argument address-name leads to cross site scripting. It is possible to launch the… | |
| Aplazada | Media (5.3) | 0.40% | — | Dingfanzu CMSAI | 29/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. This affects an unknown part of the file /ajax/getBasicInfo.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.75% | — | Geeeeeeeek Dingfanzu | 29/8/2024 | 17/6/2026 | A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ajax/chpwd.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit… | |
| Analizada | Media (6.9) | 0.76% | — | Gitapp Dingfanzu | 29/8/2024 | 17/6/2026 | A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax/checkin.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely.… |