Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.26% | — | Snstheme Samex Clean Minimal Shop Woocommerce Wordpress ThemeAISnstheme M ANH Fashion Woocommerce Wordpress ThemeAI | 13/8/2026 | 14/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress… | |
| Aplazada | Media (5.4) | 0.29% | — | Ecwid Shopping CartAI | 13/8/2026 | 26/8/2026 | The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any authenticated user, such as a subscriber, to disconnect the store and take the storefront offline until an administrator… | |
| Aplazada | Media (5.4) | 0.14% | — | ShopengineAI | 13/8/2026 | 26/8/2026 | The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, allowing an attacker to log a victim into an attacker-controlled account, so that the billing and shipping details the victim then enters at checkout are stored under and… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Computer Repair Shop Management SystemAI | 6/8/2026 | 12/8/2026 | A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_product. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.54% | — | Yushine InnoshopAI | 5/8/2026 | 12/8/2026 | A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::destroyFiles of the file innopacks/restapi/routes/panel-api.php of the component Files Endpoint. This manipulation causes path traversal. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Alta (7.2) | 0.78% | — | Hasthemes ShoplentorAI | 5/8/2026 | 12/8/2026 | The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all versions up to, and including, 3.3.7. This is due to the handle_action() method passing user-supplied input directly to call_user_func() without an allowlist of permitted… | |
| Aplazada | Baja (0.9) | 0.11% | — | Meesho Online Shopping APPAI | 3/8/2026 | 12/8/2026 | A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component com.meesho.supply. Such manipulation of the argument user_id/phone number/email address/name leads to cleartext storage of sensitive information. The… | |
| Aplazada | Alta (8.8) | 0.21% | — | Prestashop TotadministrativemandateAI | 31/7/2026 | 31/8/2026 | PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link. | |
| Aplazada | Crítica (9.8) | 0.50% | — | ShopmonitorAI | 31/7/2026 | 26/8/2026 | The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator… | |
| Modificada | Alta (8.6) | 0.30% | — | Adobe Photoshop Installer | 28/7/2026 | 26/8/2026 | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation… | |
| Aplazada | Media (4.9) | 0.44% | — | Hasthemes ShoplentorAI | 28/7/2026 | 28/7/2026 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Media (4.3) | 0.38% | — | Hasthemes ShoplentorAI | 28/7/2026 | 28/7/2026 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.5 via the 'optionSection' parameter due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Analizada | Alta (8.7) | 0.71% | — | Shopify React-router | 27/7/2026 | 3/8/2026 | React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications… | |
| Analizada | Media (5.1) | 0.32% | — | Shopify React-router | 27/7/2026 | 3/8/2026 | React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0. | |
| Analizada | Media (6.9) | 0.34% | — | Shopify React-router | 27/7/2026 | 3/8/2026 | React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site or that exploits an XSS vector.This issue has been fixed in version… | |
| Analizada | Media (6.1) | 0.36% | — | Shopify React-router | 27/7/2026 | 3/8/2026 | React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been… | |
| Analizada | Media (6.1) | 0.42% | — | Shopify React-router | 27/7/2026 | 3/8/2026 | React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which… | |
| Aplazada | Alta (7.5) | 0.39% | — | Shopfiles Ebook StoreAI | 27/7/2026 | 27/7/2026 | Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. | |
| Aplazada | Alta (8.5) | 0.46% | — | LikeshopAI | 24/7/2026 | 28/7/2026 | Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by submitting unsanitized POST parameters to the adjustAccount endpoint. The adjustAccount method in UserLogic.php concatenates the money, integral, growth, and earnings… | |
| Aplazada | Media (4.1) | 0.37% | — | ShopwareAI | 23/7/2026 | 27/7/2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP addresses. While the parallel `uploadFromURL` flow validates target IPs against private/reserved… | |
| Aplazada | Media (4.3) | 0.27% | — | ShopwareAI | 23/7/2026 | 28/7/2026 | Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is reached without the expected SSO session state, the application falls back to the request's `Referer` header and uses that value as the… | |
| Aplazada | Alta (8.7) | 0.38% | — | ShopperAI | 23/7/2026 | 23/7/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent model identifiers as public properties without the `#[Locked]`… | |
| Aplazada | Media (5.9) | 0.24% | — | Shop Manager TabsAI | 23/7/2026 | 23/7/2026 | Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Shopfiles Ebook StoreAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Shopfiles Ebook StoreAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. |