Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.46% | — | Josh Kohlbach Store ExporterAI | 6/11/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Josh Kohlbach Store Exporter woocommerce-exporter allows PHP Local File Inclusion.This issue affects Store Exporter: from n/a through <= 2.7.6. | |
| Aplazada | Alta (7.1) | 0.23% | — | Skygroup GostoreAI | 6/11/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup GoStore gostore allows Reflected XSS.This issue affects GoStore: from n/a through < 1.6.4. | |
| Aplazada | Media (4.3) | 0.14% | — | Superstorefinder Super Store FinderAI | 29/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site Request Forgery.This issue affects Super Store Finder: from n/a through <= 7.5. | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Retro Basketball Shoes Online Store | 28/10/2025 | 17/6/2026 | A security vulnerability has been detected in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file /admin/admin_football.php. The manipulation of the argument pid leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Modificada | Media (5.5) | 0.46% | — | Campcodes Retro Basketball Shoes Online Store | 28/10/2025 | 17/6/2026 | A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file /admin/admin_product.ph. Executing a manipulation of the argument pid can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the… | |
| Modificada | Media (5.5) | 0.46% | — | Campcodes Retro Basketball Shoes Online Store | 28/10/2025 | 17/6/2026 | A security flaw has been discovered in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file /admin/admin_feature.php. Performing a manipulation of the argument pid results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may… | |
| Analizada | Media (5.5) | 0.46% | — | Campcodes Retro Basketball Shoes Online Store | 28/10/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_index.php. Such manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit is publicly available and… | |
| Aplazada | Media (5.4) | 0.27% | — | Conversios Enhanced-e-commerce-for-woocommerce-storeAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Conversios Conversios.io enhanced-e-commerce-for-woocommerce-store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conversios.io: from n/a through <= 7.2.13. | |
| Aplazada | Media (4.3) | 0.23% | — | Stackwc Open Close Woocommerce StoreAI | 27/10/2025 | 5/10/2026 | Missing Authorization vulnerability in StackWC Open Close WooCommerce Store woc-open-close allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Open Close WooCommerce Store: from n/a through <= 5.0.0. | |
| Aplazada | Alta (8.8) | 0.46% | — | WP Store LocatorAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Tijmen Smit WP Store Locator wp-store-locator allows Object Injection.This issue affects WP Store Locator: from n/a through <= 2.2.260. | |
| Analizada | Media (6.1) | 0.23% | — | Oracle Istore | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human… | |
| Aplazada | Alta (7.2) | 0.69% | — | Docodoco Store LocatorAI | 15/10/2025 | 17/6/2026 | The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on… | |
| Aplazada | Alta (8.8) | 0.72% | — | 8theme XstoreAI | 15/10/2025 | 17/6/2026 | The XStore theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 9.5.4 via theet_ajax_required_plugins_popup() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .php files on the server,… | |
| Aplazada | Media (5.5) | 0.33% | — | Yousaf530 Inferno Online Clothing StoreAI | 13/10/2025 | 17/6/2026 | A vulnerability was identified in yousaf530 Inferno Online Clothing Store up to 827dd42bfbe380e8de76fdc67958c24cf1246208. The affected element is an unknown function of the file /log.php. Such manipulation of the argument cemail/password leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.38% | — | Ywxbear Php-bookstore-website-exampleAIYwxbear PHP Basic Bookstore WebsiteAI | 11/10/2025 | 17/6/2026 | A vulnerability has been found in ywxbear PHP-Bookstore-Website-Example and PHP Basic BookStore Website up to 0e0b9f542f7a2d90a8d7f8c83caca69294e234e4. This issue affects some unknown processing of the file /index.php of the component Quantity Handler. Such manipulation leads to improper validation of specified… | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Simple E-commerce Bookstore | 8/10/2025 | 17/6/2026 | A vulnerability was detected in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown function of the file /register.php. Performing manipulation of the argument register_username results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may… | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Simple E-commerce Bookstore | 8/10/2025 | 17/6/2026 | A vulnerability was identified in SourceCodester Simple E-Commerce Bookstore 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument login_username leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.42% | — | Janobe Simple E-commerce Bookstore | 8/10/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown function of the file /cart.php. The manipulation of the argument remove results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.3) | 0.29% | — | 8theme XstoreAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: from n/a through < 9.6. | |
| Analizada | Media (6.5) | 0.53% | — | Smartbear Swagger Petstore | 25/9/2025 | 17/6/2026 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server version | |
| Analizada | Media (6.1) | 0.38% | — | Smartbear Swagger Petstore | 25/9/2025 | 17/6/2026 | Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet | |
| Analizada | Media (6.5) | 0.43% | — | Smartbear Swagger Petstore | 25/9/2025 | 17/6/2026 | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint | |
| Analizada | Media (5.5) | 0.42% | — | 1000projects Bookstore Management System | 23/9/2025 | 17/6/2026 | A vulnerability was determined in 1000projects Bookstore Management System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of the argument unm causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (6.5) | 0.21% | — | Bdthemes Ultimate Store KITAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.8.6. | |
| Aplazada | Media (4.3) | 0.29% | — | Wpestore WpematicoAI | 22/9/2025 | 1/10/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in etruel WPeMatico RSS Feed Fetcher wpematico allows Retrieve Embedded Sensitive Data.This issue affects WPeMatico RSS Feed Fetcher: from n/a through <= 2.8.10. |