Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.73%—Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System30/3/202317/6/2026
A vulnerability was found in SourceCodester Simple and Beautiful Shopping Cart System 1.0 and classified as critical. This issue affects some unknown processing of the file upload.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and…
ModificadaCrítica (9.8)0.73%—Simple AND Beautiful Shopping Cart System Project Simple AND Beautiful Shopping Cart System22/3/202317/6/2026
A vulnerability classified as critical has been found in Simple and Beautiful Shopping Cart System 1.0. This affects an unknown part of the file uploadera.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.…
ModificadaCrítica (9.8)0.72%—Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script19/3/202317/6/2026
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. It has been rated as critical. This issue affects some unknown processing of the file uploaderm.php. The manipulation of the argument submit leads to unrestricted upload. The attack may be initiated remotely. The exploit has been…
ModificadaMedia (5.3)0.55%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart16/3/202317/6/2026
The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). This makes it…
ModificadaAlta (8.8)0.26%—Lightspeedhq Ecwid Ecommerce Shopping Cart14/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions.
ModificadaMedia (5.4)0.53%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart23/1/202317/6/2026
The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege…
ModificadaMedia (4.3)0.58%—Lightspeedhq Ecwid Ecommerce Shopping Cart6/9/202217/6/2026
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options…
ModificadaCrítica (9.8)0.85%—Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script25/8/202217/6/2026
A vulnerability classified as critical was found in SourceCodester Simple and Nice Shopping Cart Script. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation of the argument mem_id leads to sql injection. The attack can be launched remotely. The exploit has…
ModificadaAlta (8.8)0.83%—Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script20/8/202217/6/2026
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mkshop/Men/profile.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been…
ModificadaMedia (6.1)0.60%—Simple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script15/8/202217/6/2026
A vulnerability has been found in SourceCodester Simple and Nice Shopping Cart Script and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /mkshope/login.php. The manipulation of the argument msg leads to cross site scripting. The attack can be launched remotely. The…
ModificadaAlta (8.8)0.63%—Simple-e-commerce-shopping-cart Project Simple-e-commerce-shopping-cart13/9/202117/6/2026
The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable Digital product file, allowing any file, such as PHP to be uploaded by an administrator. Furthermore, as there is no CSRF in place, attackers could also make a logged…
ModificadaAlta (8.8)0.64%—Wpeasycart Shopping Cart & Ecommerce Store19/8/202117/6/2026
The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.1.0.
ModificadaCrítica (9.8)2.8%—Basic Shopping Cart Project Basic Shopping Cart30/7/202117/6/2026
A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin.
ModificadaAlta (7.2)1.9%—Firestormplugins Fs-shopping-cart13/9/201917/6/2026
The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter.
ModificadaAlta (8.8)0.85%—Ultra-prod Wordpress Ultra Simple Paypal Shopping Cart12/9/201917/6/2026
Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaAlta (7.5)22%💥 ExploitThecartpress Ecommerce Shopping Cart29/12/201717/6/2026
The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism."
ModificadaMedia (4.3)3.4%💥 ExploitThecartpress Ecommerce Shopping Cart14/5/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the…
ModificadaMedia (4)9.1%💥 ExploitThecartpress Ecommerce Shopping Cart14/5/201517/6/2026
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to…
ModificadaMedia (4.3)6.4%💥 ExploitThecartpress Ecommerce Shopping Cart14/5/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote attackers to inject arbitrary web script or HTML via the (1) billing_firstname, (2) billing_lastname, (3) billing_company,…
ModificadaMedia (6.8)1.1%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart13/5/201416/6/2026
Cross-site request forgery (CSRF) vulnerability in the WordPress Simple Paypal Shopping Cart plugin before 3.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings.
ModificadaAlta (7.5)3.2%💥 ExploitUaepd Shopping Cart Script21/1/201417/6/2026
Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) p_id parameter to products.php or id parameter to (3) page.php or (4) news.php.
ModificadaAlta (7.5)1.3%—Neturf Ecommerce Shopping Cart23/9/201216/6/2026
SQL injection vulnerability in search.php in Neturf eCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the SearchFor parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.3%—Avactis Shopping Cart2/11/201016/6/2026
Multiple SQL injection vulnerabilities in Pentasoft Avactis Shopping Cart 1.9.1 build 8356 free edition and earlier allow remote attackers to execute arbitrary SQL commands via the User-Agent header to (1) index.php and (2) product-list.php.
ModificadaMedia (4.3)1.1%—Ecommercesoft XSE Shopping Cart17/9/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to Default.aspx and the (2) type parameter to SearchResults.aspx.
ModificadaAlta (7.5)0.97%💥 ExploitAjsquare AJ Shopping Cart12/5/201016/6/2026
SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding action.
Orbitaley — Vulnerabilidades