Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.19% | — | Edgarrojas Woo-pdf-invoice-builderAI | 13/11/2025 | 17/6/2026 | Missing Authorization vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 1.2.150. | |
| Aplazada | Media (4.3) | 0.19% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 29/10/2025 | 17/6/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7. | |
| Aplazada | Alta (7.1) | 0.15% | — | Wpdesk Flexible PDF Invoices FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible PDF Invoices for WooCommerce & WordPress flexible-invoices allows Cross Site Request Forgery.This issue affects Flexible PDF Invoices for WooCommerce & WordPress: from n/a through <= 6.0.13. | |
| Aplazada | Alta (8.6) | 0.50% | — | Invoiceninja Invoice NinjaAI | 22/9/2025 | 17/6/2026 | Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with admin credentials to execute arbitrary code on the server via uploaded .php files. | |
| Analizada | Media (5.4) | 0.27% | 💥 PoC | Solidinvoice | 29/8/2025 | 17/6/2026 | SolidInvoice version 2.3.7 is vulnerable to a stored cross-site scripting (XSS) issue in the Clients module. An authenticated attacker can inject JavaScript that executes in other users' browsers when the Clients page is viewed. The vulnerability is fixed in version 2.3.8. | |
| Analizada | Media (5.4) | 0.27% | 💥 PoC | Solidinvoice | 29/8/2025 | 17/6/2026 | SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8. | |
| Aplazada | Media (4.8) | 0.14% | — | Invoiceninja Invoice NinjaAI | 26/8/2025 | 17/6/2026 | Invoice Ninja's configuration on macOS, specifically the presence of entitlement "com.apple.security.get-task-allow", allows local attackers with unprivileged access (e.g. via a malicious application) to attach a debugger, read or modify the process memory, inject code in the application's context despite being signed… | |
| Analizada | Baja (2) | 0.29% | — | Solidinvoice | 19/8/2025 | 17/6/2026 | A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file /clients of the component Clients Module. Performing manipulation of the argument Name results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been… | |
| Analizada | Baja (2) | 0.29% | — | Solidinvoice | 19/8/2025 | 17/6/2026 | A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax/rates of the component Tax Rates Module. Such manipulation of the argument Name leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be… | |
| Analizada | Baja (2) | 0.29% | — | Solidinvoice | 19/8/2025 | 17/6/2026 | A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the component Quote Module. This manipulation of the argument Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.… | |
| Analizada | Baja (2) | 0.29% | — | Solidinvoice | 19/8/2025 | 17/6/2026 | A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice of the component Invoice Creation Module. The manipulation of the argument Client Name results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could… | |
| Analizada | Baja (2) | 0.29% | — | Solidinvoice | 19/8/2025 | 17/6/2026 | A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice/recurring of the component Recurring Invoice Module. The manipulation of the argument client name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed… | |
| Aplazada | Media (4.3) | 0.16% | — | Edgarrojas Woo-pdf-invoice-builderAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Cross Site Request Forgery.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 1.2.148. | |
| Aplazada | Alta (7.6) | 0.43% | — | Add-ons.org PDF Invoice Builder FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in add-ons.org PDF Invoice Builder for WooCommerce pdf-for-woocommerce allows SQL Injection.This issue affects PDF Invoice Builder for WooCommerce: from n/a through <= 5.3.8. | |
| Aplazada | Alta (8.8) | 0.19% | — | Webappick ChallanAIWebappick PDF Invoice FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebAppick Challan webappick-pdf-invoice-for-woocommerce allows Privilege Escalation.This issue affects Challan: from n/a through <= 3.7.58. | |
| Aplazada | Crítica (9.4) | 0.53% | — | Ready InvoicesAI | 16/4/2025 | 17/6/2026 | Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices module allows for SQL Injection attacks. | |
| Aplazada | Media (5.3) | 0.39% | — | Slicedinvoices Sliced InvoicesAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in SlicedInvoices Sliced Invoices sliced-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sliced Invoices: from n/a through <= 3.10.0. | |
| Analizada | Crítica (9.8) | 0.69% | — | Invoiceplane | 28/3/2025 | 17/6/2026 | InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller. | |
| Aplazada | Media (5.9) | 0.54% | — | Powerpack Print Invoice Delivery NotesAI | 8/3/2025 | 17/6/2026 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 via the 'wcdn/invoice' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the… | |
| Modificada | Media (5.3) | 0.48% | — | Peprodev Ultimate Invoice | 19/2/2025 | 17/6/2026 | The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.9 via the invoicing viewer due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view invoices for completed orders which… | |
| Analizada | Media (6.3) | 0.45% | — | Wpovernight Woocommerce PDF Invoices& Packing Slips | 4/2/2025 | 17/6/2026 | woocommerce-pdf-invoices-packing-slips is an extension which allows users to create, print & automatically email PDF invoices & packing slips for WooCommerce orders. This vulnerability allows unauthorized users to access any PDF document from a store if they: 1. Have access to a guest document link and 2. Replace the… | |
| Aplazada | Media (6.4) | 0.27% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.1. | |
| Aplazada | Media (6.5) | 0.30% | — | Add-ons.org PDF Invoice Builder FOR WoocommerceAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org PDF Invoice Builder for WooCommerce pdf-for-woocommerce allows Stored XSS.This issue affects PDF Invoice Builder for WooCommerce: from n/a through <= 4.6.0. | |
| Modificada | Media (4.8) | 0.36% | — | Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels print-invoices-packing-slip-labels-for-woocommerce allows Stored XSS.This issue affects WooCommerce PDF Invoices, Packing Slips,… | |
| Aplazada | Alta (7.7) | 0.40% | — | Invoiceninja Invoice NinjaAI | 14/1/2025 | 14/7/2026 | Invoice Ninja is vulnerable to authenticated Server-Side Request Forgery (SSRF) allowing for arbitrary file read and network resource requests as the application user. This issue affects Invoice Ninja: from 5.8.56 through 5.11.23. |