Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.33% | — | Inspireui Mstore API | 13/12/2024 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4 due to insufficient file type validation. This makes it possible for authenticated attackers, with… | |
| Aplazada | Baja (2.7) | 0.25% | — | Sigstore-pythonAI | 10/12/2024 | 17/6/2026 | sigstore-python is a Python tool for generating and verifying Sigstore signatures. Versions of sigstore-python newer than 2.0.0 but prior to 3.6.0 perform insufficient validation of the "integration time" present in "v2" and "v3" bundles during the verification flow: the "integration time" is verified *if* a source of… | |
| Aplazada | Media (4.3) | 0.39% | — | Dotstore Minimum AND Maximum Quantity FOR WoocommerceAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Dotstore Minimum and Maximum Quantity for WooCommerce min-and-max-quantity-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Minimum and Maximum Quantity for WooCommerce: from n/a through <= 2.0.0. | |
| Modificada | Crítica (9.8) | 1.0% | — | Shopfiles Ebook Store | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ebook Store: from n/a through 5.775. | |
| Aplazada | Crítica (9.8) | 23% | 💥 Exploit | WP Umbrella Update Backup Restore AND MonitoringAI | 8/12/2024 | 17/6/2026 | The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the… | |
| Aplazada | Media (6.1) | 0.29% | — | Next Cart Store TO Woocommerce MigrationAI | 6/12/2024 | 17/6/2026 | The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.1) | 0.15% | — | Clickbank StorefrontAI | 6/12/2024 | 17/6/2026 | The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing or incorrect nonce validation via the cs_menu page. This makes it possible for unauthenticated attackers to update settings and inject malicious… | |
| Aplazada | Baja (2.1) | 0.21% | — | Sigstore-javaAI | 5/12/2024 | 17/6/2026 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a bundle provides a invalid signature for a checkpoint. This bug impacts clients using any variation of KeylessVerifier.verify(). Currently checkpoints are only used… | |
| Aplazada | Alta (7.1) | 0.16% | — | Cmsaccount Photo Video StoreAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in cmsaccount Photo Video Store photo-video-store allows Cross-Site Scripting (XSS).This issue affects Photo Video Store: from n/a through <= 21.07. | |
| Aplazada | Alta (7.1) | 0.16% | — | Lriaudel Cpt-to-map-storeAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in lriaudel Custom Post Type to Map Store cpt-to-map-store allows Stored XSS.This issue affects Custom Post Type to Map Store: from n/a through <= 1.1.0. | |
| Aplazada | Media (5.5) | 0.10% | — | Sigstore-javaAI | 26/11/2024 | 17/6/2026 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a validly-signed but "mismatched" bundle is presented as proof of inclusion into a transparency log. This bug impacts clients using any variation of… | |
| Analizada | Media (6.9) | 0.36% | — | 1000projects Bookstore Management System | 25/11/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in 1000 Projects Bookstore Management System 1.0. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.9) | 0.85% | — | 1000projects Bookstore Management System | 21/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affected by this issue is some unknown functionality of the file /forget_password_process.php. The manipulation of the argument unm leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (6.5) | 0.46% | — | Inspireui Mstore API | 20/11/2024 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter in all versions up to, and including, 4.15.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (6.5) | 0.32% | — | Pierre Jego MAP Store LocatorAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Jégo Map Store Locator map-store-location allows DOM-Based XSS.This issue affects Map Store Locator: from n/a through <= 1.2.1. | |
| Aplazada | Media (6.5) | 0.39% | — | Sellerthemes StorelyAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sellerthemes Storely storely allows Stored XSS.This issue affects Storely: from n/a through <= 14.7. | |
| Aplazada | Alta (7.1) | 0.41% | — | Josh Kohlbach Jigoshop - Store ExporterAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Josh Kohlbach Jigoshop – Store Exporter jigoshop-exporter allows Reflected XSS.This issue affects Jigoshop – Store Exporter: from n/a through <= 1.5.8. | |
| Analizada | Media (6.9) | 0.64% | — | Code-projects Online Shop Store | 15/11/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in code-projects Online Shop Store 1.0. This affects an unknown part of the file /signup.php. The manipulation of the argument m2 with the input <svg%20onload=alert(document.cookie)> leads to cross site scripting. It is possible to initiate the attack remotely.… | |
| Aplazada | Media (6.1) | 0.35% | — | Online Shop StoreAI | 11/11/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component. | |
| Aplazada | Crítica (10) | 1.5% | 💥 PoC | Joshua Wolfe THE Novel Design Store DirectoryAI | 11/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upload a Web Shell to a Web Server.This issue affects The Novel Design Store Directory: from n/a through <= 4.3.0. | |
| Modificada | Media (5.4) | 0.24% | — | Mysticalthemes Meta Store Elements | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mystical Themes Meta Store Elements meta-store-elements allows DOM-Based XSS.This issue affects Meta Store Elements: from n/a through <= 1.0.9. | |
| Aplazada | Alta (7.1) | 0.27% | — | Michael Visser Jigoshop Store ToolkitAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Visser Jigoshop – Store Toolkit jigoshop-store-toolkit allows Reflected XSS.This issue affects Jigoshop – Store Toolkit: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Vietfriend Friendstore FOR WoocommerceAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VietFriend team FriendStore for WooCommerce friendstore-for-woocommerce allows Reflected XSS.This issue affects FriendStore for WooCommerce: from n/a through <= 1.4.2. | |
| Aplazada | Alta (8.8) | 1.2% | 💥 PoC | TOP StoreAI | 9/11/2024 | 17/6/2026 | The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Analizada | Media (6.9) | 0.70% | — | 1000projects Bookstore Management System | 8/11/2024 | 17/6/2026 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/process_category_add.php. The manipulation of the argument cat leads to sql injection. The attack may be initiated remotely. The exploit has been… |