Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2770▲ 14 respecto a la semana anterior
Críticas / altas1475▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.38% | — | Grav Flex ObjectsAI | 25/8/2026 | 31/8/2026 | Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in published pages to expose sensitive… | |
| Aplazada | Media (6.3) | 0.33% | — | Getgrav Flex ObjectsAI | 19/8/2026 | 9/9/2026 | Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Objects Admin Next API requireFlexPermission() method in classes/Api/FlexApiController.php returns without denying access when a directory blueprint omits config.admin.permissions. An authenticated account with… | |
| Aplazada | Alta (8.7) | 0.56% | — | Getgrav Flex ObjectsAIGetgrav GravAI | 14/8/2026 | 31/8/2026 | The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiController::update() checks only the general Flex directory permission and does not apply the additional target/field/super-admin checks enforced by the dedicated Users and… | |
| Aplazada | Alta (8.7) | 0.90% | — | Getgrav GravAIGetgrav Flex ObjectsAI | 14/8/2026 | 8/9/2026 | Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can bypass routine name validation by using array notation instead of string notation,… | |
| Aplazada | Baja (2.3) | 0.29% | — | Getgrav GravAIGetgrav Flex-objectsAI | 17/7/2026 | 17/7/2026 | Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to perform unauthorized CRUD operations on permission-less directories. Attackers with api.access credentials can create, read, update,… | |
| Aplazada | Alta (8.7) | 1.1% | — | Getgrav Grav-plugin-flex-objectsAIGetgrav GravAI | 15/7/2026 | 15/7/2026 | The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. When rendering dynamic collection or object titles, the plugin passes user-controlled frontmatter values (page.header.flex.collection.title or… |