Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
3243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.17% | — | Wpfactory Product-tabs-for-woocommerceAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Product Tabs for WooCommerce product-tabs-for-woocommerce allows Stored XSS.This issue affects Additional Custom Product Tabs for WooCommerce: from n/a through <= 1.7.3. | |
| Aplazada | Media (5.9) | 0.18% | — | Welcart E-commerceAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Stored XSS.This issue affects Welcart e-Commerce: from n/a through <= 2.11.20. | |
| Aplazada | Alta (7.1) | 0.24% | — | Villatheme Woocommerce Photo ReviewsAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooCommerce Photo Reviews woocommerce-photo-reviews.This issue affects WooCommerce Photo Reviews: from n/a through <= 1.3.13. | |
| Aplazada | Crítica (9.3) | 0.62% | — | Wpswings Woocommerce Ultimate Gift CardAI | 9/9/2025 | 30/9/2026 | Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('inyección SQL') vulnerabilidad en WPSwings WooCommerce Ultimate Gift Card - Create, Sell and Manage Gift Cards with Customized Email Templates. Este problema afecta a WooCommerce Ultimate Gift Card - Create, Sell and Manage Gift Cards… | |
| Analizada | Crítica (9.1) | 95% | ⚠ Explotación activa💥 Exploit | Adobe CommerceAdobe Commerce B2BAdobe Magento | 9/9/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue… | |
| Aplazada | Media (4.9) | 0.71% | 💥 Exploit | Elex Woocommerce Google ShoppingAI | 6/9/2025 | 17/6/2026 | The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the 'file_to_delete' parameter in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Alta (7.5) | 0.41% | — | Stefan Keller Woocommerce Payment Gateway FOR SaferpayAI | 5/9/2025 | 5/10/2026 | Salto de ruta: '... / ...//' vulnerabilidad en Stefan Keller WooCommerce Payment Gateway for Saferpay woocommerce-payment-gateway-for-saferpay permite Salto de ruta. Este problema afecta a WooCommerce Payment Gateway for Saferpay: desde n/a hasta menor o igual a 0.4.9. | |
| Aplazada | Media (6.5) | 0.15% | — | Usamafarooq Woocommerce Gifts ProductAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in usamafarooq Woocommerce Gifts Product woo-gift-product allows Cross Site Request Forgery.This issue affects Woocommerce Gifts Product: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.17% | — | Ablancodev Woocommerce Notify Updated ProductAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ablancodev Woocommerce Notify Updated Product woocommerce-notify-updated-product allows Stored XSS.This issue affects Woocommerce Notify Updated Product: from n/a through <= 1.6. | |
| Aplazada | Baja (3.5) | 0.25% | — | Plugin-devs Ecommerce-product-carousel-slider-for-elementorAI | 5/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Plugin Devs Product Carousel Slider for Elementor ecommerce-product-carousel-slider-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Carousel Slider for Elementor: from n/a through <= 2.1.3. | |
| Aplazada | Media (4.3) | 0.14% | — | Michalzagdan Trustmate IO Integration FOR WoocommerceAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in michalzagdan TrustMate.io – WooCommerce integration trustmate-io-integration-for-woocommerce allows Cross Site Request Forgery.This issue affects TrustMate.io – WooCommerce integration: from n/a through <= 1.16.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Themelocation Custom Woocommerce Checkout Fields EditorAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themelocation Custom WooCommerce Checkout Fields Editor add-fields-to-checkout-page-woocommerce allows Cross Site Request Forgery.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through <= 1.3.4. | |
| Aplazada | Media (6.5) | 0.21% | — | Vwthemes Ibtana Ecommerce Product AddonsAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana – Ecommerce Product Addons ibtana-ecommerce-product-addons allows DOM-Based XSS.This issue affects Ibtana – Ecommerce Product Addons: from n/a through <= 0.4.7.6. | |
| Aplazada | Alta (7.6) | 0.37% | 💥 PoC | Wpexperts License Manager FOR WoocommerceAI | 5/9/2025 | 5/10/2026 | Vulnerabilidad de Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') en Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce permite Inyección SQL Ciega. Este problema afecta a License Manager for WooCommerce: desde n/a hasta menor o igual a 3.0.12. | |
| Analizada | Crítica (9) | 51% | ⚠ Explotación activa💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0. | |
| Aplazada | Media (5.3) | 0.22% | — | Peachpay FOR WoocommerceAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in peachpay PeachPay Payments peachpay-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PeachPay Payments: from n/a through <= 1.117.4. | |
| Aplazada | Media (4.3) | 0.24% | — | Tychesoftwares Order Delivery Date FOR WoocommerceAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery Date for WooCommerce: from n/a through <= 4.1.0. | |
| Aplazada | Media (6.6) | 0.27% | — | Klarna Order Management FOR WoocommerceAI | 3/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Debugging Code vulnerability in Klarna Klarna Order Management for WooCommerce klarna-order-management-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Klarna Order Management for WooCommerce: from n/a through <= 1.9.8. | |
| Analizada | Alta (7.5) | 6.5% | 💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4. | |
| Analizada | Crítica (9.8) | 19% | 💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform… | |
| Analizada | Alta (8.8) | 1.6% | 💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This issue affects Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4. | |
| Analizada | Crítica (9.8) | 0.73% | — | Booster FOR Woocommerce | 29/8/2025 | 26/9/2026 | El plugin Booster for WooCommerce para WordPress es vulnerable a la carga arbitraria de archivos debido a la falta de validación del tipo de archivo en la función 'add_files_to_order' en todas las versiones hasta la 7.2.4, inclusive. Esto hace posible que atacantes no autenticados carguen archivos arbitrarios con… | |
| Aplazada | Media (5.9) | 0.22% | — | Everythingwp Risk Free Cash ON Delivery COD WoocommerceAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in everythingwp Risk Free Cash On Delivery (COD) – WooCommerce risk-free-cash-on-delivery-cod-woocommerce allows Stored XSS.This issue affects Risk Free Cash On Delivery (COD) – WooCommerce: from n/a through <= 1.0.4. | |
| Aplazada | Alta (7.7) | 0.38% | — | Extendons Woocommerce CSV Import ExportAI | 28/8/2025 | 25/9/2026 | Vulnerabilidad de 'Limitación inadecuada de un nombre de ruta a un directorio restringido' (salto de ruta) en extendons WooCommerce csv import export permite salto de ruta. Este problema afecta a WooCommerce csv import export: desde n/a hasta 2.0.6. | |
| Aplazada | Media (5.3) | 0.22% | — | Aftership TrackingAIAftership Woocommerce TrackingAI | 27/8/2025 | 17/6/2026 | La vulnerabilidad de falta de autorización en AfterShip y Automizely AfterShip Tracking permite acceder a funcionalidades no restringidas correctamente por las ACL. Este problema afecta a AfterShip Tracking desde n/d hasta la versión 1.17.17. |