Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.70% | — | Mura CMSAI | 13/7/2026 | 13/7/2026 | Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/_api/json/v1/default”, where the “method” parameter in POST requests is not properly validated or sanitised before being processed by the ColdFusion engine. As a result,… | |
| Analizada | Crítica (9.8) | 0.32% | — | Murasoftware Mura CMS | 18/3/2026 | 17/6/2026 | Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection. | |
| Analizada | Crítica (9.8) | 0.26% | — | Murasoftware Mura CMS | 18/3/2026 | 17/6/2026 | Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection. | |
| Analizada | Alta (8.1) | 0.12% | — | Murasoftware Mura CMS | 18/3/2026 | 17/6/2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system through a simple CSRF attack. The vulnerable cTrash.empty function lacks CSRF token validation, enabling malicious websites to forge requests that irreversibly delete all… | |
| Analizada | Alta (7.1) | 0.11% | — | Murasoftware Mura CMS | 18/3/2026 | 17/6/2026 | The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable cUsers.updateAddress function lacks CSRF token validation, enabling malicious websites to forge requests that add, modify, or delete user addresses when an authenticated… | |
| Analizada | Alta (8.8) | 0.13% | — | Murasoftware Mura CMS | 18/3/2026 | 17/6/2026 | The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations through CSRF. The vulnerable cTrash.restore function lacks CSRF token validation, enabling malicious websites to forge requests that restore content to arbitrary parent… | |
| Analizada | Media (6.5) | 0.16% | — | Murasoftware Mura CMS | 18/3/2026 | 17/6/2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows unauthenticated attackers to force administrators to create and save site bundles containing sensitive data to publicly accessible directories. This vulnerability enables complete… | |
| Analizada | Alta (8) | 0.13% | — | Murasoftware Mura CMS | 18/3/2026 | 17/6/2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allows attackers to escalate privileges by adding any user to any group without proper authorization checks. The vulnerable function lacks CSRF token validation and directly… | |
| Analizada | Alta (8.8) | 0.16% | — | Murasoftware Mura CMS | 18/3/2026 | 17/6/2026 | The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importform function lacks CSRF token validation, enabling malicious websites to forge file upload requests that install attacker-controlled forms… | |
| Modificada | Crítica (9.8) | 3.6% | — | Murasoftware Mura CMS | 1/2/2023 | 9/7/2026 | A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request. | |
| Modificada | Media (6.5) | 6.8% | — | Getmura Mura CMS | 19/10/2017 | 17/6/2026 | tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature. | |
| Modificada | Media (5) | 6.7% | — | Blueriver Sava CMSBlueriver Mura CMS | 29/9/2010 | 16/6/2026 | Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 through 5.2, allows remote attackers to read arbitrary files via a .. (dot dot) in the FILEID parameter to the default URI under tasks/render/file/. |