Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.7) | 0.66% | — | Villatheme Orders Tracking FOR Woocommerce | 4/9/2023 | 17/6/2026 | The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content retrieved is however limited to the first… | |
| Modificada | Media (4.8) | 0.37% | — | Visualmodo Borderless | 3/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Visualmodo Borderless plugin <= 1.4.8 versions. | |
| Modificada | Media (4.8) | 0.34% | — | Etoilewebdesign Order Tracking | 31/8/2023 | 17/6/2026 | The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers (admin or higher) to inject arbitrary web… | |
| Modificada | Media (6.1) | 0.55% | — | Etoilewebdesign Order Tracking | 31/8/2023 | 17/6/2026 | The Order Tracking Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the start_date and end_date parameters in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Modificada | Media (6.1) | 0.38% | — | Bhavikpatel Woocommerce-order-address-print | 30/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Bhavik Patel Woocommerce Order address Print plugin <= 3.2 versions. | |
| Modificada | Media (6.1) | 0.40% | — | Woocommerce Pre-orders | 30/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Pre-Orders plugin <= 1.9.0 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Woocommerce Pre-orders | 30/8/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WooCommerce WooCommerce Pre-Orders plugin <= 2.0.0 versions. | |
| Modificada | Media (6.1) | 0.39% | — | Oracle Restaurant Menu - Food Ordering System - Table Reservation | 24/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GloriaFood Restaurant Menu – Food Ordering System – Table Reservation plugin <= 2.3.6 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Cagewebdev Order Your Posts Manually | 24/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <= 2.2.5 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Cagewebdev Order Your Posts Manually | 23/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <= 2.2.5 versions. | |
| Modificada | Media (5.5) | 0.27% | — | Cisco Thousandeyes Enterprise AgentCisco Thousandeyes Recorder | 16/8/2023 | 17/6/2026 | A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this… | |
| Modificada | Media (6.5) | 0.31% | — | Woocommerce Pre-orders | 31/7/2023 | 17/6/2026 | The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which could allow attackers to make logged in admins email pre-orders customer, change the released date, mark all pre-orders of a specific product as complete or cancel via CSRF attacks | |
| Modificada | Media (6.5) | 0.31% | — | Woocommerce Pre-orders | 31/7/2023 | 17/6/2026 | The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow attackers to make logged in admins cancel arbitrary pre-orders via a CSRF attack | |
| Modificada | Media (6.5) | 0.32% | — | Addify Abandoned Cart RecoveryAddify Advanced Free GiftsAddify Checkout Fields ManagerAddify Custom Fields FOR Woocommerce+6 | 31/7/2023 | 17/6/2026 | The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom Fields for WooCommerce WordPress plugin before 1.0.4, Custom Order Number WordPress plugin through 1.0.1, Custom Registration Forms Builder WordPress plugin before 1.0.2, Advanced Free Gifts… | |
| Modificada | Alta (8.8) | 0.26% | — | Woocommerce Order Barcodes | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Order Barcodes plugin <= 1.6.4 versions. | |
| Modificada | Crítica (9.8) | 0.50% | — | Bylancer Quickorder | 16/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Bylancer QuickOrder 6.3.7. Affected by this issue is some unknown functionality of the file /blog of the component GET Parameter Handler. The manipulation of the argument s leads to sql injection. The attack may be launched remotely. The identifier… | |
| Modificada | Media (6.1) | 0.63% | — | Online Pizza Ordering System Project Online Pizza Ordering System | 10/7/2023 | 17/6/2026 | Sourcecodester Online Pizza Ordering System v1.0 has a Cross-site scripting (XSS) vulnerability in "/admin/index.php?page=categories" Category item. | |
| Modificada | Alta (7.5) | 0.53% | — | Lineagrafica Lgdetailedorder | 6/7/2023 | 17/6/2026 | In the module "Detailed Order" (lgdetailedorder) in version up to 1.1.20 from Linea Grafica for PrestaShop, a guest can download personal informations without restriction formatted in json. | |
| Modificada | Alta (7.2) | 0.90% | — | Food Ordering System Project Food Ordering System | 6/7/2023 | 17/6/2026 | A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter. | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Cancel Order Request / Return Order / Repeat Order / Reorder FOR Woocommerce | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Cancel order request / Return order / Repeat Order / Reorder for WooCommerce plugin <= 1.3.2 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Piwebsolution Pi-woocommerce-order-date-time-and-type | 26/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Order date, Order pickup, Order date time, Pickup Location, delivery date for WooCommerce plugin <= 3.0.19 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Wpovernight Download Quick/bulk Order Form FOR Woocommerce | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Overnight Quick/Bulk Order Form for WooCommerce plugin <= 3.5.7 versions. | |
| Modificada | Alta (7.2) | 0.97% | — | Hijiriworld Intuitive Custom Post Order | 9/6/2023 | 17/6/2026 | The Intuitive Custom Post Order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.4.1, due to insufficient escaping on the user supplied 'objects' and 'tags' parameters and lack of sufficient preparation in the 'update_options' function as well as the 'refresh' function which… | |
| Modificada | Alta (8.8) | 0.26% | — | Tychesoftwares Custom Order Numbers FOR Woocommerce | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tyche Softwares Custom Order Numbers for WooCommerce plugin <= 1.4.0 versions. | |
| Modificada | Media (6.5) | 0.34% | — | Woocommerce Order Status Change Notifier | 15/5/2023 | 17/6/2026 | The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without… |