Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (1.1)0.34%—Wikimedia WikiforumAI30/9/202630/9/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki WikiForum extension allows Stored XSS. This issue affects MediaWiki WikiForum extension: master.
AplazadaAlta (7.5)0.31%—Gvectors Wpforo ForumAI24/9/202624/9/2026
The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a PHP Object. No POP chain is present in the wpForo Forum WordPress plugin before…
AplazadaBaja (2.1)0.34%—Weiqingwen Spring-boot-forumAI23/9/202629/9/2026
A security vulnerability has been detected in weiqingwen spring-boot-forum up to 538eecc3c6b85fdf0768ab4e8354b48c0c17d94f. Affected is the function validate of the file src/main/java/com/qingwenwei/util/NewUserFormValidator.java of the component Avatar Upload. The manipulation of the argument Username leads to path…
AplazadaMedia (6.5)0.22%—Gvectors Wpforo ForumAI23/9/202623/9/2026
Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.
Pendiente de análisisAlta (8.6)0.36%—Simplemachines ForumAI26/8/202624/9/2026
Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter. Attackers can exploit the mismatch between…
AplazadaMedia (5.4)0.23%—Elkarte ForumAI11/8/20263/9/2026
A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persistent JavaScript into the profile fields cust_blurb and cust_locate. The fields are saved without HTML encoding and rendered unescaped in profile views visible to administrators. An attacker can craft a…
AplazadaMedia (5.4)0.29%—Gvectors Wpforo ForumAI31/7/202626/8/2026
The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing users with a subscriber-level account to permanently delete the stored AI chat message history of any other user.
AplazadaMedia (6.3)0.44%—Simplemachines ForumAI14/7/202615/7/2026
Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery vulnerability in the image proxy that allows authenticated attackers to trigger internal HTTP requests by embedding attacker-controlled URLs in BBCode image tags, which the proxy fetches without…
AplazadaMedia (6.5)0.22%—Hitesh Chandwani Recaptcha FOR Asgaros ForumAIGoogle RecaptchaAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 &amp; v3) for Asgaros Forum recaptcha-for-asgaros-forum allows DOM-Based XSS.This issue affects reCAPTCHA (v2 &amp; v3) for Asgaros Forum: from n/a through <= 1.1.0.
AplazadaAlta (7.1)0.47%—Simplemachines ForumAI10/7/202614/7/2026
Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulnerability in Sources/Actions/AttachmentApprove.php where a single-character operator error causes the permission check to always pass regardless of user permissions. An authenticated low-privileged…
AplazadaCrítica (9.3)0.40%—Gvectors Wpforo ForumAI15/6/202617/6/2026
Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.
AplazadaCrítica (9.1)0.44%—Gvectors Wpforo ForumAI1/6/202622/7/2026
Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6.
AplazadaMedia (5.1)0.21%—WikidforumAI29/5/202621/7/2026
Wikidforum 2.20 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted HTML in the reply_text parameter. Attackers can post comments containing JavaScript code through the rpc.php endpoint that executes in other users' browsers when viewing…
AplazadaAlta (7.3)0.35%—Yetanotherforum Yaf.netAI12/5/202617/6/2026
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and later rendered back into the thread page without adequate HTML sanitization or contextual output encoding. This…
AplazadaAlta (8.1)0.38%—Yetanotherforum.netAI12/5/202617/6/2026
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header into a JObject, serializes it with JsonConvert, and stores the result in the EventLog.Description column whenever an event…
AplazadaAlta (8.8)0.64%—Yetanotherforum Yaf.netAI12/5/202617/6/2026
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to a 302 to /Info/4. The most impactful abuse is /Admin/RunSql, whose OnPostRunQuery binds Editor from the POST body and passes it straight to…
AplazadaMedia (5.1)0.20%—Carbon ForumAI22/4/202617/6/2026
Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript code through the Forum Name field in dashboard settings. Attackers with admin privileges can store JavaScript payloads in the Forum Name field that execute in the browsers…
AplazadaMedia (5.5)0.41%—Code-projects Simple IT Discussion ForumAI10/4/202617/6/2026
A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. This affects an unknown function of the file /add-category-function.php. Such manipulation of the argument Category leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
AplazadaMedia (5.5)0.41%—Code-projects Simple IT Discussion ForumAI10/4/202617/6/2026
A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /delete-category.php. Performing a manipulation of the argument cat_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
AplazadaBaja (1.9)0.35%—Code-projects Simple IT Discussion ForumAI10/4/202617/6/2026
A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /admin/user.php. Such manipulation of the argument fname leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and…
AplazadaMedia (5.5)0.41%—Code-projects Simple IT Discussion ForumAI9/4/202617/6/2026
A security flaw has been discovered in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /crud.php. The manipulation of the argument user_Id results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used…
AplazadaMedia (5.5)0.41%—Code-projects Simple IT Discussion ForumAI9/4/202617/6/2026
A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This vulnerability affects unknown code of the file /topic-details.php. The manipulation of the argument post_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be…
AplazadaMedia (5.5)0.41%—Code-projects Simple IT Discussion ForumAI9/4/202624/7/2026
A vulnerability was determined in code-projects Simple IT Discussion Forum 1.0. The impacted element is an unknown function of the file /pages/content.php. This manipulation of the argument post_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be…
AplazadaMedia (5.5)0.41%—Code-projects Simple IT Discussion ForumAI9/4/202624/7/2026
A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
AplazadaMedia (5.5)0.41%—Code-projects Simple IT Discussion ForumAI9/4/202624/7/2026
A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the file /question-function.php. The manipulation of the argument content leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.