Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.60% | — | Woobewoo WBW Currency Switcher FOR Woocommerce | 16/9/2022 | 17/6/2026 | The WBW Currency Switcher for WooCommerce WordPress plugin before 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.88% | — | Pluginus Woocommerce Currency Switcher | 10/1/2022 | 17/6/2026 | The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.82% | — | Woocommerce Currency Switcher | 6/12/2021 | 17/6/2026 | The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue | |
| Modificada | Alta (8.8) | 0.87% | — | Wp-currency Wordpress Currency Switcher | 7/7/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Media (6.5) | 1.8% | — | Wpwham Currency Switcher FOR Woocommerce | 2/11/2019 | 17/6/2026 | An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that was not added by the administrator. In this case, even though the currency does not exist, it will be selected, but a price amount will fall back to the default currency. This means that if an… | |
| Modificada | Alta (7.5) | 1.1% | — | Currency Converter Script Project Currency Converter Script | 7/9/2018 | 17/6/2026 | PHP Scripts Mall Currency Converter Script 2.0.5 allows remote attackers to cause a denial of service (web-interface change) via an inverted comma. | |
| Modificada | Alta (7.5) | 1.0% | — | Ucoincorp Cdcurrency | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for CDcurrency, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Media (5) | 16% | 💥 Exploit | Intelligent-it Paypal Currency Converter Basic FOR Woocommerce | 24/6/2015 | 17/6/2026 | Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before 1.4 for WordPress allows remote attackers to read arbitrary files via a full pathname in the requrl parameter. | |
| Modificada | Media (5.8) | 1.2% | — | Ubercart Currency Conversion Project Ubercart Currency Conversion | 21/4/2015 | 17/6/2026 | Open redirect vulnerability in the Ubercart Currency Conversion module before 6.x-1.2 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination query parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Dmackmedia MOD Currencyconverter | 8/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in includes/convert.php in D-Mack Media Currency Converter (mod_currencyconverter) module 1.0.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the from parameter. | |
| Modificada | Media (4.3) | 1.3% | — | 2bits Currency | 23/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Currency Exchange module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to watchdog logging. | |
| Modificada | Media (4.3) | 1.1% | — | Phpscriptsnow Real Time Currency Exchange | 15/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in rates.php in Real Time Currency Exchange allows remote attackers to inject arbitrary web script or HTML via the Amount parameter. |