Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.54% | — | Ohsoft CoffeezipAI | 22/7/2026 | 6/10/2026 | An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. | |
| Aplazada | Crítica (9.8) | 0.53% | — | HOT CoffeeAI | 17/6/2026 | 6/10/2026 | Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions. | |
| Aplazada | Alta (7.1) | 0.26% | — | Themegoods Craft CraftcoffeeAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Craft craftcoffee allows DOM-Based XSS.This issue affects Craft: from n/a through <= 2.3.6. | |
| Analizada | Alta (7.8) | 0.34% | — | Generalcoffee Fade IN | 28/10/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .fadein file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Alta (7.8) | 0.34% | — | Generalcoffee Fade IN | 28/10/2025 | 17/6/2026 | A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .xml file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Media (6.1) | 0.58% | 💥 Exploit | Coffee-code Plugin Oficial | 15/5/2025 | 17/6/2026 | The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users. | |
| Analizada | Media (4.8) | 0.26% | — | Coffee-code Plugin Oficial | 15/5/2025 | 17/6/2026 | The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (5.9) | 0.29% | — | Coffeestudios POP UPAI | 7/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in coffeestudios Pop Up popup-seo-optimized allows Stored XSS.This issue affects Pop Up: from n/a through <= 0.1. | |
| Analizada | Media (4.8) | 0.22% | — | Coffee Project Coffee | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allows Cross-Site Scripting (XSS).This issue affects Coffee: from 0.0.0 before 1.4.0. | |
| Analizada | Media (5.3) | 0.40% | — | Coffee2code Custom Post Limits | 13/9/2024 | 17/6/2026 | The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, 4.4.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web… | |
| Analizada | Media (5.3) | 0.44% | — | Coffee2code Remember ME Controls | 6/9/2024 | 17/6/2026 | The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the… | |
| Modificada | Media (5.3) | 0.48% | — | Coffee2code NO Update NAG | 12/8/2024 | 17/6/2026 | The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.12. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web… | |
| Modificada | Media (4.3) | 0.27% | — | Buymeacoffee BUY ME A Coffee | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7. | |
| Modificada | Crítica (9.8) | 0.61% | — | Coffee2code Commenter Emails | 7/11/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Scott Reilly Commenter Emails.This issue affects Commenter Emails: from n/a through 2.6.1. | |
| Modificada | Media (6.5) | 0.46% | — | Coffee-jumbo Project Coffee-jumbo | 18/9/2023 | 9/7/2026 | An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages. | |
| Modificada | Media (5.4) | 0.60% | — | Buymeacoffee BUY ME A Coffee | 14/7/2023 | 17/6/2026 | The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.6 due to insufficient sanitization and escaping on the 'text value set via the bmc_post_reception action. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.3) | 0.34% | — | Buymeacoffee BUY ME A Coffee | 11/7/2023 | 17/6/2026 | The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the recieve_post, bmc_disconnect, name_post, and widget_post functions in versions up to, and including, 3.7. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (4.3) | 0.55% | — | Buymeacoffee BUY ME A Coffee | 11/7/2023 | 17/6/2026 | The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the recieve_post, bmc_disconnect, name_post, and widget_post functions in versions up to, and including, 3.7. This makes it possible for authenticated attackers,… | |
| Modificada | Media (4.8) | 0.47% | — | Buymeacoffee BUY ME A Coffee | 10/7/2023 | 17/6/2026 | The Buy Me a Coffee WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (6.1) | 0.65% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Campcodes Coffee Shop POS System 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Users.php. The manipulation of the argument firstname leads to cross site scripting. The attack can be launched remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 1.6% | 💥 PoC | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Campcodes Coffee Shop POS System 1.0. Affected is an unknown function of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Alta (7.5) | 0.61% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Coffee Shop POS System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/sales/manage_sale.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (7.5) | 0.61% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Coffee Shop POS System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/products/manage_product.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.5) | 0.61% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Coffee Shop POS System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/products/view_product.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Alta (7.5) | 0.61% | — | Coffee Shop POS System Project Coffee Shop POS System | 21/4/2023 | 17/6/2026 | A vulnerability was found in Campcodes Coffee Shop POS System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/categories/manage_category.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been… |