Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
202 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.46% | — | Angeljudesuarez E-commerce Website | 17/9/2025 | 25/9/2026 | A security flaw has been discovered in itsourcecode E-Commerce Website 1.0. Affected is an unknown function of the file /admin/users.php. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been released to the public and may be exploited. | |
| Analizada | Baja (2.1) | 0.36% | — | Angeljudesuarez E-commerce Website | 17/9/2025 | 25/9/2026 | A vulnerability was identified in itsourcecode E-Commerce Website 1.0. This impacts an unknown function of the file /admin/products.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Alta (7.1) | 0.20% | — | Dokuzsoft Technology E-commerce WEB Design ProductAI | 17/9/2025 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology E-Commerce Web Design Product allows XSS Through HTTP Headers. This issue affects E-Commerce Web Design Product: before 11.08.2025. | |
| Aplazada | Media (5.9) | 0.18% | — | Welcart E-commerceAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Stored XSS.This issue affects Welcart e-Commerce: from n/a through <= 2.11.20. | |
| Aplazada | Alta (7.2) | 0.48% | — | Welcart E-commerceAI | 20/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Object Injection.This issue affects Welcart e-Commerce: from n/a through <= 2.11.16. | |
| Aplazada | Alta (7.3) | 0.27% | — | Unity Business Technology PTY LTD THE E-commerce ERPAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects The E-Commerce ERP: from n/a through <= 2.1.1.3. | |
| Analizada | Baja (2.1) | 0.27% | — | Fabian E-commerce Site | 17/7/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Unity Business Technology PTY LTD THE E-commerce ERPAI | 16/7/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Unity Business Technology Pty Ltd The E-Commerce ERP profitori allows Privilege Escalation.This issue affects The E-Commerce ERP: from n/a through <= 2.1.1.3. | |
| Aplazada | Media (5.9) | 0.19% | — | Welcart E-commerceAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Stored XSS.This issue affects Welcart e-Commerce: from n/a through <= 2.11.16. | |
| Analizada | Baja (2.1) | 0.41% | — | Fabian E-commerce Site | 8/7/2025 | 17/6/2026 | A vulnerability was found in code-projects E-Commerce Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/users_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Aplazada | Crítica (9.8) | 0.55% | 💥 PoC | Holest Engineering Spreadsheet Price Changer FOR Woocommerce AND WP E-commerce LightAI | 9/6/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows Privilege Escalation.This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: from… | |
| Aplazada | Crítica (10) | 0.47% | — | Holest Engineering Spreadsheet Price Changer FOR Woocommerce AND WP E-commerce LightAI | 9/6/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows Code Injection.This issue affects Spreadsheet Price Changer for WooCommerce and WP… | |
| Aplazada | Crítica (9.3) | 0.35% | — | Holest Engineering Spreadsheet Price Changer FOR Woocommerce AND WP E-commerce LightAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows SQL Injection.This issue affects Spreadsheet Price Changer… | |
| Modificada | Media (6.5) | 0.54% | — | Welcart E-commerce | 9/6/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Path Traversal.This issue affects Welcart e-Commerce: from n/a through <= 2.11.13. | |
| Aplazada | Alta (7.5) | 0.75% | — | Holest Engineering Spreadsheet Price Changer FOR Woocommerce AND WP E-commerce LightAI | 24/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows PHP Local File Inclusion.This issue… | |
| Analizada | Alta (8.8) | 0.46% | — | Welcart E-commerce | 1/4/2025 | 17/6/2026 | Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker who can access websites created using the product. | |
| Aplazada | Media (4.3) | 0.32% | — | Conversios Enhanced-e-commerce-for-woocommerce-storeAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Conversios Conversios.io enhanced-e-commerce-for-woocommerce-store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Conversios.io: from n/a through <= 7.2.3. | |
| Aplazada | Alta (8.6) | 0.31% | — | Wind Media E-commerce Website TemplateAI | 4/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Commerce Website Template allows SQL Injection. This issue affects E-Commerce Website Template: before v1.5. | |
| Aplazada | Media (4.7) | 0.28% | — | Tekrom Technology T-soft E-commerceAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tekrom Technology T-Soft E-Commerce allows Cross-Site Scripting (XSS). This issue affects T-Soft E-Commerce: before v5. | |
| Analizada | Media (6.1) | 0.36% | — | Welcart E-commerce | 12/2/2025 | 17/6/2026 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 2.11.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (5.1) | 0.55% | — | Kurniaramadhan E-commerce-php | 9/1/2025 | 17/6/2026 | A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/create_product.php of the component Create Product Page. The manipulation of the argument Name leads to cross site scripting. The attack may be… | |
| Analizada | Media (5.3) | 0.56% | — | Kurniaramadhan E-commerce-php | 9/1/2025 | 17/6/2026 | A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /blog-details.php. The manipulation of the argument blog_id leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.32% | — | Kurniaramadhan E-commerce-php | 9/1/2025 | 17/6/2026 | A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Analizada | Media (6.9) | 0.80% | — | Codezips E-commerce Site | 21/12/2024 | 17/6/2026 | A vulnerability was found in Codezips E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.3) | 0.55% | — | Codezips E-commerce Site | 19/12/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Codezips E-Commerce Site 1.0. This affects an unknown part of the file /admin/editorder.php. The manipulation of the argument dstatus/quantity/ddate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… |