Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

397 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.32%—Phpgurukul Online Shopping PortalAI5/4/202624/7/2026
A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been…
AplazadaMedia (6.4)0.19%—Fabian Simple Shopping CartAI4/4/202624/7/2026
The Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsc_display_product' shortcode in all versions up to, and including, 5.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (8.8)0.24%—Ashop Shopping Cart SoftwareAI4/3/202617/6/2026
Ashop Shopping Cart Software contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'shop' parameter. Attackers can send GET requests to index.php with malicious 'shop' values using UNION-based SQL injection to extract sensitive…
AnalizadaMedia (5.5)0.61%—Haben-cs9 Simple AND Nice Shopping Cart Script25/2/202617/6/2026
A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaAlta (8.8)0.27%—Ashop Shopping Cart SoftwareAI22/2/202617/6/2026
Ashop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through the blacklistitemid parameter. Attackers can send POST requests to the admin/bannedcustomers.php endpoint with crafted SQL payloads using SLEEP functions to extract…
AnalizadaMedia (5.5)0.59%—Adonesevangelista Agri-trading Online Shopping System21/2/202617/6/2026
A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroller.php of the component HTTP POST Request Handler. Performing a manipulation of the argument Product results in sql injection. The attack may be initiated remotely. The…
AplazadaMedia (5.1)0.34%—Easycart Easy Cart Shopping CartAI1/2/202617/6/2026
Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword parameter. Remote attackers can inject malicious script code through the search input to compromise user sessions and manipulate application content.
AplazadaMedia (5.1)0.26%—Peel ShoppingAI23/1/202617/6/2026
PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the address parameter of the change_params.php script. Attackers can inject malicious JavaScript payloads that execute when users interact with the address text box, potentially enabling client-side script execution.
AplazadaMedia (5.1)0.26%—Peel ShoppingAI23/1/202617/6/2026
PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the 'Comments / Special Instructions' parameter of the purchase page. Attackers can inject malicious JavaScript payloads that will execute when the page is refreshed, potentially allowing client-side script execution.
AplazadaMedia (5.3)0.26%—Ecwid Shopping CartAI23/1/202617/6/2026
Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ecwid Shopping Cart: from n/a through <= 7.0.6.
AplazadaMedia (4.3)0.21%—Ecwid Shopping CartAI23/1/202617/6/2026
Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ecwid Shopping Cart: from n/a through <= 7.0.5.
AnalizadaCrítica (9.8)0.43%💥 PoCIndieka900 Online Shopping System8/1/202617/6/2026
indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.
AplazadaCrítica (9.3)0.28%—Aa-team Amazon Native Shopping RecommendationsAI5/1/20267/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Native Shopping Recommendations allows SQL Injection.This issue affects Amazon Native Shopping Recommendations: from n/a through 1.3.
AplazadaMedia (4.3)0.12%—Channelize Live Shopping Video StreamsAI31/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Cross Site Request Forgery.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2.0.
AplazadaMedia (5.3)0.25%—Channelize Live Shopping AND Shoppable Videos FOR WoocommerceAI31/12/202517/6/2026
Missing Authorization vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2.0.
AnalizadaAlta (8.7)0.56%—Puneethreddyhc Online Shopping System Advanced12/12/202517/6/2026
Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by…
AnalizadaMedia (5.5)0.39%—Fabian Simple Shopping Cart8/12/202517/6/2026
A vulnerability was identified in code-projects Simple Shopping Cart 1.0. Impacted is an unknown function of the file /adminlogin.php. The manipulation of the argument admin_username leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
AnalizadaBaja (2.1)0.32%—Fabian Simple Shopping Cart8/12/202517/6/2026
A vulnerability was determined in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Admin/additems.php. Executing manipulation of the argument item_name can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be…
AnalizadaBaja (2.1)0.32%—Fabian Simple Shopping Cart8/12/202517/6/2026
A vulnerability was found in code-projects Simple Shopping Cart 1.0. This vulnerability affects unknown code of the file /Customers/settings.php. Performing manipulation of the argument user_id results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
AnalizadaMedia (4.3)0.24%—Phpgurukul Online Shopping Portal25/11/202517/6/2026
Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.
AnalizadaMedia (5.4)0.22%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.
Orbitaley — Vulnerabilidades