Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

60 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.3)0.45%—Wpovernight Woocommerce PDF Invoices& Packing Slips4/2/202517/6/2026
woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF invoices & packing slips for WooCommerce orders. This vulnerability allows unauthorized users to access any PDF document from a store if they: 1. Have access to a guest document link and 2. Replace the…
AplazadaMedia (6.4)0.27%—Webventures Client Invoicing BY Sprout InvoicesAI27/1/202517/6/2026
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.1.
ModificadaMedia (4.8)0.36%—Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels24/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels print-invoices-packing-slip-labels-for-woocommerce allows Stored XSS.This issue affects WooCommerce PDF Invoices, Packing Slips,…
AplazadaMedia (5.3)0.49%—Webventures Client Invoicing BY Sprout InvoicesAI9/12/202417/6/2026
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.0.
AplazadaMedia (6.1)0.43%—PDF Invoices AND Packing Slips Generator FOR WoocommerceAI23/11/202417/6/2026
The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to inject arbitrary…
AplazadaMedia (5.3)0.41%—Wpovernight Woocommerce PDF Invoices Packing SlipsAI29/10/202417/6/2026
Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-packing-slips allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoices & Packing Slips: from n/a through <= 3.8.6.
ModificadaAlta (8.8)0.32%—Slicedinvoices Sliced Invoices9/6/202417/6/2026
Missing Authorization vulnerability in Sliced Invoices.This issue affects Sliced Invoices: from n/a through 3.9.2.
AnalizadaAlta (7.2)0.64%—Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels17/5/202417/6/2026
Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1.
ModificadaAlta (7.2)0.40%—Wpovernight Woocommerce PDF Invoices& Packing Slips2/5/202417/6/2026
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be…
ModificadaMedia (6.1)0.57%—Wpovernight Woocommerce PDF Invoices& Packing Slips2/5/202417/6/2026
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
ModificadaMedia (5.3)0.44%—Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels6/4/202417/6/2026
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wt_pklist_reset_settings() function in all versions up to, and including, 4.4.2. This makes it possible for unauthenticated…
ModificadaAlta (8.8)0.55%—Acowebs PDF Invoices AND Packing Slips FOR Woocommerce28/3/202417/6/2026
Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/a through 1.3.7.
ModificadaMedia (6.1)0.40%—Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Reflected XSS.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a…
ModificadaMedia (6.1)0.37%—Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels22/3/202417/6/2026
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Customer Notes field in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for…
ModificadaAlta (8.8)0.97%—Acowebs PDF Invoices AND Packing Slips FOR Woocommerce7/3/202417/6/2026
The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.7 via deserialization of untrusted input via the order_id parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
ModificadaAlta (7.2)0.58%—Wpovernight Woocommerce PDF Invoices& Packing Slips27/1/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce.This issue affects PDF Invoices & Packing Slips for WooCommerce: from n/a through 3.7.5.
ModificadaMedia (6.5)0.38%—Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels3/1/202417/6/2026
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on theprint_packinglist action in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with…
ModificadaAlta (7.5)0.87%—Kiwiz Invoices Certification & PDF System Project Kiwiz Invoices Certification & PDF System15/5/202317/6/2026
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)
ModificadaMedia (4.3)0.23%—Wpovernight Woocommerce PDF Invoices& Packing Slips1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.
ModificadaMedia (6.1)0.67%—Wpovernight Woocommerce PDF Invoices& Packing Slips29/8/202217/6/2026
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting.
ModificadaMedia (6.1)0.81%—Wpovernight Woocommerce PDF Invoices& Packing Slips11/7/202217/6/2026
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks.
ModificadaMedia (4.8)1.2%💥 ExploitWpovernight Woocommerce PDF Invoices& Packing Slips3/1/202217/6/2026
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard
ModificadaMedia (4.8)0.62%—Webventures Client Invoicing BY Sprout Invoices17/11/202117/6/2026
The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (5.4)0.72%—Softrade WP Smart CRM & Invoices14/9/202017/6/2026
Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name field, Tax Code field, First Name field, Address field, Town field, Phone field, Mobile field, Place of Birth field, Web Site field, VAT Number field, Last Name field, Fax field, Email field, and…
ModificadaAlta (7.5)1.7%—Slicedinvoices Sliced Invoices31/8/202017/6/2026
Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php.
Orbitaley — Vulnerabilidades