Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
133 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | A flaw has been found in PHPGurukul PHPGurukul Online Shopping Portal Project up to 2.1. Impacted is an unknown function of the file /pending-orders.php of the component Parameter Handler. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Media (5.5) | 0.59% | — | Adonesevangelista Agri-trading Online Shopping System | 21/2/2026 | 17/6/2026 | A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroller.php of the component HTTP POST Request Handler. Performing a manipulation of the argument Product results in sql injection. The attack may be initiated remotely. The… | |
| Analizada | Crítica (9.8) | 0.43% | 💥 PoC | Indieka900 Online Shopping System | 8/1/2026 | 17/6/2026 | indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter. | |
| Analizada | Alta (8.7) | 0.56% | — | Puneethreddyhc Online Shopping System Advanced | 12/12/2025 | 17/6/2026 | Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by… | |
| Analizada | Media (4.3) | 0.24% | — | Phpgurukul Online Shopping Portal | 25/11/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter. | |
| Analizada | Media (5.5) | 0.40% | — | Oretnom23 Online Shop Project | 20/11/2025 | 17/6/2026 | A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |
| Analizada | Baja (2) | 0.24% | — | Oretnom23 Online Shop Project | 20/11/2025 | 17/6/2026 | A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /shop/register.php. This manipulation of the argument f_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.40% | — | Oretnom23 Online Shop Project | 20/11/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument Password results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php. | |
| Analizada | Media (5.4) | 0.22% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php. | |
| Analizada | Crítica (9.8) | 0.41% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 28/9/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php. | |
| Aplazada | Alta (8.2) | 0.25% | — | Indieka900 Online-shopping-system-phpAI | 27/10/2025 | 17/6/2026 | indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in the password parameter of login.php. | |
| Modificada | Media (5.5) | 0.42% | — | Projectworlds Online Shopping System | 27/10/2025 | 17/6/2026 | A flaw has been found in projectworlds Online Shopping System 1.0. Impacted is an unknown function of the file /login_submit.php. Executing a manipulation of the argument keywords can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2) | 0.26% | — | Jimit105 Project-online-shopping-websiteAI | 12/10/2025 | 17/6/2026 | A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This affects an unknown function of the file /delete.php of the component Product Inventory Handler. This manipulation of the argument product_code causes sql injection. It is possible to initiate the… | |
| Aplazada | Crítica (9.8) | 0.33% | 💥 PoC | Puneethreddy Online Shopping System AdvancedAI | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The product_id GET parameter is unsafely passed to a SQL query without proper validation or parameterization. | |
| Analizada | Media (6.5) | 0.26% | — | Phpgurukul Online Shopping Portal Project | 2/10/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname parameter. | |
| Analizada | Media (5.5) | 0.48% | — | Projectworlds Online Shopping System | 27/9/2025 | 17/6/2026 | A vulnerability was identified in Projectworlds Online Shopping System 1.0. This affects an unknown part of the file /store/cart_add.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Analizada | Media (6.1) | 0.23% | — | Phpgurukul Online Shopping Portal | 12/9/2025 | 17/6/2026 | PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a product to the cart. | |
| Analizada | Media (5.4) | 0.21% | 💥 PoC | Phpgurukul Online Shopping Portal | 4/9/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php. | |
| Modificada | Crítica (9.1) | 0.47% | — | Phpgurukul Online Shopping Portal | 3/9/2025 | 17/6/2026 | phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation. | |
| Analizada | Media (5.5) | 0.56% | — | Campcodes Online Shopping System | 30/8/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Shopping System 1.0. Affected is an unknown function of the file /product.php. Performing manipulation of the argument p results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. |