Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | — | — | Integration FOR Epos NOW AND WoocommerceAI | 7/10/2026 | 7/10/2026 | The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails… | |
| Pendiente de análisis | Alta (8.8) | — | — | Payloadcms Plugin EcommerceAI | 6/10/2026 | 6/10/2026 | Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before 3.90.0 and canary versions before 4.0.0-canary.34, use of the Stripe payment adapter can allow a Stripe order confirmation to be processed more than once under certain conditions. This issue is fixed… | |
| Aplazada | Media (6.1) | — | — | Akilli Ticaret Software Technologies E Commerce PackAI | 6/10/2026 | 6/10/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akıllı Ticaret Software Technologies Ltd. Co. E-Commerce Pack allows Reflected XSS. This issue affects E-Commerce Pack: through 2026-10-06. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Aplazada | Media (6.5) | 0.33% | — | Payplug FOR WoocommerceAI | 6/10/2026 | 6/10/2026 | Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | WPG Demos Woocommerce Simple AuctionsAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in WooCommerce Simple Auctions <= 3.0.10 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Wclovers Woocommerce Multivendor MarketplaceAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Midtrans WoocommerceAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Midtrans-WooCommerce <= 2.32.3 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Payplug FOR WoocommerceAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in PayPlug for WooCommerce (Official) <= 3.1.0 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Storegrowth Smart Sales Booster FOR WoocommerceAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.0.6 versions. | |
| Aplazada | Alta (7.5) | 0.31% | — | Woocommerce LotteryAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in WooCommerce Lottery <= 2.2.9 versions. | |
| Aplazada | Alta (7.1) | 0.31% | — | Ecpay EcommerceAI | 6/10/2026 | 6/10/2026 | Subscriber Broken Access Control in ECPay Ecommerce for WooCommerce <= 1.1.2606090 versions. | |
| Aplazada | Crítica (9.9) | 0.74% | — | Woocommerce Designer PROAI | 6/10/2026 | 6/10/2026 | Subscriber Remote Code Execution (RCE) in WooCommerce Designer Pro <= 1.9.33 versions. | |
| Aplazada | Crítica (9.3) | 0.38% | — | Woocommerce AppointmentsAI | 6/10/2026 | 6/10/2026 | Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions. | |
| Aplazada | Alta (7.1) | 0.19% | — | Villatheme Photo Reviews FOR WoocommerceAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews for WooCommerce: from n/a through 1.2.30. | |
| Aplazada | Media (5.3) | 0.18% | — | KIT FOR WoocommerceAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Kit Kit (formerly ConvertKit) for WooCommerce convertkit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kit (formerly ConvertKit) for WooCommerce: from n/a through 2.2.0. | |
| Aplazada | Media (6.5) | 0.13% | — | Implecode Ecommerce Product CatalogAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Stored XSS.This issue affects eCommerce Product Catalog: from n/a through 3.6.2. | |
| Aplazada | Media (5.9) | 0.20% | — | Imaginate-solutions File Uploads Addon FOR WoocommerceAI | 5/10/2026 | 6/10/2026 | The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files. | |
| Aplazada | Baja (2) | 0.25% | — | OscommerceAI | 5/10/2026 | 6/10/2026 | A security flaw has been discovered in osCommerce osCommerce2 up to 2.3.4.1. This vulnerability affects the function include of the file admin/newsletters.php of the component Newsletter Management. Performing a manipulation of the argument module results in code injection. The attack is possible to be carried out… | |
| Aplazada | Baja (1.9) | 0.19% | — | OscommerceAI | 5/10/2026 | 6/10/2026 | A vulnerability was identified in osCommerce osCommerce2 up to 2.3.4.1. This affects the function include of the file includes/classes/payment.php of the component Payment Page. Such manipulation of the argument MODULE_PAYMENT_INSTALLED leads to code injection. The attack can be executed remotely. The exploit is… | |
| Aplazada | Media (5.3) | 0.18% | — | Razorpay FOR WoocommerceAI | 4/10/2026 | 6/10/2026 | The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders. | |
| Aplazada | Media (5.3) | 0.22% | — | Mailchimp FOR WoocommerceAI | 3/10/2026 | 6/10/2026 | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart. | |
| Aplazada | Media (4.3) | 0.16% | — | Helpdesk Support Ticket System FOR WoocommerceAI | 3/10/2026 | 6/10/2026 | The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level… | |
| Aplazada | Alta (8.1) | 0.34% | — | Photo Reviews FOR WoocommerceAI | 3/10/2026 | 6/10/2026 | The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review's reviews-images comment meta… | |
| Aplazada | Media (5.3) | 0.20% | — | Softtr Informatics E-commerce PackAI | 2/10/2026 | 6/10/2026 | Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting. This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (7.2) | 0.24% | — | Cusrev Customer Reviews FOR WoocommerceAI | 2/10/2026 | 2/10/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… |