Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.24% | — | Squidex CMSAI | 29/6/2026 | 30/6/2026 | Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint | |
| Aplazada | Media (5.5) | 0.43% | — | Squidex.io SquidexAI | 22/4/2026 | 17/6/2026 | Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind Server-Side Request Forgery (SSRF). The application fails to validate the URI scheme of the user-supplied `Url` parameter, allowing the use of the `file://`… | |
| Aplazada | Alta (7.3) | 0.36% | — | Squidex.io SquidexAI | 22/4/2026 | 17/6/2026 | Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSRF vulnerability allows a user with asset upload permission to force the server to fetch arbitrary URLs, including localhost/private network targets, and persist the response as an asset. Version… | |
| Aplazada | Alta (7.3) | 0.36% | — | Squidex.io SquidexAI | 22/4/2026 | 17/6/2026 | Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a Server-Side Request Forgery (SSRF) vulnerability due to missing SSRF protection on the `Jint` HTTP client used by scripting engine functions (`getJSON`, `request`, etc.). An authenticated user with… | |
| Aplazada | Alta (7.2) | 0.40% | — | Squidex.io SquidexAI | 22/4/2026 | 17/6/2026 | Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `RestoreController.PostRestoreJob` endpoint allows an administrator to supply an arbitrary URL for downloading backup archives. This URL is fetched using the "Backup" `HttpClient` without any SSRF… | |
| Analizada | Alta (8.8) | 0.48% | — | Squidex.io Squidex | 27/1/2026 | 17/6/2026 | Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as actions within the Rules engine. The url parameter in the webhook configuration does not appear to validate or restrict destination IP… | |
| Modificada | Media (5.4) | 0.57% | — | Squidex.io Squidex | 7/12/2023 | 17/6/2026 | Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with assets.create permission is required for exploitation. | |
| Modificada | Alta (7.2) | 1.5% | — | Squidex.io Squidex | 7/11/2023 | 17/6/2026 | Squidex is an open source headless CMS and content management hub. Affected versions are subject to an arbitrary file write vulnerability in the backup restore feature which allows an authenticated attacker to gain remote code execution (RCE). Squidex allows users with the `squidex.admin.restore` permission to create… | |
| Modificada | Media (6.1) | 0.47% | — | Squidex.io Squidex | 7/11/2023 | 17/6/2026 | Squidex is an open source headless CMS and content management hub. Affected versions are missing origin verification in a postMessage handler which introduces a Cross-Site Scripting (XSS) vulnerability. The editor-sdk.js file defines three different class-like functions, which employ a global message event listener:… | |
| Modificada | Media (5.4) | 0.50% | — | Squidex.io Squidex | 7/11/2023 | 17/6/2026 | Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (XSS) vulnerability enables privilege escalation of authenticated users. The SVG element filtering mechanism intended to stop XSS attacks through uploaded SVG images, is insufficient resulting to… | |
| Modificada | Media (4.3) | 0.64% | — | Squidex.io Squidex | 10/7/2023 | 17/6/2026 | Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0. | |
| Modificada | Media (6.1) | 2.9% | — | Squidex.io Squidex | 18/3/2023 | 17/6/2026 | Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 0.58% | — | Squidex.io Squidex | 2/2/2023 | 17/6/2026 | Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0. | |
| Modificada | Media (6.5) | 0.41% | — | Squidex.io Squidex | 2/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0. |