Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.36% | — | Oxid-esales Eshop | 13/5/2025 | 17/6/2026 | An issue was discovered in OXID eShop before 7. CMS pages in combination with Smarty may display user information if a CMS page contains a Smarty syntax error. | |
| Aplazada | Media (6.5) | 0.22% | — | Mythemeshop WP QuizAI | 25/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MyThemeShop WP Quiz wp-quiz allows Stored XSS.This issue affects WP Quiz: from n/a through <= 2.0.10. | |
| Aplazada | Media (6.1) | 0.34% | — | SoteshopAI | 28/2/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in Soteshop, versions prior to 8.3.4, which could allow remote attackers to execute arbitrary code via the ‘query’ parameter in /app-google-custom-search/searchResults. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform… | |
| Aplazada | Media (6.4) | 0.25% | — | Brodos Onlineshop PluginAI | 25/1/2025 | 17/6/2026 | The brodos.net Onlineshop Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'BrodosCategory' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.16% | — | Mythemeshop Schema LiteAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop Schema Lite allows Cross Site Request Forgery.This issue affects Schema Lite: from n/a through 1.2.2. | |
| Aplazada | Media (6.5) | 0.31% | — | Sonalsinha21 BicycleshopAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 Bicycleshop bicycleshop allows DOM-Based XSS.This issue affects Bicycleshop: from n/a through <= 1.5. | |
| Modificada | Baja (2.1) | 0.56% | — | Beikeshop | 26/8/2024 | 17/6/2026 | A vulnerability was identified in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This vulnerability affects the function exportZip of the file /admin/file_manager/export. Such manipulation of the argument path leads to path traversal. The attack can be launched remotely. The exploit is publicly available… | |
| Modificada | Baja (2.1) | 0.55% | — | Beikeshop | 26/8/2024 | 17/6/2026 | A vulnerability was determined in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. This affects the function rename of the file /Admin/Http/Controllers/FileManagerController.php. This manipulation of the argument new_name causes unrestricted upload. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Baja (2.1) | 0.84% | — | Beikeshop | 26/8/2024 | 17/6/2026 | A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.5.5. Affected by this issue is the function destroyFiles of the file /admin/file_manager/files. The manipulation of the argument files results in path traversal. It is possible to launch the attack remotely. The exploit has been made… | |
| Analizada | Media (5.3) | 0.38% | — | Likeshop | 7/8/2024 | 17/6/2026 | An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any arbitrary IP address, specifically by adding a forged 'X-Forwarded' or 'Client-IP' header to requests. Exploiting IP spoofing, attackers can bypass account lockout… | |
| Aplazada | Media (4.3) | 0.18% | — | Mythemeshop SociallyviralAI | 12/7/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop SociallyViral.This issue affects SociallyViral: from n/a through 1.0.10. | |
| Modificada | Media (4.8) | 0.40% | — | Mythemeshop URL Shortener | 9/7/2024 | 17/6/2026 | The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Aplazada | Media (6.3) | 0.29% | — | Buy-addons BagoogleshoppingAI | 19/6/2024 | 17/6/2026 | In the module "Bulk Export products to Google Merchant-Google Shopping" (bagoogleshopping) up to version 1.0.26 from Buy Addons for PrestaShop, a guest can perform SQL injection via`GenerateCategories::renderCategories(). | |
| Modificada | Media (5.1) | 0.35% | — | Likeshop | 8/6/2024 | 17/6/2026 | A vulnerability was found in Likeshop up to 2.5.7 and classified as problematic. This issue affects some unknown processing of the file /admin of the component Merchandise Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-267449 was assigned to this… | |
| Analizada | Alta (8.2) | 0.42% | — | Likeshop | 20/5/2024 | 17/6/2026 | SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function OrderLogic::getOrderList function, exploited at the /admin/order/lists.html endpoint. | |
| Aplazada | Media (4.3) | 0.58% | — | SimpleshopAI | 14/5/2024 | 17/6/2026 | The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.0. This is due to missing or incorrect nonce validation on the maybe_disconnect_simpleshop function. This makes it possible for unauthenticated attackers to disconnect the site from simpleshop via… | |
| Aplazada | Media (5.3) | 0.62% | — | SimpleshopAI | 14/5/2024 | 17/6/2026 | The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capability check on the maybe_disconnect_simpleshop function in all versions up to, and including, 2.10.2. This makes it possible for unauthenticated attackers to disconnect the SimpleShop. | |
| Analizada | Media (5.9) | 0.22% | — | Likeshop | 21/3/2024 | 17/6/2026 | Server Side Request Forgery (SSRF) vulnerability in Likeshop before 2.5.7 allows attackers to view sensitive information via the avatar parameter in function UserLogic::updateWechatInfo. | |
| Analizada | Alta (7.2) | 0.67% | — | Likeshop | 27/2/2024 | 17/6/2026 | SQL Injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function DistributionMemberLogic::getFansLists. | |
| Modificada | Alta (8.8) | 0.52% | — | Mythemeshop URL Shortener | 17/1/2024 | 17/6/2026 | Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0.17. | |
| Modificada | Crítica (9.8) | 73% | 💥 Exploit | Likeshop | 9/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in Likeshop up to 2.5.7.20210311. This vulnerability affects the function FileServer::userFormImage of the file server/application/api/controller/File.php of the component HTTP POST Request Handler. The manipulation of the argument file leads to unrestricted upload. The… | |
| Modificada | Alta (8.8) | 0.31% | — | Mythemeshop WP Shortcode | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop WP Shortcode by MyThemeShop plugin <= 1.4.16 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Mythemeshop URL Shortener | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MyThemeShop URL Shortener by MyThemeShop plugin <= 1.0.17 versions. | |
| Modificada | Media (5.3) | 0.42% | — | Oxid-esales Eshop | 2/8/2023 | 17/6/2026 | OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upload a file with a modified header to create a HTTP Response Splitting attack. | |
| Modificada | Media (5.4) | 0.36% | — | Oxidforge Oxid Eshop | 11/4/2023 | 17/6/2026 | OXID eShop 6.2.x before 6.4.4 and 6.5.x before 6.5.2 allows session hijacking, leading to partial access of a customer's account by an attacker, due to an improper check of the user agent. |