Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.37% | — | SolidinvoiceAI | 4/9/2026 | 10/9/2026 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credentials to be recorded in server access logs, proxy logs, browser history, and HTTP… | |
| Aplazada | Media (6.8) | 0.32% | — | SolidinvoiceAI | 4/9/2026 | 10/9/2026 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning a leaked, forwarded, or archived invitation email can be used at any time in the future to join a company or silently add a… | |
| Aplazada | Baja (2.1) | 0.35% | — | Invoiceninja Invoice NinjaAI | 1/9/2026 | 2/9/2026 | A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/Pdf/Purify.php of the component invoices Endpoint. The manipulation of the argument notes leads to server-side request forgery. It is possible to… | |
| Aplazada | Baja (2.1) | 0.38% | — | Invoiceninja Invoice NinjaAI | 1/9/2026 | 1/9/2026 | A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile Update. Executing a manipulation of the argument vendor_contact can lead to authorization bypass. The attack may be performed from remote. The… | |
| Aplazada | Media (6.5) | 0.87% | — | Webtoffee Woocommerce PDF Invoices Packing Slips Delivery Notes Shipping LabelsAI | 23/8/2026 | 24/8/2026 | The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Alta (8.7) | 0.35% | — | InvoiceninjaAILaravelAI | 5/8/2026 | 26/8/2026 | InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization. | |
| Aplazada | Alta (7.2) | 0.27% | — | Peprodev Ultimate InvoiceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Peprodev Ultimate InvoiceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | Peprodev Ultimate InvoiceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | Peprodev Ultimate InvoiceAI | 23/7/2026 | 23/7/2026 | Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.13. | |
| Aplazada | Media (6.5) | 0.37% | — | Edgarrojas Woo-pdf-invoice-builderAI | 13/7/2026 | 21/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8. | |
| Aplazada | Media (4.3) | 0.39% | — | Wpdesk PDF Invoices Packing Slips FOR WoocommerceAI | 11/7/2026 | 13/7/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.14.0 via the generate_document_shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.47% | — | Invoice123AI | 10/7/2026 | 10/7/2026 | The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Media (5.3) | 0.52% | — | Easy InvoiceAI | 9/7/2026 | 9/7/2026 | The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin registering the easy_invoice_accept_quote and easy_invoice_decline_quote AJAX actions via wp_ajax_nopriv_ hooks and relying solely on a quote-scoped nonce that is rendered… | |
| Aplazada | Media (5.3) | 0.29% | — | Invoiceninja Invoice NinjaAI | 30/6/2026 | 14/7/2026 | Invoice Ninja through 5.13.26 contains an open redirect vulnerability in the client portal login that allows unauthenticated attackers to redirect authenticated victims to attacker-controlled external URLs by injecting a malicious value into the intended query parameter. Attackers can craft a client login link with an… | |
| Aplazada | Crítica (9.8) | 0.80% | 💥 PoC | Invoice GeneratorAI | 27/6/2026 | 29/6/2026 | The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account() AJAX action in versions up to, and including, 1.0.0. The handler is exposed via wp_ajax_nopriv_pravel_invoice_edit_account, accepts an attacker-controlled user_id and… | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpfactory Print Invoice AND Delivery Notes FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions. | |
| Aplazada | Crítica (9.8) | 0.67% | 💥 PoC | Invoice GeneratorAI | 24/6/2026 | 25/6/2026 | The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due to the `pravel_invoice_change_password()` function being registered as a nopriv AJAX handler with no nonce verification and no authorization check, and performing a… | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpcloud Woocommerce PDF Invoices Packing Slips Delivery Notes AND Shipping LabelsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions. | |
| Aplazada | Crítica (10) | 0.86% | — | Easy InvoiceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Wpdesk Woocommerce PDF Invoices Packing SlipsAI | 15/6/2026 | 17/6/2026 | Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions. | |
| Aplazada | Crítica (10) | 0.56% | — | Rednao Woocommerce PDF Invoice BuilderAI | 15/6/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8. | |
| Aplazada | Alta (7.1) | 0.23% | — | Slicedinvoices Sliced InvoicesAI | 15/6/2026 | 17/6/2026 | WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send requests to the admin.php endpoint with action=duplicate_quote_invoice and malicious 'post'… | |
| Aplazada | Alta (8.1) | 0.27% | — | SolidinvoiceAI | 11/6/2026 | 17/6/2026 | SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database — through SQL injection, a leaked backup, a misconfigured replica, or… |