Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
477 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.21% | — | PaymenterAI | 20/7/2026 | 23/7/2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementation in app/Livewire/Invoices/Show.php executes a pessimistic row lock (lockForUpdate()) outside of an active database transaction. Because MySQL/MariaDB requires an… | |
| Aplazada | Alta (8.5) | 0.40% | — | PaymenterAI | 20/7/2026 | 23/7/2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pairs into server provisioning parameters. Because bundled server extensions… | |
| Aplazada | Media (5.4) | 0.29% | — | PaymenterAI | 20/7/2026 | 23/7/2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint accepts a user-supplied service identifier without enforcing ownership validation, allowing authenticated users to create support tickets referencing services belonging to… | |
| Aplazada | Media (4.3) | 0.16% | — | PaymenterAI | 20/7/2026 | 23/7/2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the email update functionality fails to invalidate the existing verification state when a user changes their email address, allowing a verified account to retain its verified status after switching to… | |
| Aplazada | Media (5.3) | 0.41% | — | PaymenterAI | 20/7/2026 | 23/7/2026 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the PayPal webhook endpoint /extensions/paypal/webhook processes the PAYPAL-CERT-URL HTTP header without validation, allowing attackers to control server-side HTTP request destinations. This value is… | |
| Aplazada | Media (6.5) | 0.27% | — | Payplus Payment GatewayAI | 20/7/2026 | 21/7/2026 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to disclose the secret order key of arbitrary WooCommerce orders and, under some configurations, to modify order statuses. | |
| Aplazada | Media (5.3) | 0.29% | — | Payplus Payment GatewayAI | 20/7/2026 | 21/7/2026 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions available to unauthenticated users, allowing them to tamper with the payment-related metadata of arbitrary WooCommerce orders. | |
| Aplazada | Media (5.1) | 0.34% | — | Flow PaymentAI | 18/7/2026 | 23/7/2026 | The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page. When the plugin handles an order cancellation, the error_message GET parameter is passed directly to wc_add_notice() in flowpayment-fl.php (lines 57-58) without input… | |
| Aplazada | Alta (7.5) | 0.36% | — | Phonepe Payment SolutionsAI | 17/7/2026 | 17/7/2026 | The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces to an unkeyed hash of the request body… | |
| Pendiente de análisis | Media (4.3) | 0.28% | — | SAP Create Single PaymentAI | 14/7/2026 | 14/7/2026 | SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and availability of the application. | |
| Aplazada | Media (6.5) | 0.33% | — | Knitpay Razorpay Payment Links FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in knitpay Razorpay Payment Links for WooCommerce rzp-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay Payment Links for WooCommerce: from n/a through <= 2.1.4. | |
| Aplazada | Media (6.5) | 0.33% | — | Peachpayments Wc-peach-payments-gatewayAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Peach Payments Gateway: from n/a through <= 4.0.2. | |
| Aplazada | Media (6.5) | 0.35% | — | Wpdeveloper Better PaymentAI | 13/7/2026 | 13/7/2026 | Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More better-payment allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Better Payment – Instant Payments, Donations,… | |
| Aplazada | Alta (7.2) | 0.56% | — | Corvuspay Woocommerce Payment GatewayAI | 11/7/2026 | 13/7/2026 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Analizada | Media (4.8) | 0.22% | — | Stella Commerce Realex / Global Payments | 10/7/2026 | 6/8/2026 | Incorrect Authorization vulnerability in Drupal Commerce Realex / Global Payments allows Forceful Browsing. This issue affects Commerce Realex / Global Payments versions: from 0.0.0 to 3.0.2. | |
| Aplazada | Alta (7.2) | 0.32% | — | WP Cost Estimation Payment Forms BuilderAI | 9/7/2026 | 9/7/2026 | The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versions up to, and including, 10.5.97 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (5.3) | 0.47% | — | Corvuspay Woocommerce Payment GatewayAI | 9/7/2026 | 9/7/2026 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to cancel any… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Novalnet Payment GatewayAI | 2/7/2026 | 2/7/2026 | Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Nowpayments FOR WoocommerceAI | 2/7/2026 | 2/7/2026 | Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions. | |
| Aplazada | Alta (7.2) | 0.43% | — | Algoritmika Custom Payment Gateways FOR WoocommerceAI | 1/7/2026 | 1/7/2026 | The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alg_wc_cpg_input_fields' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.5) | 0.17% | — | Funnelkit Payment Gateway FOR Stripe WoocommerceAI | 26/6/2026 | 29/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Woocart Payment Gateway Based Fees AND Discounts FOR WoocommerceAI | 26/6/2026 | 29/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Corvuspay Woocommerce Payment GatewayAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | UPI QR Code Payment GatewayAI | 25/6/2026 | 25/6/2026 | Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions. | |
| Aplazada | Media (6.5) | 0.40% | — | Woocommerce Stripe Payment GatewayAI | 16/6/2026 | 17/6/2026 | The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_pay_for_order()` function in all versions up to, and including, 10.7.0 This is due to a missing order ownership or order_key verification when processing payment… |