Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.24% | — | Typo3 FemanagerAI | 14/9/2026 | 22/9/2026 | An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system. | |
| Aplazada | Media (5.4) | 0.42% | — | Typo3 FemanagerAI | 14/9/2026 | 22/9/2026 | An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts. | |
| Aplazada | Media (4.2) | 0.14% | — | Typo3AIIn2code FemanagerAI | 14/9/2026 | 22/9/2026 | The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component. | |
| Aplazada | Media (5.3) | 0.28% | — | Typo3AIIn2code FemanagerAI | 21/5/2025 | 17/6/2026 | The femanager extension through 8.2.1 for TYPO3 allows Insecure Direct Object Reference. | |
| Modificada | Media (5.3) | 0.60% | — | In2code Femanager | 12/12/2023 | 17/6/2026 | The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users in restricted groups (if there is a usergroup field on the registration form). This occurs because the usergroup.inList protection mechanism is mishandled. | |
| Modificada | Alta (7.5) | 0.50% | — | In2code Femanager | 2/2/2023 | 17/6/2026 | An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to delete all frontend users. | |
| Modificada | Alta (7.5) | 0.50% | — | In2code Femanager | 2/2/2023 | 17/6/2026 | An issue was discovered in the femanager extension before 5.5.3, 6.x before 6.3.4, and 7.x before 7.1.0 for TYPO3. Missing access checks in the InvitationController allow an unauthenticated user to set the password of all frontend users. | |
| Modificada | Media (5.4) | 1.3% | — | In2code Femanager | 13/8/2021 | 17/6/2026 | The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document. | |
| Modificada | Media (6.4) | 1.3% | — | In2code Femanager | 3/10/2014 | 17/6/2026 | The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspecified vectors. |