Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.16% | — | Wpfactory Wishlist FOR WoocommerceAI | 6/1/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Stored XSS.This issue affects Wishlist for WooCommerce: from n/a through <= 3.3.0. | |
| Aplazada | Media (6.4) | 0.23% | — | Hasthemes WishsuiteAI | 21/12/2025 | 17/6/2026 | The WishSuite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' parameter of the 'wishsuite_button' shortcode in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.27% | — | Templateinvaders TI Woocommerce WishlistAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.10.0. | |
| Aplazada | Media (5.3) | 0.42% | — | Templateinvaders TI Woocommerce WishlistAI | 13/12/2025 | 17/6/2026 | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 2.10.0. This is due to the plugin accepting hidden fields and not limiting the values or data that can input and is later output. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (5.3) | 0.34% | — | Premmerce Wishlist FOR WoocommerceAI | 12/12/2025 | 30/9/2026 | The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.10. This is due to a missing capability check on the deleteWishlist() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (5.3) | 0.26% | — | Qode Wishlist FOR WoocommerceAI | 27/11/2025 | 17/6/2026 | The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the 'qode_wishlist_for_woocommerce_wishlist_table_item_callback' function due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.24% | — | Wpfactory Wishlist FOR WoocommerceAI | 25/11/2025 | 17/6/2026 | The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.3 via several functions in class-th-wishlist-frontend.php due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to modify… | |
| Analizada | Media (6.1) | 0.19% | 💥 PoC | Swi-prolog Swish | 20/11/2025 | 17/6/2026 | Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code via crafted web IDE notebook. | |
| Aplazada | Media (5.3) | 0.31% | — | Yithemes Yith Woocommerce WishlistAI | 19/11/2025 | 17/6/2026 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to the plugin not properly verifying that a user is authorized to perform actions on the REST API /wp-json/yith/wishlist/v1/lists endpoint (which uses permission_callback… | |
| Aplazada | Media (5.3) | 0.28% | — | Yithemes Yith Woocommerce WishlistAI | 19/11/2025 | 17/6/2026 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via the REST API endpoint and AJAX handler due to missing validation on user-controlled keys. This makes it possible for unauthenticated attackers to discover any user's… | |
| Aplazada | Media (4.3) | 0.19% | — | Wishlist AND Save FOR Later FOR WoocommerceAI | 12/11/2025 | 17/6/2026 | The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.22 via the 'awwlm_remove_added_wishlist_page' AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Aplazada | Alta (7.5) | 0.43% | — | Premmerce WishlistAI | 6/11/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Wishlist for WooCommerce premmerce-woocommerce-wishlist allows PHP Local File Inclusion.This issue affects Premmerce Wishlist for WooCommerce: from n/a through <= 1.1.10. | |
| Aplazada | Media (4.3) | 0.28% | — | Wpclever WPC Smart WishlistAI | 18/10/2025 | 17/6/2026 | The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'wishlist_quickview' AJAX action in all versions up to, and including, 5.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (5.3) | 0.23% | — | Wpclever WPC Smart WishlistAI | 11/10/2025 | 17/6/2026 | The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via several wishlist AJAX functions due to missing validation on a user controlled key that is exposed when wishlists are shared. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.28% | — | Templateinvaders TI Woocommerce WishlistAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.10.0. | |
| Aplazada | Media (6.5) | 0.27% | — | Wpfactory Wishlist FOR WoocommerceAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wishlist for WooCommerce: from n/a through <= 3.2.3. | |
| Aplazada | Media (6.4) | 0.29% | — | Yithemes Yith Woocommerce WishlistAI | 14/6/2025 | 17/6/2026 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Alta (7.1) | 0.28% | — | Moreconvert MC Woocommerce WishlistAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert allows Reflected XSS.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.9.1. | |
| Aplazada | Alta (7.1) | 0.28% | — | Redqteam WishlistAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in redqteam Wishlist wishlist allows Reflected XSS.This issue affects Wishlist: from n/a through <= 2.1.0. | |
| Aplazada | Media (6.5) | 0.20% | — | Pickplugins WishlistAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Wishlist wishlist allows Stored XSS.This issue affects Wishlist: from n/a through <= 1.0.43. | |
| Aplazada | Crítica (10) | 4.6% | 💥 Exploit | Templateinvaders TI Woocommerce WishlistAI | 19/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Upload a Web Shell to a Web Server.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.9.2. | |
| Aplazada | Media (6.5) | 0.24% | — | Templateinvaders TI Woocommerce WishlistAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Stored XSS.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.10.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory Wishlist FOR WoocommerceAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce allows Stored XSS.This issue affects Wishlist for WooCommerce: from n/a through <= 3.2.2. | |
| Aplazada | Media (4.3) | 0.28% | — | Redqteam WishlistAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in redqteam Wishlist wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wishlist: from n/a through <= 2.1.0. | |
| Aplazada | Media (4.3) | 0.34% | — | Redqteam WishlistAI | 16/5/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in redqteam Wishlist wishlist allows Retrieve Embedded Sensitive Data.This issue affects Wishlist: from n/a through <= 2.1.0. |