Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.73% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 30/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0 and classified as critical. This issue affects some unknown processing of the file upload.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 0.73% | — | Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System | 22/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Simple and Beautiful Shopping Cart System 1.0. This affects an unknown part of the file uploadera.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 0.72% | — | Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script | 19/3/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. It has been rated as critical. This issue affects some unknown processing of the file uploaderm.php. The manipulation of the argument submit leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Media (5.3) | 0.55% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 16/3/2023 | 17/6/2026 | The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). This makes it… | |
| Modificada | Alta (8.8) | 0.26% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 14/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions. | |
| Modificada | Media (5.4) | 0.53% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 23/1/2023 | 17/6/2026 | The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege… | |
| Modificada | Media (4.3) | 0.58% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 6/9/2022 | 17/6/2026 | The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options… | |
| Modificada | Crítica (9.8) | 0.85% | — | Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script | 25/8/2022 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple and Nice Shopping Cart Script. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation of the argument mem_id leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Modificada | Alta (8.8) | 0.83% | — | Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script | 20/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.60% | — | Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script | 15/8/2022 | 17/6/2026 | A vulnerability has been found in SourceCodester Simple and Nice Shopping Cart Script and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /mkshope/login.php. The manipulation of the argument msg leads to cross site scripting. The attack can be launched remotely. The… | |
| Modificada | Alta (8.8) | 0.63% | — | Simple-e-commerce-shopping-cart Project Simple-e-commerce-shopping-cart | 13/9/2021 | 17/6/2026 | The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable Digital product file, allowing any file, such as PHP to be uploaded by an administrator. Furthermore, as there is no CSRF in place, attackers could also make a logged… | |
| Modificada | Alta (8.8) | 0.64% | — | Wpeasycart Shopping Cart & Ecommerce Store | 19/8/2021 | 17/6/2026 | The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.1.0. | |
| Modificada | Crítica (9.8) | 2.8% | — | Basic Shopping Cart Project Basic Shopping Cart | 30/7/2021 | 17/6/2026 | A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin. | |
| Modificada | Alta (7.2) | 1.9% | — | Firestormplugins Fs-shopping-cart | 13/9/2019 | 17/6/2026 | The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter. | |
| Modificada | Alta (8.8) | 0.85% | — | Ultra-prod Wordpress Ultra Simple Paypal Shopping Cart | 12/9/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Alta (7.5) | 22% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 29/12/2017 | 17/6/2026 | The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism." | |
| Modificada | Media (4.3) | 3.4% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 14/5/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the… | |
| Modificada | Media (4) | 9.1% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 14/5/2015 | 17/6/2026 | Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to… | |
| Modificada | Media (4.3) | 6.4% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 14/5/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote attackers to inject arbitrary web script or HTML via the (1) billing_firstname, (2) billing_lastname, (3) billing_company,… | |
| Modificada | Media (6.8) | 1.1% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 13/5/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Uaepd Shopping Cart Script | 21/1/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) p_id parameter to products.php or id parameter to (3) page.php or (4) news.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Neturf Ecommerce Shopping Cart | 23/9/2012 | 16/6/2026 | SQL injection vulnerability in search.php in Neturf eCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the SearchFor parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.3% | — | Avactis Shopping Cart | 2/11/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Pentasoft Avactis Shopping Cart 1.9.1 build 8356 free edition and earlier allow remote attackers to execute arbitrary SQL commands via the User-Agent header to (1) index.php and (2) product-list.php. | |
| Modificada | Media (4.3) | 1.1% | — | Ecommercesoft XSE Shopping Cart | 17/9/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to Default.aspx and the (2) type parameter to SearchResults.aspx. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Ajsquare AJ Shopping Cart | 12/5/2010 | 16/6/2026 | SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding action. |