Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3237 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.48%—Kirilkirkov Ecommerce-codeigniter-bootstrapAI4/7/20266/7/2026
A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. Impacted is the function do_upload_others_images of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Image Manager. Executing a manipulation of the…
AplazadaMedia (5.5)0.62%—Kirilkirkov Ecommerce Codeigniter BootstrapAI4/7/20266/7/2026
A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. This issue affects some unknown processing of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Multi-Image Endpoint. Performing a manipulation of the…
AplazadaBaja (2.1)0.49%—Kirilkirkov Ecommerce Codeigniter BootstrapAI4/7/20266/7/2026
A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails Admin Page. Such manipulation of the argument…
AplazadaBaja (2.1)0.49%—Kirilkirkov Ecommerce-codeigniter-bootstrapAI4/7/20267/7/2026
A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API Endpoint. This manipulation of the argument title/description causes cross site scripting.…
AplazadaBaja (2.1)0.46%—Kirilkirkov Ecommerce-codeigniter-bootstrapAI4/7/20266/7/2026
A vulnerability was found in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 95dfa8cebbb87ab46ae450643a07241274a74dce. Affected by this issue is the function setReferrer of the file application/core/MY_Controller.php of the component Trusted Backend Interface. The manipulation of the argument href results in open…
AplazadaAlta (7.5)0.68%—AR FOR WoocommerceAI3/7/20266/7/2026
The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The three…
AplazadaMedia (5.3)0.33%—KIT FOR WoocommerceAI2/7/20262/7/2026
Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.
AplazadaAlta (7.1)0.25%—Implecode Ecommerce Product CatalogAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions.
AplazadaAlta (7.1)0.25%—Customize MY Account FOR WoocommerceAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions.
AplazadaAlta (7.1)0.25%—Mildainc MC Woocommerce WishlistAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.
AplazadaMedia (6.5)0.44%—Addify TAX Exempt FOR WoocommerceAI2/7/202628/7/2026
Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5.
AplazadaAlta (7.5)0.35%—Nowpayments FOR WoocommerceAI2/7/20262/7/2026
Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
AplazadaMedia (4.4)0.34%💥 PoCProduct Video Gallery FOR WoocommerceAI2/7/20262/7/2026
The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_thumbnail Parameter in all versions up to, and including, 1.5.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with shop…
AplazadaMedia (4.3)0.39%—Envothemes Templates Widgets FOR Elementor AND WoocommerceAI2/7/20262/7/2026
The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the Envo Tabs (and Off Canvas) widget's template rendering in versions up to, and including, 1.4.26. The render() method of the Tabs widget passes a…
AplazadaAlta (7.5)0.46%—Product Configurator FOR WoocommerceAI1/7/20261/7/2026
The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status check before returning WooCommerce product data through a public AJAX action, allowing unauthenticated users to retrieve the data (title, price, weight, stock status, and configurator option…
AplazadaAlta (7.2)0.43%—Algoritmika Custom Payment Gateways FOR WoocommerceAI1/7/20261/7/2026
The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alg_wc_cpg_input_fields' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
AplazadaMedia (6.5)0.33%—Colissimo Officiel Methodes DE Livraison Pour WoocommerceAI29/6/20261/7/2026
Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.
AplazadaMedia (6.5)0.33%—Artisanworkshop Japanized FOR WoocommerceAI29/6/202629/6/2026
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
AplazadaAlta (7.1)0.34%—Wpswings Wallet System FOR WoocommerceAI29/6/202629/6/2026
Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
AplazadaMedia (6.5)0.22%—Woocommerce Designer PROAI29/6/20261/7/2026
Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions.
AplazadaMedia (4.3)0.37%—Product Specifications FOR WoocommerceAI27/6/202629/6/2026
The Product Specifications for WooCommerce plugin for WordPress is vulnerable to unauthorized modification, creation, and deletion of data in versions up to and including 0.8.9. This is due to a missing capability check and missing nonce verification in the __invoke() methods of the AttributeGroupController and…
AplazadaMedia (4.3)0.29%—Bopo Woocommerce Product Bundle BuilderAI26/6/202626/6/2026
Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.
AplazadaMedia (4.3)0.14%—Flycart Abandoned Cart Lite FOR WoocommerceAI26/6/202626/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
AplazadaMedia (6.5)0.17%—Funnelkit Payment Gateway FOR Stripe WoocommerceAI26/6/202629/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions.
AplazadaMedia (5.4)0.29%—Omnisend Email Marketing FOR WoocommerceAI26/6/202626/6/2026
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.