Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.45% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 4/2/2025 | 17/6/2026 | woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF invoices & packing slips for WooCommerce orders. This vulnerability allows unauthorized users to access any PDF document from a store if they: 1. Have access to a guest document link and 2. Replace the… | |
| Aplazada | Media (6.4) | 0.27% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.1. | |
| Modificada | Media (4.8) | 0.36% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels print-invoices-packing-slip-labels-for-woocommerce allows Stored XSS.This issue affects WooCommerce PDF Invoices, Packing Slips,… | |
| Aplazada | Media (5.3) | 0.49% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.0. | |
| Aplazada | Media (6.1) | 0.43% | — | PDF Invoices AND Packing Slips Generator FOR WoocommerceAI | 23/11/2024 | 17/6/2026 | The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (5.3) | 0.41% | — | Wpovernight Woocommerce PDF Invoices Packing SlipsAI | 29/10/2024 | 17/6/2026 | Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-packing-slips allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoices & Packing Slips: from n/a through <= 3.8.6. | |
| Modificada | Alta (8.8) | 0.32% | — | Slicedinvoices Sliced Invoices | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Sliced Invoices.This issue affects Sliced Invoices: from n/a through 3.9.2. | |
| Analizada | Alta (7.2) | 0.64% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1. | |
| Modificada | Alta (7.2) | 0.40% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 2/5/2024 | 17/6/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.8.0 via the transform() function. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be… | |
| Modificada | Media (6.1) | 0.57% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 2/5/2024 | 17/6/2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (5.3) | 0.44% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 6/4/2024 | 17/6/2026 | The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wt_pklist_reset_settings() function in all versions up to, and including, 4.4.2. This makes it possible for unauthenticated… | |
| Modificada | Alta (8.8) | 0.55% | — | Acowebs PDF Invoices AND Packing Slips FOR Woocommerce | 28/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Acowebs PDF Invoices and Packing Slips For WooCommerce.This issue affects PDF Invoices and Packing Slips For WooCommerce: from n/a through 1.3.7. | |
| Modificada | Media (6.1) | 0.40% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Reflected XSS.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a… | |
| Modificada | Media (6.1) | 0.37% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 22/3/2024 | 17/6/2026 | The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Customer Notes field in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.97% | — | Acowebs PDF Invoices AND Packing Slips FOR Woocommerce | 7/3/2024 | 17/6/2026 | The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.7 via deserialization of untrusted input via the order_id parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Alta (7.2) | 0.58% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 27/1/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce.This issue affects PDF Invoices & Packing Slips for WooCommerce: from n/a through 3.7.5. | |
| Modificada | Media (6.5) | 0.38% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 3/1/2024 | 17/6/2026 | The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on theprint_packinglist action in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (7.5) | 0.87% | — | Kiwiz Invoices Certification & PDF System Project Kiwiz Invoices Certification & PDF System | 15/5/2023 | 17/6/2026 | The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server) | |
| Modificada | Media (4.3) | 0.23% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss. | |
| Modificada | Media (6.1) | 0.67% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 29/8/2022 | 17/6/2026 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters before outputting them back in an attributes of an admin page, leading to Reflected Cross-Site Scripting. | |
| Modificada | Media (6.1) | 0.81% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 11/7/2022 | 17/6/2026 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.16.0 doesn't escape a parameter on its setting page, making it possible for attackers to conduct reflected cross-site scripting attacks. | |
| Modificada | Media (4.8) | 1.2% | 💥 Exploit | Wpovernight Woocommerce PDF Invoices& Packing Slips | 3/1/2022 | 17/6/2026 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard | |
| Modificada | Media (4.8) | 0.62% | — | Webventures Client Invoicing BY Sprout Invoices | 17/11/2021 | 17/6/2026 | The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (5.4) | 0.72% | — | Softrade WP Smart CRM & Invoices | 14/9/2020 | 17/6/2026 | Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name field, Tax Code field, First Name field, Address field, Town field, Phone field, Mobile field, Place of Birth field, Web Site field, VAT Number field, Last Name field, Fax field, Email field, and… | |
| Modificada | Alta (7.5) | 1.7% | — | Slicedinvoices Sliced Invoices | 31/8/2020 | 17/6/2026 | Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php. |