Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.39% | — | Yootheme PROAI | 25/8/2026 | 23/9/2026 | Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective com_modules permissions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Yootheme PROAI | 25/8/2026 | 23/9/2026 | Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector. | |
| Aplazada | Media (5.3) | 0.41% | — | Yootheme ZOOAI | 21/8/2026 | 26/8/2026 | Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66 | |
| Aplazada | Alta (8.6) | 0.37% | — | Yootheme PROAI | 21/8/2026 | 26/8/2026 | Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content into SQL queries. | |
| Aplazada | Alta (8.6) | 0.44% | — | Yootheme ZOOAI | 21/8/2026 | 26/8/2026 | Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field elements weren't escaped, leading to a stored XSS vector. | |
| Aplazada | Media (6.9) | 0.50% | — | Yootheme ZOOAI | 21/8/2026 | 26/8/2026 | Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66. | |
| Aplazada | Alta (7) | 0.47% | — | Yootheme PROAI | 21/8/2026 | 26/8/2026 | Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern attacks, allowing authorized users to read arbitrary files. | |
| Aplazada | Media (4.6) | 0.21% | — | Yootheme ZOOAI | 21/8/2026 | 26/8/2026 | Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66 | |
| Aplazada | Media (6.9) | 0.22% | — | Yootheme ZOOAI | 20/8/2026 | 26/8/2026 | Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by unauthenticated users. | |
| Aplazada | Media (5.1) | 0.41% | — | Yootheme ZOOAI | 19/8/2026 | 26/8/2026 | Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer request parameter is passed straight to setRedirect() with no validation. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Yootheme ZOOAI | 19/8/2026 | 26/8/2026 | Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.type IN ("..."), with no quoting or escaping. | |
| Aplazada | Crítica (10) | 0.43% | — | Yootheme ZOOAI | 19/8/2026 | 26/8/2026 | Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group. | |
| Aplazada | Media (6.8) | 0.43% | — | YoothemeAI | 2/7/2026 | 2/7/2026 | The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating certain HTML attributes, which are permitted by wp_kses_post(), as markup, allowing users with the Author role to perform Stored Cross-Site Scripting attacks that execute in the browser of any user who views the… | |
| Modificada | Media (6.8) | 1.3% | — | Yootheme Pagekit | 14/10/2014 | 17/6/2026 | Open redirect vulnerability in YOOtheme Pagekit CMS 0.8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to index.php/user/logout. | |
| Modificada | Media (4.3) | 0.99% | — | Yootheme Pagekit | 14/10/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in YOOtheme Pagekit CMS 0.8.7 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP Referer header to index.php/user or (2) PATH_INFO to index.php. |