Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.36% | — | Fomopay Fomo PAY Chinese Payment SolutionAIFomopay Fomo-payment-gateway-for-woocommerceAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fomopay FOMO Pay Chinese Payment Solution fomo-payment-gateway-for-woocommerce allows Reflected XSS.This issue affects FOMO Pay Chinese Payment Solution: from n/a through <= 2.0.4. | |
| Aplazada | Crítica (9.3) | 0.50% | — | Codesolz Bitcoin Altcoin Payment Gateway FOR WoocommerceAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CodeSolz Bitcoin / AltCoin Payment Gateway for WooCommerce woo-altcoin-payment-gateway allows Blind SQL Injection.This issue affects Bitcoin / AltCoin Payment Gateway for WooCommerce: from n/a through <= 1.7.6. | |
| Aplazada | Media (6.1) | 0.45% | — | Paygreen Payment GatewayAI | 7/1/2025 | 17/6/2026 | The PayGreen Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message_id' parameter in all versions up to, and including, 1.0.26 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (6.1) | 0.37% | — | Dreamfoxmedia Payment Gateway PER Product FOR WoocommerceAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in dreamfox Dreamfox Media Payment gateway per Product for Woocommerce woocommerce-product-payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dreamfox Media Payment gateway per Product for Woocommerce: from n/a through <= 3.5.6. | |
| Aplazada | Media (6.1) | 0.36% | — | Comfino Payment GatewayAI | 7/12/2024 | 17/6/2026 | The Comfino Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.1.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (7.1) | 0.26% | — | Planetstudio Arca Payment GatewayAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Planet Studio ArCa Payment Gateway arca-payment-gateway allows Stored XSS.This issue affects ArCa Payment Gateway: from n/a through <= 1.3.1. | |
| Aplazada | Media (5.4) | 0.28% | — | Yaad Sarig Payment Gateway FOR WCAI | 20/11/2024 | 17/6/2026 | The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data due to a missing capability check on the yaadpay_view_log_callback() and yaadpay_delete_log_callback() functions in all versions up to, and including, 2.2.4. This makes it possible for authenticated… | |
| Aplazada | Crítica (10) | 0.51% | — | Amin Omer Sudan Payment Gateway FOR WoocommerceAI | 29/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Amin Omer Sudan Payment Gateway for WooCommerce wc-sudan-payment-gateway allows Upload a Web Shell to a Web Server.This issue affects Sudan Payment Gateway for WooCommerce: from n/a through <= 1.2.2. | |
| Aplazada | Alta (7.1) | 0.29% | — | Robokassa Payment Gateway FOR WoocommerceAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robokassa Robokassa payment gateway for Woocommerce robokassa allows Reflected XSS.This issue affects Robokassa payment gateway for Woocommerce: from n/a through <= 1.6.1. | |
| Aplazada | Media (4.7) | 0.33% | — | Tomlister Payflex Payment GatewayAI | 5/10/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in tomlister Payflex Payment Gateway payflex-payment-gateway.This issue affects Payflex Payment Gateway: from n/a through <= 2.6.1. | |
| Aplazada | Alta (7.5) | 0.45% | — | Hitpay Payment Solutions PTE LTD Hitpay Payment Gateway FOR WoocommerceAI | 13/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Payment Gateway for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects HitPay Payment Gateway for WooCommerce: from n/a through 4.1.3. | |
| Modificada | Media (6.1) | 0.33% | — | Payplus Payment Gateway | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PayPlus LTD PayPlus Payment Gateway allows Reflected XSS.This issue affects PayPlus Payment Gateway: from n/a through 6.6.8. | |
| Modificada | Crítica (9.8) | 4.1% | 💥 Exploit | Payplus Payment Gateway | 19/7/2024 | 17/6/2026 | The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a WooCommerce API route available to unauthenticated users, leading to an SQL injection vulnerability. | |
| Aplazada | Alta (8.5) | 0.40% | — | Payplus Payment GatewayAI | 12/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PayPlus LTD PayPlus Payment Gateway.This issue affects PayPlus Payment Gateway: from n/a through 7.0.7. | |
| Modificada | Media (5.3) | 0.40% | — | Payflex Payment Gateway | 11/7/2024 | 17/6/2026 | The Payflex Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the payment_callback() function in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to update the status of orders, which can… | |
| Analizada | Crítica (9.8) | 0.61% | — | Woocommerce Stripe Payment Gateway | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0. | |
| Aplazada | Media (5.3) | 0.21% | — | Authorize NET Payment Gateway FOR WoocommerceAI | 4/6/2024 | 17/6/2026 | The Authorize.net Payment Gateway For WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 8.0. This is due to the plugin not properly verifying the authenticity of the request that updates a orders payment status. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (5.3) | 0.40% | — | 2checkout Payment Gateway FOR WoocommerceAI | 2/5/2024 | 17/6/2026 | The 2Checkout Payment Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sniff_ins function in all versions up to, and including, 6.2. This makes it possible for unauthenticated attackers to make changes to orders and mark them as… | |
| Aplazada | Media (4.3) | 0.34% | — | Tychesoftwares Payment Gateway Based Fees AND Discounts FOR WoocommerceAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Tyche Softwares Payment Gateway Based Fees and Discounts for WooCommerce.This issue affects Payment Gateway Based Fees and Discounts for WooCommerce: from n/a through 2.12.1. | |
| Aplazada | Media (5.3) | 0.64% | — | Woocommerce Clover Payment GatewayAI | 9/4/2024 | 17/6/2026 | The WooCommerce Clover Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the callback_handler function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to mark orders as paid. | |
| Modificada | Alta (8.8) | 0.22% | — | Woocommerce Stripe Payment Gateway | 27/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.0. | |
| Modificada | Media (6.1) | 0.35% | — | Woocommerce Payu India Payment Gateway | 15/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PayU India PayU India payu-india allows DOM-Based XSS.This issue affects PayU India: from n/a through <= 3.8.8. | |
| Modificada | Media (5.3) | 0.63% | — | Duitku Payment Gateway | 13/3/2024 | 17/6/2026 | The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_duitku_response function in all versions up to, and including, 2.11.6. This makes it possible for unauthenticated attackers to change the payment status of orders to failed. | |
| Modificada | Crítica (9.8) | 0.65% | — | Papaki Piraeus Bank Woocommerce Payment Gateway | 17/2/2024 | 17/6/2026 | The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'MerchantReference' parameter in all versions up to, and including, 1.6.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Modificada | Crítica (9.8) | 0.65% | — | Antonbond Woocommerce Tranzila Payment Gateway | 8/1/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8. |