Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
257 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.35% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 24/7/2026 | A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be executed remotely. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.35% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 24/7/2026 | A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument first_name results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made… | |
| Aplazada | Baja (1.9) | 0.35% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 24/7/2026 | A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Aplazada | Baja (1.9) | 0.35% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /admin/index.php?page=save_settings. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been published… | |
| Aplazada | Baja (2) | 0.33% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function delete_category of the file /admin/ajax.php?action=delete_category. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.33% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the function save_category of the file /admin/ajax.php?action=save_category. Such manipulation of the argument Name leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public… | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown function of the file /view_prod.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_order of the file /admin/ajax.php?action=save_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function Category of the file pizza/index.php?page=category. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items of the file /admin/ajax.php?action=get_cart_items. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to… | |
| Aplazada | Media (5.5) | 0.41% | 💥 PoC | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_count. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function Login of the file /admin/ajax.php?action=login. The manipulation of the argument e-mail results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects the function login2 of the file /admin/ajax.php?action=login2. The manipulation of the argument e-mail leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function delete_menu of the file /admin/ajax.php?action=delete_menu. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 28/4/2026 | 17/6/2026 | A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_cart of the file /admin/ajax.php?action=delete_cart. Performing a manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been released to the… | |
| Aplazada | Crítica (9.8) | 0.80% | 💥 PoC | Datalogics Ecommerce DeliveryAI | 11/3/2026 | 17/6/2026 | The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perform arbitrary WordPress… | |
| Aplazada | Media (4.3) | 0.10% | — | WpecommerceAI | 6/3/2026 | 17/6/2026 | The WP eCommerce WordPress plugin through 3.15.1 does not have CSRF check in place when deleting coupons, which could allow attackers to make a logged in admin remove them via a CSRF attack | |
| Aplazada | Alta (8.8) | 0.37% | — | Maximsecudeal Secudeal Payments FOR EcommerceAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in maximsecudeal Secudeal Payments for Ecommerce secudeal-payments-for-ecommerce allows Object Injection.This issue affects Secudeal Payments for Ecommerce: from n/a through <= 1.1. | |
| Aplazada | Media (6.5) | 0.29% | — | Wp-ecommerce WP EcommerceAI | 11/2/2026 | 17/6/2026 | The WP eCommerce WordPress plugin through 3.15.1 unserializes user input via ajax actions, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog. | |
| Analizada | Alta (7.7) | 0.55% | — | Spreecommerce Spree | 6/2/2026 | 17/6/2026 | Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 5.0.8, 5.1.10, 5.2.7, and 5.3.2, unauthenticated users can view completed guest orders by Order ID. This issue may lead to disclosure of PII of guest users (including names, addresses and phone numbers). This issue has been patched… | |
| Analizada | Alta (7.7) | 0.76% | — | Spreecommerce Spree | 6/2/2026 | 17/6/2026 | Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any guest user to bind arbitrary guest addresses to their order by manipulating address ID parameters. This enables unauthorized access to other guests'… | |
| Aplazada | Media (5.1) | 0.29% | — | Sellacious EcommerceAI | 30/1/2026 | 17/6/2026 | Sellacious eCommerce 4.6 contains a persistent cross-site scripting vulnerability in the Manage Your Addresses module that allows attackers to inject malicious scripts. Attackers can exploit multiple address input fields like full name, company, and address to execute persistent script code that can hijack user… | |
| Aplazada | Media (5.3) | 0.35% | — | Cargus EcommerceAI | 23/1/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Cargus eCommerce Cargus cargus allows Retrieve Embedded Sensitive Data.This issue affects Cargus: from n/a through <= 1.5.8. | |
| Aplazada | Media (5.1) | 0.27% | — | Workdo EcommercegoAI | 12/1/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a stored XSS due to a lack of proper validation of user input by sending a POST request to ‘/ticket/x/conversion’, using the ‘reply_description’ parameter. | |
| Aplazada | Media (5.1) | 0.27% | — | Workdo EcommercegoAI | 12/1/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in WorkDo's eCommerceGo SaaS, consisting of a lack of proper validation of user input by sending a POST request to ‘/store-ticket’, using the ‘subject’ and ‘description’ parameters. |