Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
168 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.28% | — | Zealousweb Accept Authorize.net Payments Using Contact Form 7AI | 27/6/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Authorize.NET Payments Using Contact Form 7 accept-authorize-net-payments-using-contact-form-7 allows Retrieve Embedded Sensitive Data.This issue affects Accept Authorize.NET Payments Using Contact Form 7: from n/a through <= 2.5. | |
| Aplazada | Media (5.3) | 0.28% | — | Zealousweb Accept Stripe Payments Using Contact Form 7AI | 27/6/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Stripe Payments Using Contact Form 7 accept-stripe-payments-using-contact-form-7 allows Retrieve Embedded Sensitive Data.This issue affects Accept Stripe Payments Using Contact Form 7: from n/a through <= 3.0. | |
| Aplazada | Media (4.3) | 0.27% | — | Adrian Lado Plationline PaymentsAI | 27/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Adrian Ladó PlatiOnline Payments plationline allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PlatiOnline Payments: from n/a through <= 7.0.0. | |
| Aplazada | Crítica (9.3) | 0.33% | — | Alex Zaytseff Multi Cryptocurrency PaymentsAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Zaytseff Multi CryptoCurrency Payments multi-crypto-currency-payment allows SQL Injection.This issue affects Multi CryptoCurrency Payments: from n/a through <= 2.0.7. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Coinpayments.net Payment Gateway FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CoinPayments CoinPayments.net Payment Gateway for WooCommerce coinpayments-payment-gateway-for-woocommerce allows Object Injection.This issue affects CoinPayments.net Payment Gateway for WooCommerce: from n/a through <= 1.0.17. | |
| Aplazada | Media (6.5) | 0.25% | — | Wptrio Conditional Payments FOR WoocommerceAI | 16/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Trio Conditional Payments for WooCommerce conditional-payments-for-woocommerce allows Cross Site Request Forgery.This issue affects Conditional Payments for WooCommerce: from n/a through <= 3.3.0. | |
| Aplazada | Alta (7.1) | 0.34% | — | Twispay Credit Card PaymentsAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in twispay Twispay Credit Card Payments twispay allows Reflected XSS.This issue affects Twispay Credit Card Payments: from n/a through <= 2.1.2. | |
| Aplazada | Alta (8.2) | 0.33% | — | Cardgate Payments FOR WoocommerceAI | 10/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CardGate CardGate Payments for WooCommerce cardgate allows Blind SQL Injection.This issue affects CardGate Payments for WooCommerce: from n/a through <= 3.2.1. | |
| Aplazada | Media (5.3) | 0.40% | — | Accept Sagepay Payments Using Contact Form 7AI | 8/4/2025 | 17/6/2026 | The Accept SagePay Payments Using Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in… | |
| Aplazada | Alta (7.1) | 0.24% | — | Globalpayments Global Payments WoocommerceAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Global Payments GlobalPayments WooCommerce global-payments-woocommerce allows Reflected XSS.This issue affects GlobalPayments WooCommerce: from n/a through <= 1.13.2. | |
| Aplazada | Media (6.5) | 0.21% | — | Videowhisper MicropaymentsAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in videowhisper MicroPayments paid-membership allows Stored XSS.This issue affects MicroPayments: from n/a through <= 2.9.29. | |
| Aplazada | Crítica (9.3) | 0.61% | — | Trust Payments Gateway FOR WoocommerceAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Trust Payments Trust Payments Gateway for WooCommerce trust-payments-hosted-payment-pages-integration allows SQL Injection.This issue affects Trust Payments Gateway for WooCommerce: from n/a through <= 1.1.4. | |
| Aplazada | Alta (7.1) | 0.37% | — | Videowhisper MicropaymentsAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in videowhisper MicroPayments paid-membership allows Reflected XSS.This issue affects MicroPayments: from n/a through <= 3.2.4. | |
| Aplazada | Media (5.1) | 0.37% | — | Eastnets PaymentsafeAI | 2/3/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Eastnets PaymentSafe 2.5.26.0. This affects an unknown part of the file /directRouter.rfc of the component Edit Manual Reply Handler. The manipulation of the argument Title leads to basic cross site scripting. It is possible to initiate the attack… | |
| Aplazada | Media (5.3) | 0.32% | — | Eastnets PaymentsafeAI | 2/3/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Eastnets PaymentSafe 2.5.26.0. Affected by this issue is some unknown functionality of the file /Default.aspx of the component URL Handler. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.4) | 0.41% | — | Vcita Online Payments - GET Paid With Paypal, Square & Stripe | 18/2/2025 | 17/6/2026 | The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.20.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.1) | 0.53% | 💥 PoC | Eastnets PaymentsafeAI | 16/2/2025 | 17/6/2026 | A vulnerability was found in Eastnets PaymentSafe 2.5.26.0. It has been classified as problematic. This affects an unknown part of the component BIC Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.5.27.0 is able to address this issue. | |
| Aplazada | Media (6.5) | 0.21% | — | Vcita Online Payments - GET Paid With Paypal Square AND StripeAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Payments – Get Paid with PayPal, Square & Stripe paypal-payment-button-by-vcita allows Stored XSS.This issue affects Online Payments – Get Paid with PayPal, Square & Stripe: from n/a through <= 3.20.0. | |
| Analizada | Alta (7.5) | 0.59% | — | IBM Safer Payments | 18/1/2025 | 17/6/2026 | IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a remote attacker to cause a denial of service due to improper allocation of resources. | |
| Aplazada | Media (6.4) | 0.28% | — | Videowhisper MicropaymentsAI | 18/1/2025 | 17/6/2026 | The MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_content_upload_guest' shortcode in all versions up to, and including, 2.9.29 due to insufficient input sanitization and output… | |
| Aplazada | Media (5.3) | 0.39% | — | Accept Authorize NET Payments Using Contact Form 7AI | 18/12/2024 | 17/6/2026 | The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2 via the cf7adn-info.php file. This makes it possible for unauthenticated attackers to extract configuration data which can be used to aid in other attacks. | |
| Aplazada | Media (5.3) | 0.44% | — | Depay Web3 Crypto PaymentsAI | 12/12/2024 | 17/6/2026 | The Web3 Crypto Payments by DePay for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/depay/wc/debug REST API endpoint in all versions up to, and including, 2.12.17. This makes it possible for unauthenticated attackers to retrieve debug… | |
| Analizada | Media (5.3) | 0.52% | — | Zealousweb Accept Stripe Payments Using Contact Form 7 | 12/12/2024 | 17/6/2026 | The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via the cf7sa-info.php file that returns phpinfo() data. This makes it possible for unauthenticated attackers to extract configuration information that can be leveraged… | |
| Aplazada | Alta (8.2) | 0.53% | — | Stripe PaymentsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in mra13 Stripe Payments stripe-payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stripe Payments: from n/a through <= 2.0.79. | |
| Aplazada | Alta (7.5) | 0.76% | — | Fullworksplugins Quick Paypal PaymentsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fullworks Quick Paypal Payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Paypal Payments: from n/a through 5.7.25. |