Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.64% | — | Eshop Project Eshop | 6/1/2023 | 16/6/2026 | A vulnerability was found in sheilazpy eShop. It has been classified as critical. Affected is an unknown function. The manipulation leads to sql injection. The name of the patch is e096c5849c4dc09e1074104531014a62a5413884. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is… | |
| Modificada | Media (4.8) | 0.60% | — | Mythemeshop Launcher | 6/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress. | |
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Wrteam Eshop - Ecommerce / Store Website | 8/8/2022 | 8/7/2026 | A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter. | |
| Modificada | Media (4.8) | 0.56% | — | Mythemeshop WP Subscribe | 2/5/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress. | |
| Modificada | Media (4.8) | 0.71% | — | Bakeshop Online Ordering System Project Bakeshop Online Ordering System | 26/1/2021 | 17/6/2026 | Bakeshop Online Ordering System in PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML in admin dashboard - "Categories". | |
| Modificada | Alta (8.8) | 1.2% | — | Oxid-esales Eshop | 5/11/2019 | 17/6/2026 | An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Version: 4.9.x-4.10.x. By using a specially crafted URL, users with administrative rights could… | |
| Modificada | Media (6.5) | 1.1% | — | Eshop Project Eshop | 26/9/2019 | 17/6/2026 | The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter. | |
| Modificada | Alta (8.8) | 0.67% | — | Mythemeshop MY WP Translate | 20/8/2019 | 17/6/2026 | The my-wp-translate plugin before 1.0.4 for WordPress has CSRF. | |
| Modificada | Media (6.1) | 0.91% | — | Mythemeshop MY WP Translate | 20/8/2019 | 17/6/2026 | The my-wp-translate plugin before 1.0.4 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 1.4% | — | Oxid-esales Eshop | 30/7/2019 | 17/6/2026 | OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary. | |
| Modificada | Media (5.4) | 0.91% | — | Mythemeshop Launcher | 13/5/2019 | 17/6/2026 | Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Title, (2) Favicon, (3) Meta Description, (4) Subscribe Form (Name field label, Last name field label, Email field label),… | |
| Modificada | Crítica (9.8) | 1.1% | — | Oxid-esales Eshop | 15/1/2019 | 17/6/2026 | The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxConfig::getRequestParameter() method in core/oxconfig.php. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | Bakeshop Inventory System Project Bakeshop Inventory System | 16/11/2018 | 17/6/2026 | Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb. | |
| Modificada | Alta (8.1) | 1.2% | — | Oxid-esales Eshop | 20/8/2018 | 17/6/2026 | An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0. An attacker could gain… | |
| Modificada | Alta (7.5) | 1.2% | — | Oxid-esales Eshop | 20/2/2018 | 17/6/2026 | OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11 (legacy), Enterprise Edition before 6.0.0 RC3 (development), 5.2.x before 5.2.11 (legacy), and 5.3.x before 5.3.6 (maintenance), and Professional Edition before 6.0.0 RC3 (development), 4.9.x before… | |
| Modificada | Alta (7.5) | 0.67% | — | Oxid-esales Eshop | 20/2/2018 | 17/6/2026 | OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition before 6.0.0 RC2 (development), 5.2.x before 5.2.10 (legacy), and 5.3.x before 5.3.5 (maintenance), and Professional Edition before 6.0.0 RC2 (development), 4.9.x before… | |
| Modificada | Media (5.9) | 1.1% | — | Oxid-esales Eshop | 19/2/2018 | 17/6/2026 | An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. This is only valid if OXID High Performance Option is activated and Varnish is used. | |
| Modificada | Alta (7.5) | 1.1% | — | Oxid-esales Eshop | 19/1/2018 | 17/6/2026 | The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address in a crafted authentication token. | |
| Modificada | Media (5.4) | 0.82% | — | Oxid-esales Eshop | 19/1/2018 | 17/6/2026 | OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition before 4.7.13 and 4.8.x before 4.8.7 allow remote attackers to assign users to arbitrary dynamical user groups. | |
| Modificada | Media (6.1) | 2.4% | 💥 Exploit | Oxidforge Eshop | 18/1/2018 | 17/6/2026 | CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks… | |
| Modificada | Media (6.1) | 1.3% | — | Eshop Project Eshop | 21/7/2017 | 17/6/2026 | The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables. | |
| Modificada | Alta (8.8) | 1.9% | — | Oxidforge Oxid Eshop | 10/4/2017 | 17/6/2026 | OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Enterprise Edition v5.1.12, Enterprise Edition v5.2.9, Professional Edition v4.8.12, Professional Edition v4.9.9, Community Edition v4.8.12, Community Edition v4.9.9. | |
| Modificada | Alta (8.8) | 2.9% | — | Elfden Eshop Plugin | 23/1/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2) view, (3) mark, or (4) change parameter. | |
| Modificada | Media (6.1) | 1.8% | — | Elfden Eshop Plugin | 23/1/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter. | |
| Modificada | Media (4.3) | 1.6% | — | Swipe Checkout FOR Eshop Project Swipe Checkout FOR Eshop | 1/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for eShop plugin 3.7.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter. |