Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.56% | — | Prestalife Product DesignerAI | 9/7/2024 | 17/6/2026 | The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to delete arbitrary attachments.… | |
| Aplazada | Baja (2.1) | 1.1% | 💥 PoC | DjangorestframeworkAI | 26/6/2024 | 17/6/2026 | Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Promokit PK IsotopeAIPrestashopAI | 24/6/2024 | 17/6/2026 | SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attackers to obtain sensitive information and cause other impacts via `pk_isotope::saveData` and `pk_isotope::removeData` methods. | |
| Aplazada | Alta (8.8) | 0.40% | — | PrestashopAIFmemodules HelpdeskAI | 24/6/2024 | 17/6/2026 | SQL Injection vulnerability in the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via 'Tickets::getsearchedtickets()' | |
| Aplazada | Crítica (10) | 0.79% | 💥 PoC | Prestashop M4 PDF ExtensionsAIPrestashopAI | 24/6/2024 | 17/6/2026 | PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaShop allows attackers to run arbitrary code via the M4PDF::saveTemplate() method. | |
| Aplazada | Alta (7.5) | 0.38% | — | Promokit PK ThemesettingsAIPrestashopAI | 24/6/2024 | 17/6/2026 | In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. Due to a lack of permissions control, a guest can access the txt file which collect email when maintenance is enable which can lead to leak of personal… | |
| Aplazada | Alta (7.5) | 0.38% | — | PrestashopAIQuadra-informatique AxeptaAI | 24/6/2024 | 17/6/2026 | In the module "Axepta" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credit card information (expiry date) / postal address / email / etc. without restriction due to a lack of permissions control. | |
| Aplazada | Crítica (9.8) | 0.48% | — | RSI PrestapdfAIPrestashopAI | 21/6/2024 | 17/6/2026 | In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injection via `PrestaPDFProductListModuleFrontController::queryDb().' | |
| Modificada | Crítica (9.8) | 0.41% | — | Prestashop PK Customlinks | 19/6/2024 | 17/6/2026 | In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The script ajax.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Aplazada | Alta (7.5) | 10% | — | Promokit Facebook ModuleAIPrestashopAI | 19/6/2024 | 17/6/2026 | In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The ajax script facebookConnect.php have a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Aplazada | Crítica (10) | 0.51% | — | PrestashopAIFmemodules HelpdeskAI | 19/6/2024 | 17/6/2026 | In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop, a customer can upload .php files. Methods `HelpdeskHelpdeskModuleFrontController::submitTicket()` and `HelpdeskHelpdeskModuleFrontController::replyTicket()` allow upload of .php files on a… | |
| Aplazada | Media (6.4) | 0.27% | — | Auburnforest BlogmentorAI | 19/6/2024 | 17/6/2026 | The Blogmentor – Blog Layouts for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pagination_style’ parameter in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.1) | 0.35% | — | Code-projects Restaurant Reservation System | 18/6/2024 | 17/6/2026 | CodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Date parameter at index.php. | |
| Analizada | Media (5.4) | 0.32% | — | Code-projects Restaurant Reservation System | 18/6/2024 | 17/6/2026 | CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at view_reservations.php. | |
| Aplazada | Media (6.4) | 0.27% | — | Restaurant Menu Food Ordering System Table ReservationAI | 15/6/2024 | 17/6/2026 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.3) | 0.31% | — | Wpeverest Everest Forms | 14/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WPEverest Everest Forms.This issue affects Everest Forms: from n/a through 2.0.3. | |
| Modificada | Media (5.4) | 0.28% | — | Magnigenie Restropress | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagniGenie RestroPress allows Stored XSS.This issue affects RestroPress: from n/a through 3.1.2.1. | |
| Modificada | Media (5.3) | 0.45% | — | Restrict FOR Elementor | 6/6/2024 | 17/6/2026 | The Restrict for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.7 due to improper restrictions on hidden data that make it accessible through the REST API. This makes it possible for unauthenticated attackers to extract potentially sensitive… | |
| Modificada | Media (4.3) | 0.36% | — | Fivestarplugins Five Star Restaurant Menu | 5/6/2024 | 17/6/2026 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on 'add_section', 'add_menu', 'add_menu_item', and 'add_menu_page' functions in all versions up to, and including, 2.4.16. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.50% | — | Kitforest Better Elementor Addons | 4/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BetterAddons Better Elementor Addons allows PHP Local File Inclusion.This issue affects Better Elementor Addons: from n/a through 1.4.1. | |
| Aplazada | Media (5.3) | 0.35% | — | 10up Restricted Site AccessAI | 4/6/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in 10up Restricted Site Access allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Restricted Site Access: from n/a through 7.4.1. | |
| Aplazada | Alta (7.1) | 0.33% | — | Wpeverest User RegistrationAI | 1/6/2024 | 17/6/2026 | The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_form_action' function in versions up to, and including, 3.2.0.1. This makes it possible for… | |
| Analizada | Media (5.3) | 0.53% | — | Prestashop | 14/5/2024 | 17/6/2026 | PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key parameter in the url. This issue is patched in version 8.1.6. No known workarounds are available. | |
| Analizada | Media (6.1) | 56% | 💥 PoC | Prestashop | 14/5/2024 | 17/6/2026 | PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled through the front-office… | |
| Modificada | Media (5.4) | 0.41% | — | Kitforest Better Elementor Addons | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BetterAddons Better Elementor Addons better-elementor-addons allows Stored XSS.This issue affects Better Elementor Addons: from n/a through 1.4.4. |