Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Burgersoftware StorebizAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in burgersoftware StoreBiz storebiz allows DOM-Based XSS.This issue affects StoreBiz: from n/a through <= 1.0.32. | |
| Aplazada | Alta (7.1) | 0.17% | — | Store Locator WidgetAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Store Locator Widgets Store Locator Widget store-locator-widget allows Stored XSS.This issue affects Store Locator Widget: from n/a through <= 2025r2. | |
| Aplazada | Media (4.3) | 0.32% | — | Conversios Enhanced-e-commerce-for-woocommerce-storeAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Conversios Conversios.io enhanced-e-commerce-for-woocommerce-store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conversios.io: from n/a through <= 7.2.3. | |
| Modificada | Media (5.4) | 0.36% | — | Themehunk BIG Store | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in themehunk Big Store big-store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Big Store: from n/a through <= 2.0.8. | |
| Aplazada | Crítica (9.3) | 0.59% | — | Wpexperts WP Multistore LocatorAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Multistore Locator wp-multi-store-locator allows SQL Injection.This issue affects WP Multistore Locator: from n/a through <= 2.5.2. | |
| Analizada | Alta (8.1) | 0.34% | — | Tecno Com.transsnet.store | 11/3/2025 | 17/6/2026 | The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which may lead to code injection risks. | |
| Aplazada | Media (4.3) | 0.24% | — | Lafka Multi Store Burger Pizza Food DeliveryAI | 5/3/2025 | 17/6/2026 | The Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'lafka_import_lafka' AJAX actions in all versions up to, and including, 4.5.7. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (4.3) | 0.29% | — | Vwthemes VW Storefront | 4/3/2025 | 17/6/2026 | The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all versions up to, and including, 0.9.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset… | |
| Analizada | Crítica (9) | 0.62% | 💥 PoC | Selldone Storefront | 3/3/2025 | 17/6/2026 | Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component | |
| Aplazada | Alta (7.1) | 0.37% | — | Dactum Clickbank StorefrontAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dactum ClickBank Storefront mycbgenie-clickbank-storefront allows Reflected XSS.This issue affects ClickBank Storefront: from n/a through <= 1.7. | |
| Aplazada | Alta (7.1) | 0.37% | — | JAS Saran G Gwebpro-store-locatorAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jas Saran G Web Pro Store Locator gwebpro-store-locator allows Reflected XSS.This issue affects G Web Pro Store Locator: from n/a through <= 2.0.1. | |
| Aplazada | Alta (7.1) | 0.28% | — | Cmsaccount Photo Video StoreAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmsaccount Photo Video Store photo-video-store allows Reflected XSS.This issue affects Photo Video Store: from n/a through <= 21.07. | |
| Aplazada | Alta (7.1) | 0.23% | — | Simonhunter WOO Store ModeAI | 27/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in simonhunter Woo Store Mode woo-store-mode allows Reflected XSS.This issue affects Woo Store Mode: from n/a through <= 1.0.1. | |
| Analizada | Crítica (9.1) | 0.37% | — | Sainwp Onestore Sites | 27/2/2025 | 17/6/2026 | The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 0.1.1 via the class-export.php file. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query… | |
| Aplazada | Crítica (9.3) | 0.53% | — | Wpexperts WP Multistore LocatorAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPExperts.io WP Multistore Locator wp-multi-store-locator allows Blind SQL Injection.This issue affects WP Multistore Locator: from n/a through <= 2.5.1. | |
| Aplazada | Media (6.4) | 0.33% | — | Store Locator WidgetAI | 19/2/2025 | 17/6/2026 | The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocatorwidget' shortcode in all versions up to, and including, 2025r1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (4.8) | 0.51% | — | 1000projects Bookstore Management System | 11/2/2025 | 17/6/2026 | A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file process_book_add.php of the component Add Book Page. The manipulation of the argument Book Name leads to cross site scripting. The attack can be initiated… | |
| Analizada | Media (5.1) | 0.67% | — | 1000projects Bookstore Management System | 11/2/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affects an unknown part of the file process_users_del.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. | |
| Analizada | Media (5.3) | 0.55% | — | 1000projects Bookstore Management System | 11/2/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affected by this issue is some unknown functionality of the file addtocart.php. The manipulation of the argument bcid leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.39% | — | Superstorefinder Super Store Finder | 9/2/2025 | 17/6/2026 | The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all versions up to, and including, 7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.6) | 0.24% | — | Sainwp Onestore SitesAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites onestore-sites allows Cross Site Request Forgery.This issue affects OneStore Sites: from n/a through <= 0.1.1. | |
| Analizada | Media (4.4) | 0.16% | — | Samsung Blockchain Keystore | 4/2/2025 | 17/6/2026 | Out-of-bounds read in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to read out-of-bounds memory. | |
| Analizada | Media (4.4) | 0.15% | — | Samsung Blockchain Keystore | 4/2/2025 | 17/6/2026 | Out-of-bounds write in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to write out-of-bounds memory. | |
| Analizada | Media (4.6) | 0.20% | — | Samsung Galaxy Store | 4/2/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard. | |
| Aplazada | Alta (7.1) | 0.32% | — | Umangmetatagg Custom WP Store LocatorAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in umangmetatagg Custom WP Store Locator custom-store-locator allows Reflected XSS.This issue affects Custom WP Store Locator: from n/a through <= 1.4.7. |