Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.32% | — | Phpgurukul Online Shopping PortalAI | 5/4/2026 | 24/7/2026 | A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Media (6.4) | 0.19% | — | Fabian Simple Shopping CartAI | 4/4/2026 | 24/7/2026 | The Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsc_display_product' shortcode in all versions up to, and including, 5.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (8.8) | 0.24% | — | Ashop Shopping Cart SoftwareAI | 4/3/2026 | 17/6/2026 | Ashop Shopping Cart Software contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'shop' parameter. Attackers can send GET requests to index.php with malicious 'shop' values using UNION-based SQL injection to extract sensitive… | |
| Analizada | Media (5.5) | 0.61% | — | Haben-cs9 Simple AND Nice Shopping Cart Script | 25/2/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Alta (8.8) | 0.27% | — | Ashop Shopping Cart SoftwareAI | 22/2/2026 | 17/6/2026 | Ashop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through the blacklistitemid parameter. Attackers can send POST requests to the admin/bannedcustomers.php endpoint with crafted SQL payloads using SLEEP functions to extract… | |
| Analizada | Media (5.5) | 0.59% | — | Adonesevangelista Agri-trading Online Shopping System | 21/2/2026 | 17/6/2026 | A vulnerability was found in itsourcecode Agri-Trading Online Shopping System 1.0. This impacts an unknown function of the file admin/productcontroller.php of the component HTTP POST Request Handler. Performing a manipulation of the argument Product results in sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.1) | 0.34% | — | Easycart Easy Cart Shopping CartAI | 1/2/2026 | 17/6/2026 | Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword parameter. Remote attackers can inject malicious script code through the search input to compromise user sessions and manipulate application content. | |
| Aplazada | Media (5.1) | 0.26% | — | Peel ShoppingAI | 23/1/2026 | 17/6/2026 | PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the address parameter of the change_params.php script. Attackers can inject malicious JavaScript payloads that execute when users interact with the address text box, potentially enabling client-side script execution. | |
| Aplazada | Media (5.1) | 0.26% | — | Peel ShoppingAI | 23/1/2026 | 17/6/2026 | PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the 'Comments / Special Instructions' parameter of the purchase page. Attackers can inject malicious JavaScript payloads that will execute when the page is refreshed, potentially allowing client-side script execution. | |
| Aplazada | Media (5.3) | 0.26% | — | Ecwid Shopping CartAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ecwid Shopping Cart: from n/a through <= 7.0.6. | |
| Aplazada | Media (4.3) | 0.21% | — | Ecwid Shopping CartAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ecwid Shopping Cart: from n/a through <= 7.0.5. | |
| Analizada | Crítica (9.8) | 0.43% | 💥 PoC | Indieka900 Online Shopping System | 8/1/2026 | 17/6/2026 | indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Aa-team Amazon Native Shopping RecommendationsAI | 5/1/2026 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Native Shopping Recommendations allows SQL Injection.This issue affects Amazon Native Shopping Recommendations: from n/a through 1.3. | |
| Aplazada | Media (4.3) | 0.12% | — | Channelize Live Shopping Video StreamsAI | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Cross Site Request Forgery.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2.0. | |
| Aplazada | Media (5.3) | 0.25% | — | Channelize Live Shopping AND Shoppable Videos FOR WoocommerceAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live-shopping-video-streams allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live Shopping & Shoppable Videos For WooCommerce: from n/a through <= 2.2.0. | |
| Analizada | Alta (8.7) | 0.56% | — | Puneethreddyhc Online Shopping System Advanced | 12/12/2025 | 17/6/2026 | Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows attackers to inject malicious SQL through the unfiltered 'cm' parameter. Attackers can exploit the vulnerability by sending crafted SQL queries to retrieve sensitive database information by… | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Simple Shopping Cart | 8/12/2025 | 17/6/2026 | A vulnerability was identified in code-projects Simple Shopping Cart 1.0. Impacted is an unknown function of the file /adminlogin.php. The manipulation of the argument admin_username leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. | |
| Analizada | Baja (2.1) | 0.32% | — | Fabian Simple Shopping Cart | 8/12/2025 | 17/6/2026 | A vulnerability was determined in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Admin/additems.php. Executing manipulation of the argument item_name can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Baja (2.1) | 0.32% | — | Fabian Simple Shopping Cart | 8/12/2025 | 17/6/2026 | A vulnerability was found in code-projects Simple Shopping Cart 1.0. This vulnerability affects unknown code of the file /Customers/settings.php. Performing manipulation of the argument user_id results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. | |
| Analizada | Media (4.3) | 0.24% | — | Phpgurukul Online Shopping Portal | 25/11/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php. | |
| Analizada | Media (5.4) | 0.22% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page. | |
| Analizada | Media (6.5) | 0.24% | — | Phpgurukul Online Shopping Portal | 17/11/2025 | 17/6/2026 | PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php. |