Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
3237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.70% | — | Adobe CommerceAdobe MagentoAdobe Commerce B2B | 11/8/2026 | 25/9/2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially… | |
| Analizada | Alta (7.2) | 0.56% | — | Adobe CommerceAdobe MagentoAdobe Commerce B2B | 11/8/2026 | 25/9/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. | |
| Analizada | Media (4.9) | 0.63% | — | Adobe CommerceAdobe MagentoAdobe Commerce B2B | 11/8/2026 | 25/9/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. | |
| Pendiente de análisis | Crítica (10) | 0.85% | 💥 PoC | SAP Commerce CloudAI | 11/8/2026 | 17/8/2026 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on… | |
| Aplazada | Crítica (9.3) | 0.50% | — | ReadyecommerceAI | 10/8/2026 | 9/9/2026 | ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in ProductController.php. Attackers can perform time-based blind SQL… | |
| Aplazada | Media (5.1) | 0.24% | — | ReadyecommerceAI | 10/8/2026 | 9/9/2026 | ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated customers to inject malicious HTML payloads through the chat and support ticket messaging systems by exploiting unsanitized rendering via the v-html directive in Messages.vue, RightChatSidebar.vue,… | |
| Aplazada | Crítica (9.8) | 0.83% | 💥 PoC | Tychesoftwares Product Input Fields FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution on… | |
| Aplazada | Baja (3.7) | 0.24% | — | Accept Paypal Stripe With Subscriptions FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal… | |
| Aplazada | Media (5.3) | 0.29% | — | Accept Paypal Stripe With Subscriptions FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full… | |
| Aplazada | Media (5.4) | 0.23% | — | Cusrev Customer Reviews FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer Reviews for WooCommerce WordPress plugin… | |
| Aplazada | Media (5.9) | 0.16% | — | Subscriptions FOR WoocommerceAI | 7/8/2026 | 26/8/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal order token to the order being completed on the WooCommerce order-received flow: it captures a client-supplied token and marks the order paid whenever the capture status is COMPLETED, without… | |
| Aplazada | Alta (8.8) | 0.64% | — | Subscriptions FOR WoocommerceAI | 7/8/2026 | 26/8/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack… | |
| Aplazada | Media (4.3) | 0.27% | — | Subscriptions FOR WoocommerceAI | 7/8/2026 | 26/8/2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering its details, allowing any authenticated customer to read another customer's subscription information (the subscribed product, status, and dates) by supplying that… | |
| Aplazada | Media (5.3) | 0.32% | — | Event Booking Manager FOR WoocommerceAI | 6/8/2026 | 26/8/2026 | The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to… | |
| Aplazada | Alta (7.5) | 0.19% | — | Redyx Payment Gateway FOR Redsys AND Woocommerce LiteAI | 6/8/2026 | 26/8/2026 | The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own… | |
| Aplazada | Alta (7.5) | 0.21% | — | Integrate Phonepe With WoocommerceAI | 6/8/2026 | 26/8/2026 | The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to reuse a single valid transaction to mark… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpml Woocommerce Multilingual AND MulticurrencyAI | 6/8/2026 | 12/8/2026 | Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Facebook FOR WoocommerceAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Mercadopago Mercado Pago Payments FOR WoocommerceAI | 6/8/2026 | 12/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions. | |
| Aplazada | Media (5.3) | 0.33% | — | Yithemes Yith Woocommerce Zoom MagnifierAI | 6/8/2026 | 12/8/2026 | Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Kadence Woocommerce Email DesignerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | |
| Aplazada | Media (6.5) | 0.40% | — | Welcart E-commerceAI | 6/8/2026 | 26/8/2026 | The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks. | |
| Aplazada | Crítica (9.1) | 0.49% | — | Codedropz Drag AND Drop Multiple File Upload FOR WoocommerceAI | 6/8/2026 | 26/8/2026 | The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload directory and irreversibly destroy… | |
| Aplazada | Media (5.3) | 0.32% | — | Peprodev Woocommerce Receipt UploaderAI | 6/8/2026 | 26/8/2026 | The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they… | |
| Aplazada | Media (5.3) | 0.16% | — | Peprodev Pepro Bacs Receipt Upload FOR WoocommerceAI | 6/8/2026 | 26/8/2026 | PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is vulnerable to unauthenticated… |