Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

257 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.8)0.83%—Kirilkirkov Ecommerce-codeigniter-bootstrapAI4/7/20266/7/2026
A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affected element is the function getCartItems in the library application/libraries/ShoppingCart.php. The manipulation of the argument shopping_cart leads to deserialization. The…
AplazadaMedia (5.3)0.48%—Kirilkirkov Ecommerce-codeigniter-bootstrapAI4/7/20266/7/2026
A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. Impacted is the function do_upload_others_images of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Image Manager. Executing a manipulation of the…
AplazadaMedia (5.5)0.62%—Kirilkirkov Ecommerce Codeigniter BootstrapAI4/7/20266/7/2026
A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. This issue affects some unknown processing of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Multi-Image Endpoint. Performing a manipulation of the…
AplazadaBaja (2.1)0.49%—Kirilkirkov Ecommerce Codeigniter BootstrapAI4/7/20266/7/2026
A vulnerability was identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails Admin Page. Such manipulation of the argument…
AplazadaBaja (2.1)0.49%—Kirilkirkov Ecommerce-codeigniter-bootstrapAI4/7/20267/7/2026
A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API Endpoint. This manipulation of the argument title/description causes cross site scripting.…
AplazadaBaja (2.1)0.46%—Kirilkirkov Ecommerce-codeigniter-bootstrapAI4/7/20266/7/2026
A vulnerability was found in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 95dfa8cebbb87ab46ae450643a07241274a74dce. Affected by this issue is the function setReferrer of the file application/core/MY_Controller.php of the component Trusted Backend Interface. The manipulation of the argument href results in open…
AplazadaAlta (7.1)0.25%—Implecode Ecommerce Product CatalogAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions.
AplazadaCrítica (9.9)0.48%—Ecommerce ZoneAI17/6/202617/6/2026
Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.
AplazadaCrítica (9.3)0.40%—Implecode Ecommerce Product CatalogAI15/6/202617/6/2026
Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.
AplazadaCrítica (9.8)0.54%—Datalogics Ecommerce DeliveryAI15/6/202617/6/2026
Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.
AplazadaBaja (2.1)0.23%—Sourcecodester Pizzafy Ecommerce SystemAI2/6/202622/7/2026
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation of the argument page can lead to file inclusion. The attack may be performed from remote. The exploit has been published and may be used.
AplazadaBaja (2.1)0.23%—Sourcecodester Pizzafy Ecommerce SystemAI2/6/202622/7/2026
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument page results in file inclusion. The attack is possible to be carried out remotely. The exploit is now public and may be used.
AplazadaAlta (7.1)0.18%—Jthemes Themebox - Digital Products EcommerceAI27/5/202630/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jthemes Themebox - Digital Products Ecommerce allows Reflected XSS. This issue affects Themebox - Digital Products Ecommerce: from n/a through 1.4.2.
AplazadaCrítica (9.3)0.25%—Ecommerce SystempayAI13/5/202617/6/2026
Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. Attackers can extract payment form data and signatures from POST requests to the payment endpoint, then use SHA1 hash…
AplazadaMedia (5.1)0.44%—Cradle EcommerceAI11/5/202617/6/2026
Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /product/. Exploitation of this vulnerability would allow an attacker to execute arbitrary JavaScript code.
AplazadaMedia (5.1)0.44%—Cradle EcommerceAI11/5/202617/6/2026
Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input is insecurely reflected in the HTML output in the endpoint /collection/. Exploitation of this vulnerability would allow an attacker to execute arbitrary JavaScript code.
AplazadaMedia (5.3)0.44%—Cradle Ecommerce PlatformAI8/5/202617/6/2026
Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The vulnerability occurs in the login form endpoint, where the ‘returnUrl’ parameter allows redirection because the web application accepts a URL as a parameter without properly validating it. As a result, it is possible to…
AplazadaBaja (2.1)0.45%—Sourcecodester Pizzafy Ecommerce SystemAI8/5/202617/6/2026
A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects some unknown processing of the file /admin/index.php. Such manipulation of the argument page leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may…
AplazadaMedia (6.1)0.36%—Andrewtch88 Mvc-ecommerceAI30/4/202617/6/2026
Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the product_catalogue.php component
AplazadaBaja (2.1)0.32%—Sourcecodester Pizzafy Ecommerce SystemAI29/4/202617/6/2026
A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may…
AplazadaBaja (2)0.33%—Sourcecodester Pizzafy Ecommerce SystemAI29/4/202617/6/2026
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
AplazadaBaja (2)0.33%—Sourcecodester Pizzafy Ecommerce SystemAI29/4/202617/6/2026
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Performing a manipulation results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
AplazadaBaja (2)0.33%—Sourcecodester Pizzafy Ecommerce SystemAI29/4/202617/6/2026
A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save_settings of the component Setting Handler. Such manipulation leads to sql injection. It is possible to launch the…
AplazadaBaja (2)0.33%💥 PoCSourcecodester Pizzafy Ecommerce SystemAI29/4/202617/6/2026
A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the component GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from…
AplazadaBaja (2)0.38%💥 PoCSourcecodester Pizzafy Ecommerce SystemAI29/4/202617/6/2026
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img results in unrestricted upload. The attack is possible to be carried out remotely.…
Orbitaley — Vulnerabilidades