Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
257 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.45% | — | Spreecommerce Spree | 10/1/2026 | 17/6/2026 | Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an unauthenticated attacker to access guest address information without supplying valid… | |
| Analizada | Media (6.5) | 0.40% | — | Spreecommerce Spree | 8/1/2026 | 17/6/2026 | Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Authenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an authenticated user to retrieve other users’ address information by modifying an existing order.… | |
| Aplazada | Media (5.9) | 0.21% | — | Ecommerce Platforms Gift HuntAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecommerce Platforms Gift Hunt gift-hunt allows Stored XSS.This issue affects Gift Hunt: from n/a through <= 2.0.2. | |
| Aplazada | Baja (2.1) | 0.32% | — | Winston-dsouza Ecommerce-websiteAI | 30/11/2025 | 3/9/2026 | A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter Handler. Executing manipulation of the argument Error can lead to cross site… | |
| Aplazada | Alta (7.1) | 0.40% | 💥 Exploit | Wordpress EcommerceAI | 24/11/2025 | 1/10/2026 | The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Media (6.1) | 0.23% | — | Learnwithfair Php-ecommerce-project | 19/11/2025 | 17/6/2026 | A reflected cross-site scripted (XSS) vulnerability in the /ecommerce/products.php component of E-commerce Project v1.0 and earlier allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into the id parameter. | |
| Analizada | Media (6.5) | 0.24% | — | Kashipara Ecommerce Website | 17/11/2025 | 17/6/2026 | Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php. | |
| Analizada | Media (6.5) | 0.24% | — | Kashipara Ecommerce Website | 17/11/2025 | 17/6/2026 | Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php. | |
| Analizada | Media (6.5) | 0.24% | — | Kashipara Ecommerce Website | 17/11/2025 | 17/6/2026 | Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php. | |
| Aplazada | Baja (2) | 0.31% | — | Ashymuzuro Full-ecommece-websiteAIMuzuro Ecommerce SystemAI | 27/10/2025 | 17/6/2026 | A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an unknown part of the file /admin/index.php?add_product of the component Add Product Page. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Baja (3.5) | 0.25% | — | Plugin-devs Ecommerce-product-carousel-slider-for-elementorAI | 5/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Plugin Devs Product Carousel Slider for Elementor ecommerce-product-carousel-slider-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Carousel Slider for Elementor: from n/a through <= 2.1.3. | |
| Aplazada | Media (6.5) | 0.21% | — | Vwthemes Ibtana Ecommerce Product AddonsAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana – Ecommerce Product Addons ibtana-ecommerce-product-addons allows DOM-Based XSS.This issue affects Ibtana – Ecommerce Product Addons: from n/a through <= 0.4.7.6. | |
| Aplazada | Media (5.9) | 0.18% | — | Wp-ecommerce Recurring Paypal DonationsAI | 22/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce Recurring PayPal Donations recurring-donation allows Stored XSS.This issue affects Recurring PayPal Donations: from n/a through <= 1.8. | |
| Analizada | Baja (2) | 0.29% | — | Codeastro Ecommerce Website | 20/8/2025 | 17/6/2026 | A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_account.php?edit_account of the component Edit Your Account Page. Performing manipulation of the argument Username results in cross site scripting. It is possible to initiate the attack remotely. The… | |
| Modificada | Crítica (9.3) | 2.6% | 💥 Exploit | Spreecommerce Spree | 20/8/2025 | 16/6/2026 | Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using Ruby’s send method. This flaw enables… | |
| Aplazada | Media (6.5) | 0.31% | — | Logicdata Ecommerce FrameworkAI | 19/8/2025 | 17/6/2026 | An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5.0.9.7000 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Aplazada | Media (5.3) | 0.50% | — | Logicdata Ecommerce FrameworkAI | 19/8/2025 | 17/6/2026 | An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows attackers to bypass authentication and compromise user accounts via a bruteforce attack. | |
| Analizada | Crítica (10) | 5.8% | 💥 Exploit | Spreecommerce Spree | 13/8/2025 | 16/6/2026 | Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell… | |
| Aplazada | Alta (7.2) | 0.52% | — | Implecode Ecommerce Product CatalogAI | 17/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Object Injection.This issue affects eCommerce Product Catalog: from n/a through <= 3.4.3. | |
| Aplazada | Media (5.5) | 0.16% | — | CE Phoenix Ecommerce PlatformAI | 2/6/2025 | 17/6/2026 | The CE Phoenix eCommerce platform, starting in version 1.0.9.7 and prior to version 1.1.0.3, allowed logged-in users to delete their accounts without requiring password re-authentication. An attacker with temporary access to an authenticated session (e.g., on a shared/public machine) could permanently delete the… | |
| Aplazada | Media (5.3) | 0.45% | — | Merikbest Ecommerce-spring-reactjsAI | 18/5/2025 | 17/6/2026 | A vulnerability was found in merikbest ecommerce-spring-reactjs up to 464e610bb11cc2619cf6ce8212ccc2d1fd4277fd. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/v1/admin/ of the component File Upload Endpoint. The manipulation of the argument filename leads to path… | |
| Analizada | Baja (3.5) | 0.32% | — | Vk011 Real WP Shop Lite Ajax Ecommerce Shopping Cart | 15/5/2025 | 17/6/2026 | The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite… | |
| Analizada | Media (6.9) | 0.77% | — | Scriptandtools Ecommerce-website-in-php | 27/4/2025 | 17/6/2026 | A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of the file /admin/subscriber-csv.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.34% | — | Scriptandtools Ecommerce-website-in-php | 14/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.3) | 0.99% | — | Scriptandtools Ecommerce-website-in-php | 14/4/2025 | 17/6/2026 | A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely. The… |