Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
257 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.99% | — | Scriptandtools Ecommerce-website-in-php | 14/4/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected is an unknown function of the file /login.php. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The complexity of an attack… | |
| Aplazada | Alta (8.1) | 0.47% | — | Boggibill Getshop EcommerceAI | 28/3/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in boggibill GetShop ecommerce getshop-ecommerce allows Path Traversal.This issue affects GetShop ecommerce: from n/a through <= 1.3. | |
| Analizada | Media (6.1) | 0.25% | — | Shinecommerce Traveler | 15/3/2025 | 17/6/2026 | The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Analizada | Crítica (9.8) | 0.67% | — | Shinecommerce Traveler | 15/3/2025 | 17/6/2026 | The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_post' function 'style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any… | |
| Analizada | Media (5.3) | 0.54% | — | S-a-zhd Ecommerce-website-using-php | 6/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. Affected by this issue is some unknown functionality of the file /shop.php. The manipulation of the argument p_cat leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.54% | — | S-a-zhd Ecommerce-website-using-php | 6/3/2025 | 17/6/2026 | A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. It has been classified as critical. This affects an unknown part of the file details.php. The manipulation of the argument pro_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.57% | — | S-a-zhd Ecommerce-website-using-php | 6/3/2025 | 17/6/2026 | A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /customer_register.php. The manipulation of the argument name leads to unrestricted upload. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (4.3) | 0.18% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 18/2/2025 | 17/6/2026 | The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it possible for unauthenticated attackers to send… | |
| Modificada | Media (4.3) | 0.30% | — | Ecpay Ecommerce FOR Woocommerce | 30/1/2025 | 17/6/2026 | The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clear_ecpay_debug_log' AJAX action in all versions up to, and including, 1.1.2411060. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Media (6.5) | 0.21% | — | Wpecommerce Sell Digital DownloadsAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpecommerce Sell Digital Downloads sell-digital-downloads allows Stored XSS.This issue affects Sell Digital Downloads: from n/a through <= 2.2.7. | |
| Aplazada | Media (5.3) | 0.35% | — | Shopping Cart Ecommerce StoreAI | 8/1/2025 | 17/6/2026 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible for unauthenticated attackers to modify order statuses. | |
| Aplazada | Alta (7.1) | 0.34% | — | Perfectsolution WP Ecommerce QuickpayAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PerfectSolution WP eCommerce Quickpay wp-ecommerce-quickpay allows Reflected XSS.This issue affects WP eCommerce Quickpay: from n/a through <= 1.1.0. | |
| Aplazada | Media (5.3) | 0.39% | — | Cocart Headless EcommerceAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in CoCart Headless CoCart – Headless ecommerce cart-rest-api-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CoCart – Headless ecommerce: from n/a through <= 3.11.2. | |
| Aplazada | Media (6.5) | 0.40% | — | Revenuehunt Product-recommendation-quiz-for-ecommerceAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in RevenueHunt Product Recommendation Quiz for eCommerce product-recommendation-quiz-for-ecommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Recommendation Quiz for eCommerce: from n/a through <= 2.1.2. | |
| Aplazada | Alta (8.8) | 0.27% | — | Implecode Ecommerce Product CatalogAI | 21/12/2024 | 17/6/2026 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.43. This is due to missing or incorrect nonce validation on the 'customer_panel_password_reset' function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.4) | 0.26% | — | Simple Ecommerce Shopping CartAI | 7/12/2024 | 17/6/2026 | The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'save_settings', 'export_csv', and 'simpleecommcart-action' actions in all versions up to, and including, 3.1.2. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.30% | — | Simple Ecommerce Shopping Cart PluginAI | 7/12/2024 | 17/6/2026 | The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘monthly_sales_current_year’ parameter in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8.8) | 0.51% | — | Shopping Cart Ecommerce StoreAI | 20/8/2024 | 17/6/2026 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_number’ parameter in all versions up to, and including, 5.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Modificada | Media (5.3) | 0.77% | — | Shuttur Ecommerce-laravel-bootstrap | 24/7/2024 | 17/6/2026 | A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It has been rated as critical. Affected by this issue is the function getCartProductsIds of the file app/Cart.php. The manipulation of the argument laraCart leads to deserialization. The attack may be… | |
| Modificada | Media (6.1) | 0.29% | — | Makecommerce FOR Woocommerce | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Maksekeskus AS MakeCommerce for WooCommerce allows Reflected XSS.This issue affects MakeCommerce for WooCommerce: from n/a through 3.5.1. | |
| Modificada | Media (5.3) | 0.52% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 5/7/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in CodeIgniter Ecommerce-CodeIgniter-Bootstrap up to 1998845073cf433bc6c250b0354461fbd84d0e03. This affects an unknown part. The manipulation of the argument search_title/catName/sub/name/categorie leads to cross site scripting. It is possible to initiate the… | |
| Modificada | Baja (2.7) | 0.33% | — | Wp-ecommerce Easy WP Smtp | 13/6/2024 | 17/6/2026 | The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.3.0. This is due to plugin providing the SMTP password in the SMTP Password field when viewing the settings. This makes it possible for authenticated… | |
| Analizada | Media (5.4) | 0.25% | — | Wp-ecommerce Recurring Paypal Donations | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpecommerce Recurring PayPal Donations allows Stored XSS.This issue affects Recurring PayPal Donations: from n/a through 1.7. | |
| Aplazada | Media (5.3) | 0.50% | — | Woothemes Shopping Cart Ecommerce StoreAI | 14/5/2024 | 17/6/2026 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order details such as payment details,… | |
| Modificada | Crítica (9.8) | 1.7% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 29/4/2024 | 24/8/2026 | An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component. |