Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
3243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.48% | — | Loadedcommerce Loaded CommerceAI | 4/12/2025 | 17/6/2026 | Loaded Commerce 6.6 contains a client-side template injection vulnerability via the search parameter that allows unauthenticated attackers to execute arbitrary code in the victim's browser context when they visit a crafted URL. | |
| Aplazada | Alta (7.2) | 0.29% | — | Codisto Omnichannel FOR WoocommerceAI | 4/12/2025 | 17/6/2026 | The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sync() function in all versions up to, and including, 1.3.65 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.2) | 0.30% | — | Kadencewp Kadence Woocommerce Email DesignerAI | 2/12/2025 | 17/6/2026 | The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1.5.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Alta (7.1) | 0.43% | — | Nopcommerce | 1/12/2025 | 17/6/2026 | nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination, allowing an attacker who has a a valid session cookie access to privileged endpoints (such as /admin) even after the legitimate user has logged out, enabling session hijacking. Any version above… | |
| Aplazada | Media (5.4) | 0.12% | — | Tekrom Technology INC T-soft E-commerceAI | 1/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tekrom Technology Inc. T-Soft E-Commerce allows Cross Site Request Forgery. This issue affects T-Soft E-Commerce: through 28112025. | |
| Aplazada | Baja (2.1) | 0.32% | — | Winston-dsouza Ecommerce-websiteAI | 30/11/2025 | 3/9/2026 | A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter Handler. Executing manipulation of the argument Error can lead to cross site… | |
| Aplazada | Media (5.3) | 0.26% | — | Quick View FOR WoocommerceAI | 27/11/2025 | 17/6/2026 | The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.17 via the 'wqv_popup_content' AJAX endpoint due to insufficient restrictions on which products can be included. This makes it possible for unauthenticated attackers to extract data from… | |
| Aplazada | Media (5.3) | 0.26% | — | Qode Wishlist FOR WoocommerceAI | 27/11/2025 | 17/6/2026 | The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.7 via the 'qode_wishlist_for_woocommerce_wishlist_table_item_callback' function due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.18% | — | Refund Request FOR WoocommerceAI | 25/11/2025 | 17/6/2026 | The Refund Request for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_refund_status' function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (6.5) | 0.24% | — | Wpfactory Wishlist FOR WoocommerceAI | 25/11/2025 | 17/6/2026 | The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.3 via several functions in class-th-wishlist-frontend.php due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to modify… | |
| Aplazada | Media (6.5) | 0.26% | — | Quadlayers Perfect Brands FOR WoocommerceAI | 24/11/2025 | 8/10/2026 | El plugin Perfect Brands for WooCommerce para WordPress es vulnerable a inyección SQL basada en tiempo a través del atributo 'brands' del shortcode 'products' en todas las versiones hasta la 3.6.2, inclusive, debido a un escape insuficiente en el parámetro proporcionado por el usuario y a la falta de preparación… | |
| Aplazada | Alta (7.1) | 0.40% | 💥 Exploit | Wordpress EcommerceAI | 24/11/2025 | 1/10/2026 | El plugin de WordPress eCommerce plugin de WordPress hasta la versión 2.9.0 no sanea y escapa un parámetro antes de devolverlo en la página, lo que lleva a un cross-site scripting reflejado que podría ser utilizado contra usuarios con altos privilegios, como administradores. | |
| Aplazada | Media (5.3) | 0.20% | — | WOO Show Single Variations Shop Category Show Variations AS Single Products WoocommerceAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in theme funda Show Variations as Single Products Woocommerce woo-show-single-variations-shop-category allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Show Variations as Single Products Woocommerce: from n/a through <= 2.0. | |
| Aplazada | Media (5.3) | 0.20% | — | Octolize Cart Weight FOR WoocommerceAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Octolize Shipping Plugins Cart Weight for WooCommerce woo-cart-weight allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cart Weight for WooCommerce: from n/a through <= 1.9.11. | |
| Aplazada | Media (4.3) | 0.20% | — | Webtoffee Product Feed FOR WoocommerceAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Feed for WooCommerce: from n/a through <= 2.3.1. | |
| Aplazada | Media (5.3) | 0.30% | — | Tychesoftwares Custom Order Numbers FOR WoocommerceAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in tychesoftwares Custom Order Numbers for WooCommerce custom-order-numbers-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Custom Order Numbers for WooCommerce: from n/a through <= 1.11.0. | |
| Aplazada | Media (4.3) | 0.22% | — | Themeisle Ppom FOR WoocommerceAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Themeisle PPOM for WooCommerce woocommerce-product-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PPOM for WooCommerce: from n/a through <= 33.0.16. | |
| Aplazada | Media (5.4) | 0.17% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 21/11/2025 | 7/10/2026 | El plugin Return Refund and Exchange For WooCommerce para WordPress es vulnerable a Referencia Directa Insegura a Objeto en todas las versiones hasta la 4.5.5, inclusive, a través de la wps_rma_fetch_order_msgs() debido a la falta de validación en una clave controlada por el usuario. Esto hace posible que atacantes… | |
| Aplazada | Media (4.3) | 0.19% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 21/11/2025 | 7/10/2026 | El plugin Return Refund and Exchange For WooCommerce para WordPress es vulnerable a Referencia Directa Insegura a Objeto en todas las versiones hasta la 4.5.5, inclusive, a través del endpoint AJAX 'wps_rma_cancel_return_request' debido a la falta de validación en una clave controlada por el usuario. Esto hace posible… | |
| Analizada | Media (6.1) | 0.23% | — | Learnwithfair Php-ecommerce-project | 19/11/2025 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the /ecommerce/products.php component of E-commerce Project v1.0 and earlier allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into the id parameter. | |
| Aplazada | Media (6.4) | 0.24% | — | Funnelkit Funnel Builder FOR Woocommerce CheckoutAI | 19/11/2025 | 17/6/2026 | The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `wfop_phone` shortcode in all versions up to, and including, 3.13.1.2. This is due to insufficient input sanitization and output escaping on the user-supplied `default` attribute. This… | |
| Aplazada | Media (5.3) | 0.31% | — | Yithemes Yith Woocommerce WishlistAI | 19/11/2025 | 17/6/2026 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.10.0. This is due to the plugin not properly verifying that a user is authorized to perform actions on the REST API /wp-json/yith/wishlist/v1/lists endpoint (which uses permission_callback… | |
| Aplazada | Media (5.3) | 0.28% | — | Yithemes Yith Woocommerce WishlistAI | 19/11/2025 | 17/6/2026 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.10.0 via the REST API endpoint and AJAX handler due to missing validation on user-controlled keys. This makes it possible for unauthenticated attackers to discover any user's… | |
| Analizada | Media (5.4) | 0.25% | — | Bhabishya-123 E-commerce | 18/11/2025 | 17/6/2026 | A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client-side JavaScript reads attacker-controlled input (for example, values derived from the URL or page fragment) and inserts it into the DOM via unsafe sinks (innerHTML/insertAdjacentHTML/document.write)… | |
| Aplazada | Media (5.3) | 0.29% | — | Pixel Manager FOR WoocommerceAI | 18/11/2025 | 17/6/2026 | The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.49.2 via the ajax_pmw_get_product_ids() function due to insufficient restrictions on which products can be included. This… |