Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.58% | — | Moreconvert Team MC Woocommerce WishlistAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert allows SQL Injection.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.8.9. | |
| Modificada | Media (6.5) | 0.18% | — | Wpfactory Wishlist FOR Woocommerce | 8/3/2025 | 17/6/2026 | The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.7. This is due to missing or incorrect nonce validation on the 'save_to_multiple_wishlist' function. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (6.4) | 0.31% | — | WishlistAI | 7/3/2025 | 17/6/2026 | The Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wishlist_button' shortcode in all versions up to, and including, 1.0.43 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.5) | 0.42% | — | Pickplugins WishlistAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PickPlugins Wishlist wishlist allows SQL Injection.This issue affects Wishlist: from n/a through <= 1.0.41. | |
| Analizada | Media (4.3) | 0.17% | — | Wpdesk Flexible Wishlist FOR Woocommerce | 18/2/2025 | 17/6/2026 | The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.26. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to… | |
| Analizada | Alta (7.5) | 0.59% | — | Moreconvert Woocommerce Wishlist | 30/1/2025 | 17/6/2026 | The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.7 via the download_pdf_file() function due to missing validation on a user controlled key. This makes it… | |
| Aplazada | Alta (7.2) | 0.40% | — | Wpdesk Flexible Wishlist FOR WoocommerceAI | 29/1/2025 | 17/6/2026 | The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wishlist_name’ parameter in all versions up to, and including, 1.2.25 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.9) | 0.35% | — | Webtoffee Wishlist FOR WoocommerceAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee Wishlist for WooCommerce wt-woocommerce-wishlist allows Stored XSS.This issue affects Wishlist for WooCommerce: from n/a through <= 2.1.2. | |
| Aplazada | Alta (8.5) | 0.37% | — | Crispweb NC Wishlist FOR WoocommerceAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crispweb NC Wishlist for Woocommerce nc-wishlist-for-woocommerce allows SQL Injection.This issue affects NC Wishlist for Woocommerce: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.1) | 0.29% | — | Wpfactory Wishlist FOR WoocommerceAI | 31/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Wishlist for WooCommerce wish-list-for-woocommerce.This issue affects Wishlist for WooCommerce: from n/a through <= 3.1.2. | |
| Aplazada | Alta (7.5) | 0.38% | — | Templateinvaders TI Woocommerce WishlistAI | 4/12/2024 | 17/6/2026 | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform… | |
| Analizada | Media (6.1) | 0.51% | — | Wpfactory Wishlist FOR Woocommerce | 23/11/2024 | 17/6/2026 | The Wishlist for WooCommerce: Multi Wishlists Per Customer PRO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wtab' parameter in versions 3.0.8 to 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Alta (7.7) | 0.62% | — | Wishlistmember Wishlist Member XAI | 1/11/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WishList Products WishList Member X allows Path Traversal.This issue affects WishList Member X: from n/a through 3.26.6. | |
| Aplazada | Alta (8.2) | 0.36% | — | Wishlistmember Wishlist Member XAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WishList Products WishList Member X allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WishList Member X: from n/a through 3.26.6 | |
| Analizada | Alta (7.5) | 0.39% | — | Templateinvaders TI Woocommerce Wishlist | 10/10/2024 | 17/6/2026 | The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing… | |
| Analizada | Crítica (9.8) | 23% | 💥 Exploit | Templateinvaders TI Woocommerce Wishlist | 29/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce Wishlist: from n/a through 2.8.2. | |
| Aplazada | Crítica (9.8) | 0.54% | — | Wishlistmember Wishlist Member XAI | 10/7/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7. | |
| Aplazada | Alta (7.5) | 0.55% | — | Wishlistmember Wishlist Member XAI | 10/7/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7. | |
| Modificada | Crítica (9.8) | 0.49% | — | Wishlist Member | 9/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7. | |
| Modificada | Alta (7.5) | 0.46% | — | Wishlistmember Wishlist Member X | 24/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7. | |
| Modificada | Alta (8.8) | 0.53% | — | Wishlistmember Wishlist Member | 24/6/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue affects WishList Member X: from n/a before 3.26.7. | |
| Modificada | Alta (8.8) | 0.42% | — | Wishlistmember Wishlist Member X | 24/6/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This issue affects WishList Member X: from n/a before 3.26.7. | |
| Modificada | Media (5.3) | 0.41% | — | Moreconvert Woocommerce Wishlist | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.2. | |
| Aplazada | Media (5.3) | 0.32% | — | Moreconvert MC Woocommerce WishlistAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.8. | |
| Aplazada | Media (5.9) | 0.26% | — | Yithemes Yith Woocommerce WishlistAI | 3/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Wishlist yith-woocommerce-wishlist.This issue affects YITH WooCommerce Wishlist: from n/a through <= 3.32.0. |