Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
201 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.18% | — | Checkoutplugins Stripe Payments FOR Woocommerce | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through 1.9.1. | |
| Aplazada | Alta (7.5) | 0.43% | — | Checkoutplugins Stripe Payments FOR WoocommerceAI | 18/8/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through 1.9.1. | |
| Aplazada | Media (5.4) | 0.33% | — | Accept Stripe PaymentsAI | 7/8/2024 | 17/6/2026 | The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, 2.0.86 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.4) | 0.35% | — | Silverstripe Framework | 17/7/2024 | 17/6/2026 | Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor with access to edit content in the CMS could add send a specifically crafted encoded payload to the server, which could be used to inject a JavaScript payload on the front end of the site. The… | |
| Analizada | Media (4.3) | 0.40% | — | Silverstripe Reports | 17/7/2024 | 17/6/2026 | silverstripe/reports is an API for creating backend reports in the Silverstripe Framework. In affected versions reports can be accessed by their direct URL by any user who has access to view the reports admin section, even if the `canView()` method for that report returns `false`. This issue has been addressed in… | |
| Analizada | Crítica (9.8) | 0.61% | — | Woocommerce Stripe Payment Gateway | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.4.0. | |
| Aplazada | Media (5.3) | 0.31% | — | Tips AND Tricks HQ Stripe PaymentsAI | 4/6/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe Payments: from n/a through 2.0.79. | |
| Aplazada | Media (6.5) | 0.32% | — | Noorsplugin WP Stripe CheckoutAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in naa986 WP Stripe Checkout allows Stored XSS.This issue affects WP Stripe Checkout: from n/a through 1.2.2.41. | |
| Modificada | Alta (8.8) | 0.22% | — | Woocommerce Stripe Payment Gateway | 27/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.0. | |
| Modificada | Media (6.1) | 0.40% | — | Wpplugin Paypal & Stripe Add-on | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on allows Reflected XSS.This issue affects Contact Form 7 – PayPal & Stripe Add-on: from n/a through 2.0. | |
| Modificada | Alta (8.8) | 0.22% | — | Wpplugin Easy Paypal & Stripe BUY NOW Button | 28/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now Button: from n/a through 1.8.1. | |
| Modificada | Media (4.3) | 0.30% | — | Wpplugin Paypal & Stripe Add-on | 28/2/2024 | 17/6/2026 | The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.3 and in Contact Form 7 – PayPal & Stripe Add-on all versions up to, and including 2.1. This is due to missing or incorrect nonce validation on the… | |
| Modificada | Media (4.3) | 0.34% | — | Silverstripe Admin | 23/1/2024 | 17/6/2026 | Silverstripe Admin provides a basic management interface for the Silverstripe Framework. In versions on the 1.x branch prior to 1.13.19 and on the 2.x branch prior to 2.1.8, users who don't have edit or delete permissions for records exposed in a `ModelAdmin` can still edit or delete records using the CSV import form,… | |
| Modificada | Media (4.3) | 0.36% | — | Silverstripe Framework | 23/1/2024 | 17/6/2026 | Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a `GridField` using the `GridFieldAddExistingAutocompleter` component, the record's title can be… | |
| Modificada | Media (5.3) | 0.42% | — | Silverstripe Graphql | 23/1/2024 | 17/6/2026 | The Silverstripe CMS GraphQL Server serves Silverstripe data as GraphQL representations. In versions 4.0.0 prior to 4.3.7 and 5.0.0 prior to 5.1.3, `canView` permission checks are bypassed for ORM data in paginated GraphQL query results where the total number of records is greater than the number of records per page.… | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Webtoffee Stripe Payment Plugin FOR Woocommerce | 19/1/2024 | 17/6/2026 | The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Alta (7.5) | 0.52% | — | Noorsplugin WP Stripe Checkout | 5/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Naa986 WP Stripe Checkout.This issue affects WP Stripe Checkout: from n/a through 1.2.2.37. | |
| Modificada | Crítica (9.8) | 0.60% | — | Automattic Woocommerce Stripe | 5/1/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Stripe Payment Gateway.This issue affects WooCommerce Stripe Payment Gateway: from n/a through 7.6.1. | |
| Modificada | Alta (8.8) | 0.29% | — | Paymentsplugin WP Full Stripe Free | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mammothology WP Full Stripe Free.This issue affects WP Full Stripe Free: from n/a through 7.0.16. | |
| Modificada | Media (4.8) | 0.32% | — | Paymentsplugin WP Full Stripe Free | 26/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology WP Full Stripe Free plugin <= 1.6.1 versions. | |
| Modificada | Alta (7.5) | 0.90% | — | Silverstripe Graphql | 16/10/2023 | 17/6/2026 | silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed graphql schemas. If your Silverstripe CMS… | |
| Modificada | Crítica (9.8) | 1.2% | — | Webtoffee Stripe Payment Plugin FOR Woocommerce | 31/8/2023 | 17/6/2026 | The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a Stripe checkout through the plugin. This allows unauthenticated attackers to log in as users who… | |
| Modificada | Media (5.3) | 0.46% | — | Webtoffee Stripe Payment Plugin FOR Woocommerce | 18/8/2023 | 17/6/2026 | The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eh_callback_handler function in versions up to, and including, 3.7.9. This makes it possible for unauthenticated attackers to modify the order status of arbitrary… | |
| Modificada | Media (4.8) | 0.37% | — | Paymentsplugin WP Full Stripe Free | 8/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mammothology WP Full Stripe Free plugin <= 1.6.1 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Wpplugin Paypal & Stripe Add-on | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on plugin <= 1.9.3 versions. |