Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.39%—Yootheme PROAI25/8/202623/9/2026
Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules permissions.
AplazadaAlta (7.5)0.42%—Yootheme PROAI25/8/202623/9/2026
Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.
AplazadaMedia (5.3)0.41%—Yootheme ZOOAI21/8/202626/8/2026
Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66
AplazadaAlta (8.6)0.37%—Yootheme PROAI21/8/202626/8/2026
Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries.
AplazadaAlta (8.6)0.44%—Yootheme ZOOAI21/8/202626/8/2026
Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector.
AplazadaMedia (6.9)0.50%—Yootheme ZOOAI21/8/202626/8/2026
Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66.
AplazadaAlta (7)0.47%—Yootheme PROAI21/8/202626/8/2026
Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern attacks, allowing authorized users to read arbitrary files.
AplazadaMedia (4.6)0.21%—Yootheme ZOOAI21/8/202626/8/2026
Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66
AplazadaMedia (6.9)0.22%—Yootheme ZOOAI20/8/202626/8/2026
Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users.
AplazadaMedia (5.1)0.41%—Yootheme ZOOAI19/8/202626/8/2026
Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer request parameter is passed straight to setRedirect() with no validation.
AplazadaCrítica (9.3)0.39%—Yootheme ZOOAI19/8/202626/8/2026
Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.type IN ("..."), with no quoting or escaping.
AplazadaCrítica (10)0.43%—Yootheme ZOOAI19/8/202626/8/2026
Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.
AplazadaMedia (6.8)0.43%—YoothemeAI2/7/20262/7/2026
The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating certain HTML attributes, which are permitted by wp_kses_post(), as markup, allowing users with the Author role to perform Stored Cross-Site Scripting attacks that execute in the browser of any user who views the…
ModificadaMedia (6.8)1.3%—Yootheme Pagekit14/10/201417/6/2026
Open redirect vulnerability in YOOtheme Pagekit CMS 0.8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to index.php/user/logout.
ModificadaMedia (4.3)0.99%—Yootheme Pagekit14/10/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in YOOtheme Pagekit CMS 0.8.7 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP Referer header to index.php/user or (2) PATH_INFO to index.php.