Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

93 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.64%—Eshop Project Eshop6/1/202316/6/2026
A vulnerability was found in sheilazpy eShop. It has been classified as critical. Affected is an unknown function. The manipulation leads to sql injection. The name of the patch is e096c5849c4dc09e1074104531014a62a5413884. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is…
ModificadaMedia (4.8)0.60%—Mythemeshop Launcher6/9/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress.
ModificadaMedia (6.1)1.7%💥 ExploitWrteam Eshop - Ecommerce / Store Website8/8/20228/7/2026
A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter.
ModificadaMedia (4.8)0.56%—Mythemeshop WP Subscribe2/5/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on WordPress.
ModificadaMedia (4.8)0.71%—Bakeshop Online Ordering System Project Bakeshop Online Ordering System26/1/202117/6/2026
Bakeshop Online Ordering System in PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML in admin dashboard - "Categories".
ModificadaAlta (8.8)1.2%—Oxid-esales Eshop5/11/201917/6/2026
An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2.x-5.3.x, OXID eShop Professional Edition Version 4.9.x-4.10.x and OXID eShop Community Edition Version: 4.9.x-4.10.x. By using a specially crafted URL, users with administrative rights could…
ModificadaMedia (6.5)1.1%—Eshop Project Eshop26/9/201917/6/2026
The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.
ModificadaAlta (8.8)0.67%—Mythemeshop MY WP Translate20/8/201917/6/2026
The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
ModificadaMedia (6.1)0.91%—Mythemeshop MY WP Translate20/8/201917/6/2026
The my-wp-translate plugin before 1.0.4 for WordPress has XSS.
ModificadaCrítica (9.8)1.4%—Oxid-esales Eshop30/7/201917/6/2026
OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by an attacker. This includes all shopping cart options, customer data, and the database. No interaction between the attacker and the victim is necessary.
ModificadaMedia (5.4)0.91%—Mythemeshop Launcher13/5/201917/6/2026
Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Title, (2) Favicon, (3) Meta Description, (4) Subscribe Form (Name field label, Last name field label, Email field label),…
ModificadaCrítica (9.8)1.1%—Oxid-esales Eshop15/1/201917/6/2026
The DB abstraction layer of OXID eSales 4.10.6 is vulnerable to SQL injection via the oxid or synchoxid parameter to the oxConfig::getRequestParameter() method in core/oxconfig.php.
ModificadaCrítica (9.8)3.2%💥 ExploitBakeshop Inventory System Project Bakeshop Inventory System16/11/201817/6/2026
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
ModificadaAlta (8.1)1.2%—Oxid-esales Eshop20/8/201817/6/2026
An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0. An attacker could gain…
ModificadaAlta (7.5)1.2%—Oxid-esales Eshop20/2/201817/6/2026
OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11 (legacy), Enterprise Edition before 6.0.0 RC3 (development), 5.2.x before 5.2.11 (legacy), and 5.3.x before 5.3.6 (maintenance), and Professional Edition before 6.0.0 RC3 (development), 4.9.x before…
ModificadaAlta (7.5)0.67%—Oxid-esales Eshop20/2/201817/6/2026
OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition before 6.0.0 RC2 (development), 5.2.x before 5.2.10 (legacy), and 5.3.x before 5.3.5 (maintenance), and Professional Edition before 6.0.0 RC2 (development), 4.9.x before…
ModificadaMedia (5.9)1.1%—Oxid-esales Eshop19/2/201817/6/2026
An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. This is only valid if OXID High Performance Option is activated and Varnish is used.
ModificadaAlta (7.5)1.1%—Oxid-esales Eshop19/1/201817/6/2026
The OpenID Single Sign-On authentication functionality in OXID eShop before 4.5.0 allows remote attackers to impersonate users via the email address in a crafted authentication token.
ModificadaMedia (5.4)0.82%—Oxid-esales Eshop19/1/201817/6/2026
OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition before 4.7.13 and 4.8.x before 4.8.7 allow remote attackers to assign users to arbitrary dynamical user groups.
ModificadaMedia (6.1)2.4%💥 ExploitOxidforge Eshop18/1/201817/6/2026
CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks…
ModificadaMedia (6.1)1.3%—Eshop Project Eshop21/7/201717/6/2026
The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.
ModificadaAlta (8.8)1.9%—Oxidforge Oxid Eshop10/4/201717/6/2026
OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Enterprise Edition v5.1.12, Enterprise Edition v5.2.9, Professional Edition v4.8.12, Professional Edition v4.9.9, Community Edition v4.8.12, Community Edition v4.9.9.
ModificadaAlta (8.8)2.9%—Elfden Eshop Plugin23/1/201717/6/2026
Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2) view, (3) mark, or (4) change parameter.
ModificadaMedia (6.1)1.8%—Elfden Eshop Plugin23/1/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.
ModificadaMedia (4.3)1.6%—Swipe Checkout FOR Eshop Project Swipe Checkout FOR Eshop1/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for eShop plugin 3.7.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.
Orbitaley — Vulnerabilidades