Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

201 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.61%—Paymentplugins Payment Plugins FOR StripeAI24/7/202624/7/2026
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary…
AplazadaMedia (6.5)0.22%—Accept Donations With Paypal AND StripeAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.
AplazadaMedia (5.4)0.26%—Silverstripe CMSAISilverstripe FrameworkAI1/7/20262/7/2026
Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert media from web" functionality in the CMS is vulnerable to XSS from a specially crafted embed. This issue was fixed in version 6.2.2/
AplazadaAlta (7.7)0.38%—PretixAIPretix MollieAIPretix OppwaAIPretix BitpayAI+51/7/20262/7/2026
We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and…
AplazadaMedia (5.3)0.56%💥 PoCWP Full StripeAI27/6/202629/6/2026
The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is registered through both wp_ajax_ and wp_ajax_nopriv_ hooks and the underlying update_failed_payment_status() function…
AplazadaMedia (6.5)0.17%—Funnelkit Payment Gateway FOR Stripe WoocommerceAI26/6/202629/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions.
AplazadaAlta (8.2)0.32%—StripeAI17/6/202617/6/2026
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions.
AplazadaAlta (8.2)0.34%—StripeAI17/6/202617/6/2026
Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.
AplazadaMedia (6.5)0.40%—Woocommerce Stripe Payment GatewayAI16/6/202617/6/2026
The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment…
AplazadaMedia (6.5)0.30%—Stripe PaymentsAI15/6/202617/6/2026
Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions.
AplazadaMedia (6.5)0.42%—WP Full StripeAI15/6/202617/6/2026
Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions.
AplazadaMedia (5.1)0.19%—Stripe PaymentsAI8/6/202627/8/2026
WordPress Plugin Stripe Payments before 2.0.40 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the AcceptStripePayments-settings[currency_code] parameter. Attackers can submit POST requests to /wp-admin/options.php with script payloads in the…
AplazadaMedia (5.5)0.29%—Stripe PluginAIBeikeshopAI7/6/202623/7/2026
A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipulation of the argument Request results in improper authorization. The attack can…
AplazadaMedia (6.4)0.33%—Express Payment FOR StripeAI6/6/202623/7/2026
The Express Payment For Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the [stripe-express] shortcode in versions up to, and including, 1.28.0. This is due to insufficient input sanitization and output escaping on the shortcode attribute value, which is…
AplazadaMedia (5.3)0.25%—Contact Form 7 Paypal Stripe ADD ONAI29/5/202621/7/2026
The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, and including, 2.4.9. Although `cf7pp_paypal_ipn_handler()` correctly validates IPN authenticity by posting back to PayPal with…
AplazadaMedia (6.5)0.46%—Themehigh Stripe Payment Gateway FOR WoocommerceAI25/5/202624/7/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommerce allows Password Recovery Exploitation. This issue affects Stripe Payment Gateway for WooCommerce: from n/a through 5.0.7.
AplazadaMedia (5.3)0.40%—Silverstripe Assets ModuleAISilverstripe FrameworkAI16/4/202617/6/2026
The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or otherwise accessed via DBFile::getURL() or DBFile::getSourceURL() incorrectly add an access grant to the current session, which bypasses file…
AplazadaBaja (2.3)0.32%—Mickasmt Next-saas-stripe-starterAI22/3/202617/6/2026
A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack…
AplazadaMedia (5.3)0.34%—Mickasmt Next-saas-stripe-starterAI22/3/202617/6/2026
A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the argument userId/role results in improper authorization. The attack may be launched remotely.
AplazadaMedia (5.3)0.36%—Mickasmt Next-saas-stripe-starterAI22/3/202617/6/2026
A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected is the function generateUserStripe of the file actions/generate-user-stripe.ts of the component Checkout Handler. The manipulation of the argument priceId leads to business logic errors. The attack may be initiated remotely.
AplazadaMedia (6.4)0.29%—Payment Page Payment Form FOR StripeAI14/2/202617/6/2026
The Payment Page | Payment Form for Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pricing_plan_select_text_font_family' parameter in all versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaMedia (5.1)0.44%—Stripe Green DownloadsAI1/2/202617/6/2026
Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote attackers to inject malicious scripts in button label fields. Attackers can exploit input parameters to execute arbitrary scripts, potentially leading to session hijacking and application module…
AplazadaMedia (4.7)0.49%💥 ExploitScott Paterson Accept Donations With Paypal AND StripeAI24/12/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Phishing.This issue affects Accept Donations with PayPal & Stripe: from n/a through <= 1.5.2.
AplazadaMedia (6.1)0.25%—Zealousweb Accept Stripe Payments Using Contact Form 7AI12/12/202530/9/2026
The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failure_message' parameter in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaAlta (7.1)0.12%—Zipang Simple StripeAI6/11/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affects Simple Stripe: from n/a through <= 0.9.17.
Orbitaley — Vulnerabilidades