Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.43% | — | Coreshop | 8/1/2026 | 6/10/2026 | CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-based or time-based techniques. The database account used by the application is… | |
| Aplazada | Alta (7.1) | 0.18% | — | Hands01 E-shops-cart2AI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hands01 e-shops e-shops-cart2 allows DOM-Based XSS.This issue affects e-shops: from n/a through <= 1.0.4. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpshop.ru Adsplace RAI | 6/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPShop.Ru AdsPlace'r – Ad Manager, Inserter, AdSense Ads allows DOM-Based XSS.This issue affects AdsPlace'r – Ad Manager, Inserter, AdSense Ads: from n/a through 1.1.5. | |
| Analizada | Media (6.5) | 0.21% | — | Evershop | 5/1/2026 | 17/6/2026 | A Blind Server-Side Request Forgery (SSRF) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to force the server to initiate an HTTP request via the "GET /images" API. The vulnerability occurs due to insufficient validation of the "src" query parameter, which permits arbitrary HTTP or HTTPS… | |
| Analizada | Alta (7.5) | 0.35% | — | Evershop | 5/1/2026 | 17/6/2026 | A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the application server's resources via the "GET /images" API. The application fails to limit the height of the use-element shadow tree or the dimensions of pattern tiles during the processing of SVG files,… | |
| Aplazada | Crítica (9.9) | 0.31% | — | Themify ShopoAI | 5/1/2026 | 7/10/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server.This issue affects Shopo: from n/a through 1.1.4. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Aa-team Amazon Native Shopping RecommendationsAI | 5/1/2026 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Native Shopping Recommendations allows SQL Injection.This issue affects Amazon Native Shopping Recommendations: from n/a through 1.3. | |
| Aplazada | Media (6.1) | 0.22% | — | Radiustheme ShopbuilderAI | 2/1/2026 | 17/6/2026 | The ShopBuilder WordPress plugin before 3.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (4.3) | 0.12% | — | Channelize Live Shopping Video StreamsAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Cross Site Request Forgery.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2.0. | |
| Aplazada | Media (5.3) | 0.25% | — | Channelize Live Shopping AND Shoppable Videos FOR WoocommerceAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2.0. | |
| Aplazada | Media (5.3) | 0.22% | — | Wpdesk Shopmagic FOR WoocommerceAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in wpdesk ShopMagic shopmagic-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShopMagic: from n/a through <= 4.7.2. | |
| Analizada | Media (5.5) | 0.39% | — | Facebook-riares Online PET Shop Management System | 14/12/2025 | 7/10/2026 | A security vulnerability has been detected in itsourcecode Online Pet Shop Management System 1.0. This issue affects some unknown processing of the file /pet1/update_cnp.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and… | |
| Analizada | Media (5.5) | 0.39% | — | Facebook-riares Online PET Shop Management System | 13/12/2025 | 7/10/2026 | A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown code of the file /pet1/addcnp.php. This manipulation of the argument cnpname causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could… | |
| Analizada | Media (5.5) | 0.39% | — | Facebook-riares Online PET Shop Management System | 13/12/2025 | 7/10/2026 | A vulnerability was identified in itsourcecode Online Pet Shop Management System 1.0. This affects an unknown part of the file /pet1/available.php. Such manipulation of the argument Name leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Analizada | Alta (8.7) | 0.56% | — | Puneethreddyhc Online Shopping System Advanced | 12/12/2025 | 17/6/2026 | Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by… | |
| Analizada | Media (6.1) | 0.19% | — | Shopware | 11/12/2025 | 17/6/2026 | Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XSS vulnerability in AuthController.php. A request parameter from the login page URL is directly rendered within the Twig template of the Storefront login page without further processing or input… | |
| Aplazada | Media (6.5) | 0.19% | — | GET Bowtied Shopkeeper ExtenderAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Get Bowtied Shopkeeper Extender shopkeeper-extender allows Stored XSS.This issue affects Shopkeeper Extender: from n/a through < 7.0. | |
| Aplazada | Baja (2.1) | 0.23% | — | Jihai Jshop Miniprogram Mall SystemAI | 8/12/2025 | 7/10/2026 | A vulnerability was found in Jihai Jshop MiniProgram Mall System 2.9.0. Affected by this issue is some unknown functionality of the file /index.php/api.html. The manipulation of the argument cat_id results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. The… | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Simple Shopping Cart | 8/12/2025 | 7/10/2026 | A vulnerability was identified in code-projects Simple Shopping Cart 1.0. Impacted is an unknown function of the file /adminlogin.php. The manipulation of the argument admin_username leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. | |
| Analizada | Baja (2.1) | 0.32% | — | Fabian Simple Shopping Cart | 8/12/2025 | 7/10/2026 | A vulnerability was determined in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Admin/additems.php. Executing manipulation of the argument item_name can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Baja (2.1) | 0.32% | — | Fabian Simple Shopping Cart | 8/12/2025 | 7/10/2026 | A vulnerability was found in code-projects Simple Shopping Cart 1.0. This vulnerability affects unknown code of the file /Customers/settings.php. Performing manipulation of the argument user_id results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.30% | — | Trippwastaken PHP Guitar ShopAI | 5/12/2025 | 25/9/2026 | A weakness has been identified in TrippWasTaken PHP-Guitar-Shop up to 6ce0868889617c1975982aae6df8e49555d0d555. This vulnerability affects unknown code of the file /product.php of the component Product Details Page. Executing manipulation of the argument ID can lead to sql injection. It is possible to launch the… | |
| Aplazada | Media (4.3) | 0.12% | — | Hide Categories OR Products ON Shop PageAI | 5/12/2025 | 25/9/2026 | The Hide Categories Or Products On Shop Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7. This is due to missing or incorrect nonce validation on the save_data_hcps() function. This makes it possible for unauthenticated attackers to update the plugin's… | |
| Aplazada | Media (4.3) | 0.12% | — | ShopengineAI | 3/12/2025 | 17/6/2026 | The ShopEngine Elementor WooCommerce Builder Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.8.5. This is due to missing nonce validation on the "post_add_to_list" function as well as an incorrect permissions callback in the "Api/init" function. This makes… | |
| Modificada | Alta (7.5) | 0.37% | — | Evershop | 2/12/2025 | 17/6/2026 | EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/images endpoint. The endpoint is accessible without authentication by default, and server-side validation of uploaded files is insufficient. This can be abused to upload arbitrary content (including… |