Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.28% | — | Hasthemes Shoplentor | 25/4/2025 | 17/6/2026 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.1.2 via the woolentor_template_proxy function. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.5) | 0.53% | — | Wordpress Simple Shopping CartAI | 23/4/2025 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up to, and including, 5.1.2. This is due to a logic flaw involving the inconsistent use of parameters during the cart addition process. The plugin uses the parameter 'product_tmp_two' for computing a… | |
| Aplazada | Alta (8.2) | 0.40% | — | Wordpress Simple Shopping CartAI | 23/4/2025 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' parameter. This makes it possible for unauthenticated attackers to view potentially sensitive information and download a digital product without paying… | |
| Analizada | Media (5.3) | 0.53% | — | Oretnom23 Online Eyewear Shop | 19/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /oews/classes/Master.php?f=delete_stock. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Aplazada | Alta (7.1) | 0.29% | — | Shopup Shipping With Venipak FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Akadrama Shipping with Venipak for WooCommerce wc-venipak-shipping allows Reflected XSS.This issue affects Shipping with Venipak for WooCommerce: from n/a through <= 1.22.3. | |
| Analizada | Media (4.8) | 0.38% | — | Oretnom23 Online Eyewear Shop | 16/4/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (6.8) | 13% | 💥 Exploit | Shopware | 15/4/2025 | 17/6/2026 | Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression. | |
| Aplazada | Alta (7.5) | 0.92% | — | Trusty Plugins Shop Products FilterAI | 11/4/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Trusty Plugins Shop Products Filter trusty-woo-products-filter allows PHP Local File Inclusion.This issue affects Shop Products Filter: from n/a through <= 1.2. | |
| Aplazada | Crítica (9.6) | 0.26% | — | Wpshop WP ShopAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Agence web Eoxia - Montpellier WP shop wpshop allows Upload a Web Shell to a Web Server.This issue affects WP shop: from n/a through <= 2.6.1. | |
| Analizada | Media (6.9) | 0.30% | — | Shopware | 9/4/2025 | 17/6/2026 | Shopware is an open source e-commerce software platform. Prior to 6.6.10.3 or 6.5.8.17, the default settings for double-opt-in allow for mass unsolicited newsletter sign-ups without confirmation. Default settings are Newsletter: Double Opt-in set to active, Newsletter: Double opt-in for registered customers set to… | |
| Analizada | Alta (7.8) | 0.41% | — | Adobe Photoshop | 8/4/2025 | 17/6/2026 | Photoshop Desktop versions 25.12.1, 26.4.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.5) | 0.41% | — | Shopware | 8/4/2025 | 17/6/2026 | Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in Storefront forms or Store-API. This vulnerability is fixed in 6.6.10.3 or 6.5.8.17. For older versions of 6.4, corresponding security measures are also available via a plugin. For the full range of… | |
| Analizada | Media (5.5) | 0.39% | — | Shopware | 8/4/2025 | 17/6/2026 | Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Through the store-api it is possible as a attacker to check if a specific e-mail address has an account in the shop. Using the store-api endpoint /store-api/account/recovery-password you get the response, which indicates clearly that there is… | |
| Analizada | Media (5.5) | 0.30% | — | Localshop Webservice\ | 5/4/2025 | 17/6/2026 | WebService::Xero 0.11 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically WebService::Xero uses the Data::Random library which specifically states that it is "Useful mostly for test programs". Data::Random uses… | |
| Analizada | Media (5.3) | 0.41% | — | Oretnom23 Online Eyewear Shop | 5/4/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Registration Handler. The manipulation of the argument email leads to improper access… | |
| Analizada | Media (5.1) | 0.42% | — | Oretnom23 Online Eyewear Shop | 5/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_product. The manipulation of the argument brand leads to cross site scripting. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.40% | — | Oretnom23 Online Eyewear Shop | 5/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=delete_customer. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Aplazada | Media (4.3) | 0.43% | — | Anzar Ahmed Display Product Variations Dropdown ON Shop PageAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Anzar Ahmed Display product variations dropdown on shop page display-product-variations-dropdown-on-shop-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Display product variations dropdown on shop page: from n/a through <= 1.1.3. | |
| Aplazada | Media (6.5) | 0.40% | — | Ecwid Shopping CartAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Stored XSS.This issue affects Ecwid Shopping Cart: from n/a through <= 7.0. | |
| Aplazada | Alta (7.1) | 0.24% | — | Wpshopee Awesome LogosAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpshopee Awesome Logos awesome-logos allows Reflected XSS.This issue affects Awesome Logos: from n/a through <= 1.2. | |
| Aplazada | Media (6.5) | 0.38% | — | Plugin-devs Shopify TO Woocommerce MigrationAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Plugin Devs Shopify to WooCommerce Migration migrate-shopify-to-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shopify to WooCommerce Migration: from n/a through <= 1.3.0. | |
| Aplazada | Crítica (9.8) | 31% | 💥 Exploit | Vipshop SaturnAI | 2/4/2025 | 17/6/2026 | SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via /console/dashboard/executorCount?zkClusterKey component. | |
| Aplazada | Alta (8.8) | 0.40% | — | Shopper Approved ReviewsAI | 2/4/2025 | 17/6/2026 | The Shopper Approved Reviews plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the ajax_callback_update_sa_option() function in versions 2.0 to 2.1. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Crítica (9.3) | 0.49% | — | Shopperdotcom ShopperAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shopperdotcom Shopper shopper allows SQL Injection.This issue affects Shopper: from n/a through <= 3.2.5. | |
| Aplazada | Media (6.5) | 0.36% | — | Devscred ShopcredAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devscred ShopCred shopcred allows DOM-Based XSS.This issue affects ShopCred: from n/a through <= 1.3.0. |