Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
201 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.61% | — | Paymentplugins Payment Plugins FOR StripeAI | 24/7/2026 | 24/7/2026 | The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary… | |
| Aplazada | Media (6.5) | 0.22% | — | Accept Donations With Paypal AND StripeAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. | |
| Aplazada | Media (5.4) | 0.26% | — | Silverstripe CMSAISilverstripe FrameworkAI | 1/7/2026 | 2/7/2026 | Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert media from web" functionality in the CMS is vulnerable to XSS from a specially crafted embed. This issue was fixed in version 6.2.2/ | |
| Aplazada | Alta (7.7) | 0.38% | — | PretixAIPretix MollieAIPretix OppwaAIPretix BitpayAI+5 | 1/7/2026 | 2/7/2026 | We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and… | |
| Aplazada | Media (5.3) | 0.56% | 💥 PoC | WP Full StripeAI | 27/6/2026 | 29/6/2026 | The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying update_failed_payment_status() function… | |
| Aplazada | Media (6.5) | 0.17% | — | Funnelkit Payment Gateway FOR Stripe WoocommerceAI | 26/6/2026 | 29/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions. | |
| Aplazada | Alta (8.2) | 0.32% | — | StripeAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions. | |
| Aplazada | Alta (8.2) | 0.34% | — | StripeAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions. | |
| Aplazada | Media (6.5) | 0.40% | — | Woocommerce Stripe Payment GatewayAI | 16/6/2026 | 17/6/2026 | The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment… | |
| Aplazada | Media (6.5) | 0.30% | — | Stripe PaymentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions. | |
| Aplazada | Media (6.5) | 0.42% | — | WP Full StripeAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions. | |
| Aplazada | Media (5.1) | 0.19% | — | Stripe PaymentsAI | 8/6/2026 | 27/8/2026 | WordPress Plugin Stripe Payments before 2.0.40 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script payloads in the… | |
| Aplazada | Media (5.5) | 0.29% | — | Stripe PluginAIBeikeshopAI | 7/6/2026 | 23/7/2026 | A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipulation of the argument Request results in improper authorization. The attack can… | |
| Aplazada | Media (6.4) | 0.33% | — | Express Payment FOR StripeAI | 6/6/2026 | 23/7/2026 | The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the [stripe-express] shortcode in versions up to, and including, 1.28.0. This is due to insufficient input sanitization and output escaping on the shortcode attribute value, which is… | |
| Aplazada | Media (5.3) | 0.25% | — | Contact Form 7 Paypal Stripe ADD ONAI | 29/5/2026 | 21/7/2026 | The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correctly validates IPN authenticity by posting back to PayPal with… | |
| Aplazada | Media (6.5) | 0.46% | — | Themehigh Stripe Payment Gateway FOR WoocommerceAI | 25/5/2026 | 24/7/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommerce allows Password Recovery Exploitation. This issue affects Stripe Payment Gateway for WooCommerce: from n/a through 5.0.7. | |
| Aplazada | Media (5.3) | 0.40% | — | Silverstripe Assets ModuleAISilverstripe FrameworkAI | 16/4/2026 | 17/6/2026 | The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which bypasses file… | |
| Aplazada | Baja (2.3) | 0.32% | — | Mickasmt Next-saas-stripe-starterAI | 22/3/2026 | 17/6/2026 | A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack… | |
| Aplazada | Media (5.3) | 0.34% | — | Mickasmt Next-saas-stripe-starterAI | 22/3/2026 | 17/6/2026 | A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the argument userId/role results in improper authorization. The attack may be launched remotely. | |
| Aplazada | Media (5.3) | 0.36% | — | Mickasmt Next-saas-stripe-starterAI | 22/3/2026 | 17/6/2026 | A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected is the function generateUserStripe of the file actions/generate-user-stripe.ts of the component Checkout Handler. The manipulation of the argument priceId leads to business logic errors. The attack may be initiated remotely. | |
| Aplazada | Media (6.4) | 0.29% | — | Payment Page Payment Form FOR StripeAI | 14/2/2026 | 17/6/2026 | The Payment Page | Payment Form for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pricing_plan_select_text_font_family' parameter in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.1) | 0.44% | — | Stripe Green DownloadsAI | 1/2/2026 | 17/6/2026 | Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote attackers to inject malicious scripts in button label fields. Attackers can exploit input parameters to execute arbitrary scripts, potentially leading to session hijacking and application module… | |
| Aplazada | Media (4.7) | 0.49% | 💥 Exploit | Scott Paterson Accept Donations With Paypal AND StripeAI | 24/12/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Phishing.This issue affects Accept Donations with PayPal & Stripe: from n/a through <= 1.5.2. | |
| Aplazada | Media (6.1) | 0.25% | — | Zealousweb Accept Stripe Payments Using Contact Form 7AI | 12/12/2025 | 30/9/2026 | The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failure_message' parameter in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (7.1) | 0.12% | — | Zipang Simple StripeAI | 6/11/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affects Simple Stripe: from n/a through <= 0.9.17. |