Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been made public and… | |
| Aplazada | Media (4.3) | 0.27% | — | Shoppable Images LiteAI | 26/6/2026 | 26/6/2026 | Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Fabian Simple Shopping CartAI | 15/6/2026 | 17/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions. | |
| Aplazada | Media (6.5) | 0.31% | — | ShopperAI | 29/5/2026 | 22/7/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, disable, edit, delete) that were rendered for any authenticated panel user without checking the corresponding per-action permission. A… | |
| Aplazada | Crítica (9.9) | 0.42% | — | ShopperAI | 29/5/2026 | 22/7/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any authenticated user could load the page and use its public actions to create new… | |
| Aplazada | Media (6.5) | 0.31% | — | ShopperAI | 29/5/2026 | 22/7/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() method. Any authenticated panel user, regardless of role, could mutate any product's pricing, stock, SEO metadata, shipping… | |
| Aplazada | Media (5.9) | 0.31% | — | ShopperAI | 29/5/2026 | 22/7/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Under concurrent checkout pressure (Black Friday, flash sale, viral coupon), the global usage_limit was silently exceeded:… | |
| Aplazada | Alta (8.1) | 0.36% | — | ShopperAI | 29/5/2026 | 22/7/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orders. The order detail actions cancel, mark paid, mark complete, capture payment,… | |
| Aplazada | Baja (1.9) | 0.35% | — | Sourcecodester SUP Online ShoppingAI | 24/5/2026 | 23/7/2026 | A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The manipulation of the argument productName leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester SUP Online ShoppingAI | 8/5/2026 | 17/6/2026 | A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the file /admin/replymsg.php. The manipulation of the argument msgid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester SUP Online ShoppingAI | 8/5/2026 | 17/6/2026 | A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /admin/message.php. The manipulation of the argument seenid leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester SUP Online ShoppingAI | 8/5/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file wishlist.php. Executing a manipulation of the argument delwlistid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester SUP Online ShoppingAI | 8/5/2026 | 17/6/2026 | A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the file /admin/viewmsg.php. Performing a manipulation of the argument msgid results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be… | |
| Aplazada | Alta (8.4) | 0.56% | — | Codethat ShoppingcartAI | 15/4/2026 | 17/6/2026 | Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field | |
| Aplazada | Media (5.1) | 0.19% | — | Joomla VirtuemartAIVirtuemart Shopping CartAI | 9/4/2026 | 26/9/2026 | Joomla VirtueMart Shopping-Cart 4.0.12 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the keyword parameter. Attackers can craft malicious URLs containing script payloads in the keyword parameter of the product-variants endpoint to execute… | |
| Aplazada | Baja (2.9) | 0.28% | 💥 PoC | Meesho Online Shopping APPAI | 6/4/2026 | 24/7/2026 | A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation leads to risky cryptographic algorithm. The attack may be performed from remote. The attack requires a high level of… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function of the file /admin/update-image1.php of the component Parameter Handler. The manipulation of the argument filename results in sql injection. The attack may be performed from remote. The exploit has… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried out remotely. The… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 17/6/2026 | A flaw has been found in PHPGurukul Online Shopping Portal Project 2.1. Impacted is an unknown function of the file /admin/update-image3.php of the component Parameter Handler. Executing a manipulation of the argument filename can lead to sql injection. The attack can be executed remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 24/7/2026 | A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /cancelorder.php of the component Parameter Handler. This manipulation of the argument oid causes sql injection. The attack may be initiated remotely. The exploit has been made available to the… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 24/7/2026 | A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. Affected by this issue is some unknown functionality of the file /categorywise-products.php of the component Parameter Handler. The manipulation of the argument cid results in sql injection. The attack can be launched remotely. The… | |
| Aplazada | Media (5.3) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 6/4/2026 | 24/7/2026 | A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /order-details.php of the component Parameter Handler. The manipulation of the argument orderid results in sql injection. It is possible to launch the attack remotely. | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | A security vulnerability has been detected in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /my-profile.php of the component Parameter Handler. The manipulation of the argument fullname leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | A vulnerability was found in PHPGurukul Online Shopping Portal Project 2.1. The impacted element is an unknown function of the file /payment-method.php of the component Parameter Handler. Performing a manipulation of the argument paymethod results in sql injection. It is possible to initiate the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | A flaw has been found in PHPGurukul PHPGurukul Online Shopping Portal Project up to 2.1. Impacted is an unknown function of the file /pending-orders.php of the component Parameter Handler. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been… |