Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.28% | — | PDF Invoices Packing Slips FOR WoocommerceAI | 1/10/2026 | 1/10/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields in all versions up to, and including, 5.16.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.23% | — | Sprout InvoicesAI | 30/9/2026 | 30/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions. | |
| Pendiente de análisis | Alta (8.7) | 0.30% | — | InvoiceshelfAI | 23/9/2026 | 23/9/2026 | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.4.1, in InvoiceShelf's multi-company installations, any user who is an Owner of one company can read and overwrite any user account in any other company on the same… | |
| Aplazada | Media (4.3) | 0.25% | — | Sprout InvoicesAI | 12/9/2026 | 14/9/2026 | The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users. | |
| Aplazada | Media (6.5) | 0.87% | — | Webtoffee Woocommerce PDF Invoices Packing Slips Delivery Notes Shipping LabelsAI | 23/8/2026 | 24/8/2026 | The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Media (6.5) | 0.34% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.13. | |
| Aplazada | Media (4.3) | 0.39% | — | Wpdesk PDF Invoices Packing Slips FOR WoocommerceAI | 11/7/2026 | 13/7/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpcloud Woocommerce PDF Invoices Packing Slips Delivery Notes AND Shipping LabelsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Wpdesk Woocommerce PDF Invoices Packing SlipsAI | 15/6/2026 | 17/6/2026 | Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions. | |
| Aplazada | Alta (7.1) | 0.23% | — | Slicedinvoices Sliced InvoicesAI | 15/6/2026 | 17/6/2026 | WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send requests to the admin.php endpoint with action=duplicate_quote_invoice and malicious 'post'… | |
| Aplazada | Media (5.3) | 0.29% | — | Boldgrid Client Invoicing BY Sprout InvoicesAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.10. | |
| Analizada | Alta (8.7) | 0.39% | — | Invoiceshelf | 31/3/2026 | 24/7/2026 | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Invoice PDF generation module. User-supplied HTML in the invoice Notes field is passed unsanitised… | |
| Analizada | Alta (8.1) | 0.35% | — | Invoiceshelf | 31/3/2026 | 24/7/2026 | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Payment receipt PDF generation module. User-supplied HTML in the payment Notes field is passed… | |
| Analizada | Alta (8.1) | 0.35% | — | Invoiceshelf | 31/3/2026 | 24/7/2026 | InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates. Prior to version 2.2.0, a Server-Side Request Forgery (SSRF) vulnerability exists in the Estimate PDF generation module. User-supplied HTML in the estimate Notes field is passed… | |
| Aplazada | Alta (7.2) | 0.57% | — | Boldgrid Client Invoicing BY Sprout InvoicesAISprout InvoicesAI | 13/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows PHP Local File Inclusion.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.9. | |
| Aplazada | Media (5.3) | 0.22% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.8. | |
| Aplazada | Media (4.3) | 0.27% | — | Wp-pdf-invoices-packing-slips PDF Invoices Packing SlipsAI | 18/2/2026 | 17/6/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.0 via the `wpo_ips_edi_save_order_customer_peppol_identifiers` AJAX action due to missing capability checks and order ownership validation. This makes it… | |
| Aplazada | Media (6.4) | 0.26% | — | QR Code FOR Woocommerce Order Emails PDF Invoices Packing SlipsAI | 7/1/2026 | 17/6/2026 | The QR Code for WooCommerce order emails, PDF invoices, packing slips plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 1.9.42 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Analizada | Crítica (9.6) | 0.25% | — | UI Argentina Afip Invoices | 5/1/2026 | 7/10/2026 | A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow privilege escalation if an Administrator is tricked into visiting a crafted malicious page. This plugin is disabled by default. Affected Products: UCRM Argentina AFIP invoices Plugin (Version 1.2.0… | |
| Aplazada | Crítica (9.8) | 0.38% | — | Boldgrid Client Invoicing BY Sprout InvoicesAI | 18/12/2025 | 5/10/2026 | Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7. | |
| Aplazada | Media (4.3) | 0.22% | — | Wpovernight Woocommerce PDF Invoices Packing SlipsAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-packing-slips allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoices & Packing Slips: from n/a through <= 4.9.1. | |
| Aplazada | Media (4.3) | 0.19% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 29/10/2025 | 17/6/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7. | |
| Aplazada | Alta (7.1) | 0.15% | — | Wpdesk Flexible PDF Invoices FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible PDF Invoices for WooCommerce & WordPress flexible-invoices allows Cross Site Request Forgery.This issue affects Flexible PDF Invoices for WooCommerce & WordPress: from n/a through <= 6.0.13. | |
| Aplazada | Crítica (9.4) | 0.53% | — | Ready InvoicesAI | 16/4/2025 | 17/6/2026 | Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices module allows for SQL Injection attacks. | |
| Aplazada | Media (5.3) | 0.39% | — | Slicedinvoices Sliced InvoicesAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in SlicedInvoices Sliced Invoices sliced-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sliced Invoices: from n/a through <= 3.10.0. |