Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.46% | — | Wishlistmember Wishlist Member X | 24/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7. | |
| Modificada | Alta (8.8) | 0.53% | — | Wishlistmember Wishlist Member | 24/6/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue affects WishList Member X: from n/a before 3.26.7. | |
| Modificada | Alta (8.8) | 0.42% | — | Wishlistmember Wishlist Member X | 24/6/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This issue affects WishList Member X: from n/a before 3.26.7. | |
| Modificada | Media (5.3) | 0.41% | — | Moreconvert Woocommerce Wishlist | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.2. | |
| Aplazada | Media (5.3) | 0.32% | — | Moreconvert MC Woocommerce WishlistAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.8. | |
| Aplazada | Media (5.9) | 0.26% | — | Yithemes Yith Woocommerce WishlistAI | 3/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Wishlist yith-woocommerce-wishlist.This issue affects YITH WooCommerce Wishlist: from n/a through <= 3.32.0. | |
| Modificada | Media (5.4) | 0.34% | — | Hasthemes Wishsuite | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasTheme WishSuite allows Stored XSS.This issue affects WishSuite: from n/a through 1.3.7. | |
| Modificada | Media (6.1) | 0.47% | — | Wishfulthemes Raise MAGWishfulthemes Wishful Blog | 16/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wishfulthemes Raise Mag, Wishfulthemes Wishful Blog themes allows Reflected XSS.This issue affects Raise Mag: from n/a through 1.0.7; Wishful Blog: from n/a through 2.0.1. | |
| Modificada | Alta (8.8) | 0.31% | — | Wpclever WPC Smart Wishlist FOR Woocommerce | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPClever WPC Smart Wishlist for WooCommerce plugin <= 4.7.1 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Jetimpex TM Woocommerce Compare & Wishlist | 28/9/2023 | 17/6/2026 | The TM WooCommerce Compare & Wishlist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tm_woo_wishlist_table' shortcode in versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (4.8) | 0.37% | — | Hasthemes Wishsuite | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in HasTheme WishSuite – Wishlist for WooCommerce plugin <= 1.3.4 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Hasthemes Wishsuite | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HasTheme WishSuite plugin <= 1.3.3 versions. | |
| Modificada | Alta (8.1) | 1.1% | — | Templateinvaders TI Woocommerce Wishlist | 7/6/2023 | 17/6/2026 | The TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1.21.4 via the 'ti-woocommerce-wishlist/includes/export.class.php' file. This makes it possible for authenticated attackers to gain otherwise… | |
| Modificada | Media (4.3) | 0.25% | — | Hasthemes Quickswish | 27/3/2023 | 17/6/2026 | The QuickSwish WordPress plugin before 1.1.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | |
| Modificada | Alta (8.8) | 23% | 💥 Exploit | Prestashop Blockwishlist | 27/6/2022 | 17/6/2026 | prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue. | |
| Modificada | Media (6.1) | 0.86% | — | Wpclever WPC Smart Wishlist FOR Woocommerce | 16/5/2022 | 17/6/2026 | The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before outputting it back in an attribute via an AJAX action, leading to a Reflected Cross-Site Scripting issue. | |
| Modificada | Media (5.4) | 0.60% | — | Wpclever WPC Smart Wishlist FOR Woocommerce | 28/3/2022 | 17/6/2026 | The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.4 does not sanitise and escape the key parameter before outputting it back in the wishlist_quickview AJAX action's response (available to any authenticated user), leading to a Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 74% | 💥 Exploit | Templateinvaders TI Woocommerce Wishlist | 28/2/2022 | 17/6/2026 | The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated attackers to perform SQL injection attacks | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Wish Lists | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Wish Lists extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Media (6.1) | 0.98% | — | Nlb-creationst MY Wish List | 22/10/2019 | 17/6/2026 | The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues. | |
| Modificada | Baja (3.5) | 0.95% | — | Wishlist Project Wishlist | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Wishlist module before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "access wishlists" permission to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a log message. | |
| Modificada | Media (5.8) | 0.64% | — | Wishlist Project Wishlist | 21/4/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Wishlist module before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that delete wishlist purchase intentions via unspecified vectors. | |
| Modificada | Media (5.4) | 0.27% | — | Getswish Swish Payments | 11/9/2014 | 17/6/2026 | The Swish payments (aka se.bankgirot.swish) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Water Wish Shop Love | 9/9/2014 | 17/6/2026 | The Shop Love (aka com.waterwish.shoplove) application 1.05 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |