Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.26% | — | Payhere Payment Gateway Plugin FOR WoocommerceAI | 14/1/2026 | 17/6/2026 | The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to change the status of… | |
| Aplazada | Media (5.3) | 0.26% | — | Netcash Woocommerce Payment GatewayAI | 14/1/2026 | 17/6/2026 | The Netcash WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_return_url function in all versions up to, and including, 4.1.3. This makes it possible for unauthenticated attackers to mark any WooCommerce order as… | |
| Aplazada | Alta (8.2) | 0.34% | — | Ipaymu Payment Gateway FOR WoocommerceAI | 7/1/2026 | 17/6/2026 | The iPaymu Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 2.0.2 via the 'check_ipaymu_response' function. This is due to the plugin not validating webhook request authenticity through signature verification or origin checks. This makes… | |
| Aplazada | Media (5.3) | 0.40% | — | Papaki Piraeus Bank Woocommerce Payment GatewayAI | 7/1/2026 | 17/6/2026 | The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to unauthorized order status modification in all versions up to, and including, 3.1.4. This is due to missing authorization checks on the payment callback endpoint handler when processing the 'fail' callback from the payment gateway. This… | |
| Aplazada | Media (6.1) | 0.21% | — | Hblpay Payment GatewayAI | 7/1/2026 | 30/9/2026 | The HBLPAY Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cusdata’ parameter in all versions up to, and including, 5.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (5.3) | 0.27% | — | Yaadsarig Yaad Sarig Payment Gateway FOR WCAI | 16/12/2025 | 5/10/2026 | Missing Authorization vulnerability in yaadsarig Yaad Sarig Payment Gateway For WC yaad-sarig-payment-gateway-for-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Yaad Sarig Payment Gateway For WC: from n/a through <= 2.2.11. | |
| Aplazada | Media (5.3) | 0.37% | — | Campay Woocommerce Payment GatewayAI | 12/12/2025 | 17/6/2026 | The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly validating that a transaction has occurred through the payment gateway. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.3) | 0.22% | — | WOO Payment Gateway PayseraAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in paysera WooCommerce Payment Gateway - Paysera woo-payment-gateway-paysera allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce Payment Gateway - Paysera: from n/a through <= 3.10.0. | |
| Aplazada | Media (5.3) | 0.27% | — | Cryptocurrency Payment GatewayAI | 18/11/2025 | 17/6/2026 | The Cryptocurrency Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'handle_optin_optout' function in all versions up to, and including, 2.0.25. This makes it possible for unauthenticated attackers to opt in and out of… | |
| Aplazada | Crítica (9.3) | 0.34% | — | Hiecor Hcv4-payment-gatewayAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiecor HieCOR Payment Gateway Plugin hcv4-payment-gateway allows SQL Injection.This issue affects HieCOR Payment Gateway Plugin: from n/a through <= 1.5.11. | |
| Aplazada | Alta (7.5) | 0.30% | — | Crypto Payment Gateway With PayeerAI | 4/11/2025 | 17/6/2026 | The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a payments status through server-side validation though the /wc-api/bp-payeer-gateway-callback endpoint. This makes… | |
| Aplazada | Media (6.1) | 0.22% | — | Vnpay Payment GatewayAI | 24/10/2025 | 17/6/2026 | The VNPAY Payment gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (7.1) | 0.24% | — | Robokassa Payment Gateway FOR WoocommerceAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robokassa Robokassa payment gateway for Woocommerce robokassa allows Reflected XSS.This issue affects Robokassa payment gateway for Woocommerce: from n/a through <= 1.8.6. | |
| Aplazada | Media (4.3) | 0.25% | — | Payrexx Payment Gateway FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in payrexx Payrexx Payment Gateway for WooCommerce woo-payrexx-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Payrexx Payment Gateway for WooCommerce: from n/a through <= 3.1.5. | |
| Aplazada | Media (5.3) | 0.28% | — | Cardcom Payment GatewayAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in CardCom CardCom Payment Gateway woo-cardcom-payment-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CardCom Payment Gateway: from n/a through <= 3.5.0.7. | |
| Aplazada | Media (5.9) | 0.18% | — | Gourl Bitcoin Payment Gateway Paid Downloads MembershipAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gourl GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership gourl-bitcoin-payment-gateway-paid-downloads-membership allows Stored XSS.This issue affects GoUrl Bitcoin Payment Gateway & Paid Downloads &… | |
| Aplazada | Alta (7.5) | 0.41% | — | Stefan Keller Woocommerce Payment Gateway FOR SaferpayAI | 5/9/2025 | 5/10/2026 | Path Traversal: '.../...//' vulnerability in Stefan Keller WooCommerce Payment Gateway for Saferpay woocommerce-payment-gateway-for-saferpay allows Path Traversal.This issue affects WooCommerce Payment Gateway for Saferpay: from n/a through <= 0.4.9. | |
| Aplazada | Media (5.3) | 0.30% | — | Icount Payment GatewayAI | 27/6/2025 | 17/6/2026 | Missing Authorization vulnerability in iCount iCount Payment Gateway icount allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iCount Payment Gateway: from n/a through <= 2.0.7. | |
| Aplazada | Media (6.5) | 0.28% | — | Cryptocloud - Crypto Payment GatewayAI | 9/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Crypto Cloud CryptoCloud - Crypto Payment Gateway cryptocloud-crypto-payment-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CryptoCloud - Crypto Payment Gateway: from n/a through <= 2.1.2. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Coinpayments.net Payment Gateway FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CoinPayments CoinPayments.net Payment Gateway for WooCommerce coinpayments-payment-gateway-for-woocommerce allows Object Injection.This issue affects CoinPayments.net Payment Gateway for WooCommerce: from n/a through <= 1.0.17. | |
| Analizada | Media (6.1) | 0.51% | 💥 Exploit | Hkdigit Payment Gateway FOR Telcell | 15/5/2025 | 17/6/2026 | The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue | |
| Aplazada | Alta (7.1) | 0.15% | — | Axima Pays Woocommerce Payment GatewayAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in axima Pays – WooCommerce Payment Gateway axima-payment-gateway allows Stored XSS.This issue affects Pays – WooCommerce Payment Gateway: from n/a through <= 2.6. | |
| Aplazada | Alta (7.1) | 0.29% | — | WE ARE DE Woo-tbc-payment-gatewayAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in We Are De WooCommerce TBC Credit Card Payment Gateway (Free) woo-tbc-payment-gateway allows Reflected XSS.This issue affects WooCommerce TBC Credit Card Payment Gateway (Free): from n/a through <= 2.0.0. | |
| Aplazada | Alta (7.1) | 0.34% | — | ABA Bank ABA Payway Woocommerce Payment GatewayAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ABA Bank ABA PayWay Payment Gateway for WooCommerce aba-payway-woocommerce-payment-gateway allows Reflected XSS.This issue affects ABA PayWay Payment Gateway for WooCommerce: from n/a through <= 2.1.4. | |
| Aplazada | Alta (7.1) | 0.39% | — | Codesolz Bitcoin Altcoin Payment Gateway FOR WoocommerceAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce woo-altcoin-payment-gateway allows Reflected XSS.This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through <= 1.7.6. |