Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.40% | — | Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, GetSimpleCMS-CE is vulnerable to stored Cross-Site Scripting (XSS) in the "Theme to Components" functionality (admin/components.php) via the title parameter. The stored title is… | |
| Aplazada | Alta (7.1) | 0.34% | — | Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated user with page-editing rights can store an arbitrary filesystem path in a page's template attribute. On the public front-end, this value is passed unsanitized to… | |
| Aplazada | Alta (8.8) | 0.26% | — | Getsimplecms Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In versions 3.3.22 and prior, an authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the page backup viewer (admin/backup-edit.php). Page fields are correctly HTML-encoded when a page is… | |
| Aplazada | Crítica (9.6) | 0.22% | — | Getsimplecms Getsimple CMS CEAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a… | |
| Aplazada | Alta (7.5) | 0.26% | — | Getsimplecms Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALIDATE_URL) — there is no validation of the request destination. An… | |
| Aplazada | Crítica (9.1) | 0.53% | — | Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written… | |
| Aplazada | Crítica (9.1) | 0.34% | — | Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and… | |
| Aplazada | Crítica (9.8) | 0.55% | — | Getsimple CMSAIGetsimple CMS CEAI | 11/9/2026 | 30/9/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security… | |
| Analizada | Alta (8.8) | 0.32% | — | Getsimple-ce Getsimple CMS | 10/3/2026 | 17/6/2026 | GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite the gsconfig.php configuration file with arbitrary PHP code via the gsconfig editor module. The form lacks CSRF protection, enabling a remote… | |
| Modificada | Media (4.8) | 0.39% | — | Getsimple-ce Getsimple CMS | 24/2/2026 | 14/7/2026 | GetSimpleCMS Community Edition (CE) versions prior to 3.3.22 (3.3.16 tested) contains a stored cross-site scripting (XSS) vulnerability in the Theme to Components functionality within components.php. User-supplied input provided to the "slug" field of a component is stored without proper output encoding. While other… | |
| Analizada | Alta (8.8) | 0.54% | — | Getsimple-ce Getsimple CMS | 21/2/2026 | 17/6/2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time of publication. | |
| Analizada | Alta (8.7) | 0.47% | — | Getsimple-ce Getsimple CMS | 21/2/2026 | 17/6/2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess files to restrict access to sensitive directories such as /data/ and /backups/. If Apache AllowOverride is disabled (common in hardened or shared hosting environments), these protections are silently ignored, allowing… | |
| Analizada | Media (6.9) | 0.25% | — | Getsimple-ce Getsimple CMS | 21/2/2026 | 17/6/2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS are vulnerable to XSS through SVG file uploads. Authenticated users can upload SVG files via the administrative upload functionality, but they are not properly sanitized or restricted, allowing an attacker to embed malicious JavaScript. When… | |
| Analizada | Alta (7.1) | 0.17% | — | Getsimple-ce Getsimple CMS | 21/2/2026 | 17/6/2026 | GetSimple CMS is a content management system. All versions of GetSimple CMS do not implement CSRF protection on the administrative file upload endpoint. As a result, an attacker can craft a malicious web page that silently triggers a file upload request from an authenticated victim’s browser. The request is accepted… | |
| Analizada | Media (5.1) | 0.33% | — | Simplephpscripts Simple CMS PHP | 1/2/2026 | 17/6/2026 | Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request to execute arbitrary scripts and potentially hijack user sessions or perform phishing attacks. | |
| Analizada | Alta (8.6) | 0.57% | — | Simplephpscripts Simple CMS PHP | 1/2/2026 | 17/6/2026 | Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. Attackers can exploit unvalidated input parameters in the admin.php file to compromise the database management system and web application. | |
| Analizada | Media (5.1) | 0.33% | — | Simplephpscripts Simple CMS PHP | 1/2/2026 | 17/6/2026 | Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote attackers to inject malicious script code. Attackers can exploit the newUser and editUser modules to inject persistent scripts that execute on user list preview, potentially leading to session hijacking… | |
| Modificada | Media (5.1) | 0.28% | — | Phpjabbers Simple CMS | 17/12/2025 | 17/6/2026 | PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Attackers can create sections with embedded JavaScript payloads that will execute when administrators view the sections, potentially enabling… | |
| Analizada | Alta (8.7) | 0.61% | — | Phpjabbers Simple CMS | 17/12/2025 | 17/6/2026 | PHPJabbers Simple CMS 5.0 contains a SQL injection vulnerability in the 'column' parameter that allows remote attackers to manipulate database queries. Attackers can inject crafted SQL payloads through the 'column' parameter in the index.php endpoint to potentially extract or modify database information. | |
| Analizada | Alta (8.6) | 0.91% | — | Getsimple-ce Getsimple CMS | 30/5/2025 | 17/6/2026 | GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject arbitrary PHP into a component file and execute it via a crafted query string, resulting in Remote Code Execution (RCE). This issue is set to be patched in… | |
| Analizada | Alta (8.8) | 0.25% | — | Getsimple-ce Getsimple CMS | 18/12/2024 | 17/6/2026 | GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module. | |
| Analizada | Alta (7.2) | 0.41% | — | Getsimple-ce Getsimple CMS | 18/12/2024 | 17/6/2026 | In the GetSimple CMS CE 3.3.19 management page, Server-Side Request Forgery (SSRF) can be achieved in the plug-in download address in the backend management system. | |
| Analizada | Crítica (9.8) | 0.86% | — | Getsimple-ce Getsimple CMS | 16/12/2024 | 17/6/2026 | GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an attacker to implement RCE. | |
| Analizada | Media (5.9) | 1.2% | — | Codelyfe Stupid Simple CMS | 2/4/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in codelyfe Stupid Simple CMS 1.2.4. This issue affects some unknown processing of the component Login Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The complexity of… | |
| Analizada | Alta (8.8) | 0.32% | — | Codelyfe Stupid Simple CMS | 1/3/2024 | 17/6/2026 | Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php. |