Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.34% | — | Dotstore Hide Shipping Method FOR WoocommerceAI | 3/2/2025 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Hide Shipping Method For WooCommerce hide-shipping-method-for-woocommerce.This issue affects Hide Shipping Method For WooCommerce: from n/a through <= 1.5.1. | |
| Analizada | Media (4.3) | 0.24% | — | Ikjweb Zstore Manager Basic | 30/1/2025 | 17/6/2026 | The zStore Manager Basic plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the zstore_clear_cache() function in all versions up to, and including, 3.311. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's… | |
| Modificada | Media (5.4) | 0.27% | — | Sellerthemes Storely | 30/1/2025 | 17/6/2026 | The Storely theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versions up to, and including, 18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary… | |
| Aplazada | Alta (8.1) | 0.39% | 💥 PoC | LifestylestoreAI | 27/1/2025 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf of an authenticated user, potentially leading to account modifications or data compromise. | |
| Modificada | Media (6.1) | 0.26% | — | Wpexperts WP Multi Store Locator | 27/1/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WPExperts.io WP Multistore Locator wp-multi-store-locator allows Reflected XSS.This issue affects WP Multistore Locator: from n/a through <= 2.4.7. | |
| Aplazada | Alta (7.1) | 0.26% | — | Codepeople Music StoreAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Music Store music-store allows Reflected XSS.This issue affects Music Store: from n/a through <= 1.1.19. | |
| Aplazada | Media (4.3) | 0.24% | — | Bdthemes Ultimate Store KITAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Store Kit Elementor Addons: from n/a through <= 2.3.0. | |
| Aplazada | Media (4.3) | 0.34% | — | Gohero Store CustomizerAI | 25/1/2025 | 17/6/2026 | The GoHero Store Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wooh_action_settings_save_frontend() function in all versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to update limited… | |
| Aplazada | Media (5.3) | 0.43% | — | Silverplugins Build Private Store FOR WoocommerceAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in silverplugins217 Build Private Store For Woocommerce build-private-store-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Build Private Store For Woocommerce: from n/a through <= 1.0. | |
| Aplazada | Media (4.3) | 0.24% | — | Dotstore Product Size Charts Plugin FOR WoocommerceAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Product Size Charts Plugin for WooCommerce woo-advanced-product-size-chart.This issue affects Product Size Charts Plugin for WooCommerce: from n/a through <= 2.4.5. | |
| Aplazada | Alta (7.5) | 0.62% | — | Moaluko Store LocatorAI | 24/1/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in moaluko Store Locator store-locator allows PHP Local File Inclusion.This issue affects Store Locator: from n/a through <= 3.98.10. | |
| Analizada | Media (6.1) | 0.35% | — | Nbubna Store | 23/1/2025 | 17/6/2026 | Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary code via the store.deep.js component | |
| Aplazada | Alta (7.6) | 0.83% | 💥 PoC | Storeapps Smart Manager FOR WP E CommerceAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce allows Blind SQL Injection.This issue affects Smart Manager: from n/a through <= 8.52.0. | |
| Aplazada | Media (4.3) | 0.17% | — | Silverplugins217 Build Private Store FOR WoocommerceAI | 15/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Build Private Store For Woocommerce build-private-store-for-woocommerce allows Cross Site Request Forgery.This issue affects Build Private Store For Woocommerce: from n/a through <= 1.0. | |
| Aplazada | Media (4.7) | 0.13% | — | Lenovo PC ManagerAILenovo BrowserAILenovo APP StoreAI | 14/1/2025 | 17/6/2026 | A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash. | |
| Aplazada | Media (4.7) | 0.12% | — | Lenovo PC ManagerAILenovo BrowserAILenovo APP StoreAI | 14/1/2025 | 17/6/2026 | A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash. | |
| Aplazada | Alta (7.1) | 0.32% | — | WP Scripts Food StoreAI | 13/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Scripts Food Store – Online Food Delivery & Pickup food-store allows Reflected XSS.This issue affects Food Store – Online Food Delivery & Pickup: from n/a through <= 1.5.4. | |
| Aplazada | Media (6.5) | 0.21% | — | Vfthemes StorepressAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vfthemes StorePress storepress allows DOM-Based XSS.This issue affects StorePress: from n/a through <= 1.0.12. | |
| Analizada | Media (5.1) | 0.49% | — | Donglight Bookstore | 9/1/2025 | 17/6/2026 | A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/AdminBookController. java. The manipulation of the argument pictureFile leads to unrestricted… | |
| Analizada | Media (5.3) | 0.41% | — | Donglight Bookstore | 9/1/2025 | 17/6/2026 | A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been rated as problematic. This issue affects the function updateUser of the file src/main/Java/org/zdd/bookstore/web/controller/admin/AdminUserControlle.java. The manipulation leads to cross site scripting. The attack may be initiated remotely.… | |
| Analizada | Media (5.3) | 0.31% | — | Donglight Bookstore | 9/1/2025 | 17/6/2026 | A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been declared as problematic. This vulnerability affects the function BookSearchList of the file src/main/java/org/zdd/bookstore/web/controller/BookInfoController.java. The manipulation of the argument keywords leads to cross site scripting. The… | |
| Analizada | Media (5.3) | 0.43% | — | Donglight Bookstore | 9/1/2025 | 17/6/2026 | A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been classified as critical. This affects the function getHtml of the file src/main/java/org/zdd/bookstore/rawl/HttpUtil.java. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack… | |
| Aplazada | Media (5.3) | 0.35% | — | Shopping Cart Ecommerce StoreAI | 8/1/2025 | 17/6/2026 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible for unauthenticated attackers to modify order statuses. | |
| Aplazada | Media (6.5) | 0.23% | — | Code Themes Digi StoreAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Code Themes Digi Store allows DOM-Based XSS.This issue affects Digi Store: from n/a through 1.1.4. | |
| Aplazada | Media (6.5) | 0.21% | — | Athemeart Store CommerceAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in athemeart Store Commerce store-commerce allows DOM-Based XSS.This issue affects Store Commerce: from n/a through <= 1.2.3. |