Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
182 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.29% | — | Hccoder Paypal Express CheckoutAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hccoder PayPal Express Checkout paypal-express-checkout allows Stored XSS.This issue affects PayPal Express Checkout: from n/a through <= 2.1.2. | |
| Aplazada | Media (5.9) | 0.22% | — | Codepeople Payment Form FOR Paypal PROAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Payment Form for PayPal Pro payment-form-for-paypal-pro allows Stored XSS.This issue affects Payment Form for PayPal Pro: from n/a through <= 1.1.72. | |
| Aplazada | Media (6.5) | 0.39% | — | Noorsplugin Checkout FOR PaypalAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Checkout for PayPal checkout-for-paypal allows Stored XSS.This issue affects Checkout for PayPal: from n/a through <= 1.0.38. | |
| Aplazada | Media (6.5) | 0.34% | — | Sylius Paypal PluginAI | 19/3/2025 | 17/6/2026 | The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. Prior to 1.6.2, 1.7.2, and 2.0.2, a discovered vulnerability allows users to modify their shopping cart after completing the PayPal Checkout process and payment authorization. If a user initiates a PayPal transaction from a… | |
| Aplazada | Media (6.5) | 0.49% | — | Sylius Paypal PluginAI | 17/3/2025 | 17/6/2026 | The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. A vulnerability in versions prior to 1.6.1, 1.7.1, and 2.0.1 allows users to manipulate the final payment amount processed by PayPal. If a user modifies the item quantity in their shopping cart after initiating the PayPal… | |
| Analizada | Media (5.4) | 0.29% | — | Thememakers Paypal Checkout | 27/2/2025 | 17/6/2026 | The ThemeMakers PayPal Express Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'paypal' shortcode in versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Aplazada | Media (4.3) | 0.29% | — | Subscriptions Memberships FOR PaypalAI | 26/2/2025 | 17/6/2026 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged… | |
| Aplazada | Media (6.1) | 0.32% | — | Accept Donations With Paypal StripeAI | 23/2/2025 | 17/6/2026 | The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the rf parameter in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (5.4) | 0.41% | — | Vcita Online Payments - GET Paid With Paypal, Square & Stripe | 18/2/2025 | 17/6/2026 | The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.20.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.21% | — | Vcita Online Payments - GET Paid With Paypal Square AND StripeAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Payments – Get Paid with PayPal, Square & Stripe paypal-payment-button-by-vcita allows Stored XSS.This issue affects Online Payments – Get Paid with PayPal, Square & Stripe: from n/a through <= 3.20.0. | |
| Aplazada | Media (6.4) | 0.35% | — | Payment Button FOR PaypalAI | 17/1/2025 | 17/6/2026 | The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_paypal_checkout' shortcode in all versions up to, and including, 1.2.3.35 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.28% | — | Noorsplugin Checkout FOR PaypalAI | 17/1/2025 | 17/6/2026 | The Checkout for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'checkout_for_paypal' shortcode in all versions up to, and including, 1.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.25% | — | Paypalmuse Paypal Marketing SolutionsAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in paypalmuse PayPal Marketing Solutions paypal-promotions-and-insights allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Marketing Solutions: from n/a through <= 1.2. | |
| Aplazada | Media (6.5) | 0.35% | — | Bharatkambariya Donation Block FOR PaypalAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bharat Kambariya Donation Block For PayPal donations-block allows Stored XSS.This issue affects Donation Block For PayPal: from n/a through <= 2.2.0. | |
| Aplazada | Alta (7.5) | 0.76% | — | Fullworksplugins Quick Paypal PaymentsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Fullworks Quick Paypal Payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Paypal Payments: from n/a through 5.7.25. | |
| Aplazada | Media (4.3) | 0.56% | — | Paypal Brasil Para WoocommerceAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in PayPal PayPal Brasil para WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PayPal Brasil para WooCommerce: from n/a through 1.4.2. | |
| Aplazada | Alta (7.1) | 0.15% | — | Maevelander Paypal ResponderAI | 1/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Maeve Lander PayPal Responder allows Stored XSS.This issue affects PayPal Responder: from n/a through 1.2. | |
| Analizada | Media (6.1) | 0.38% | — | Wpplugin Paypal & Stripe Add-on | 9/11/2024 | 17/6/2026 | The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.3.1. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (7.1) | 0.30% | — | Scott Paterson Contact Form 7 Paypal Stripe ADD ONAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on contact-form-7-paypal-add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through <= 2.3. | |
| Aplazada | Media (6.1) | 0.11% | — | Easy Paypal Gift CertificateAI | 12/10/2024 | 17/6/2026 | The Easy PayPal Gift Certificate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the 'wpppgc_plugin_options' function. This makes it possible for unauthenticated attackers to update the plugin's settings… | |
| Analizada | Media (4.3) | 0.23% | — | Wpplugin Easy Paypal Events | 25/9/2024 | 17/6/2026 | The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the wpeevent_plugin_buttons() function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a… | |
| Analizada | Media (6.1) | 0.19% | — | Michalaugustyniak Misiek Paypal | 12/9/2024 | 17/6/2026 | The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Aplazada | Media (4.7) | 0.31% | — | Wpplugin Easy Paypal BUY NOW ButtonAI | 19/8/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Scott Paterson Easy PayPal Buy Now Button.This issue affects Easy PayPal Buy Now Button: from n/a through 1.9. | |
| Analizada | Alta (7.5) | 0.41% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance' and 'YearLevel' in… | |
| Analizada | Alta (7.5) | 0.41% | — | Janobe Credit CardJanobe Debit Card PaymentJanobe PaypalJanobe School Attendence Monitoring System+1 | 6/8/2024 | 17/6/2026 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'events' in '/report/event_print.php' parameter. |