Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

124 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.72%—Payhere Payment Gateway1/1/202417/6/2026
The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur.
ModificadaMedia (6.5)42%💥 ExploitPaytm Payment Gateway7/12/202317/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway: from n/a through 2.7.0.
ModificadaMedia (4.8)0.39%—Tripay Payment Gateway30/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PT Trijaya Digital Grup TriPay Payment Gateway allows Stored XSS.This issue affects TriPay Payment Gateway: from n/a through 3.2.7.
ModificadaCrítica (9.8)2.3%💥 ExploitPaytm Payment Gateway3/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue affects Paytm Payment Gateway: from n/a through 2.7.3.
ModificadaMedia (4.3)0.43%—Yanco Woocommerce EAN Payment Gateway20/10/202317/6/2026
The WooCommerce EAN Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the refresh_order_ean_data AJAX action in versions up to 6.1.0. This makes it possible for authenticated attackers with contributor-level access and above, to update EAN…
ModificadaMedia (6.1)0.41%—Dreamfoxmedia Payment Gateway PER Product FOR Woocommerce2/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dreamfox Payment gateway per Product for WooCommerce plugin <= 3.2.7 versions.
ModificadaMedia (4.3)0.39%—Yanco Woocommerce CVR Payment Gateway14/9/202317/6/2026
The WooCommerce CVR Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the refresh_order_cvr_data AJAX action in versions up to 6.1.0. This makes it possible for authenticated attackers with contributor-level access and above, to update CVR…
ModificadaAlta (7.5)1.2%—Woocommerce Stripe Payment Gateway14/6/202317/6/2026
Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions.
ModificadaCrítica (9.8)0.90%—Coinmarketstats Bitcoin / Altcoin Payment Gateway FOR Woocommerce8/5/202317/6/2026
The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users
ModificadaMedia (6.1)1.3%💥 ExploitPHP Curl Class Project PHP Curl ClassHT Slider Range FOR Amazon Affiliates Project HT Slider Range FOR Amazon AffiliatesWoo-qiwi-payment-gatewayTeamleader CRM Forms+226/12/202217/6/2026
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.
ModificadaMedia (6.1)0.78%—Woo-myghpay-payment-gateway Project Woo-myghpay-payment-gateway14/12/202117/6/2026
The WooCommerce myghpay Payment Gateway WordPess plugin is vulnerable to Reflected Cross-Site Scripting via the clientref parameter found in the ~/processresponse.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.0.
ModificadaMedia (6.1)0.83%—Coinmarketstats Bitcoin / Altcoin Payment Gateway FOR Woocommerce4/10/202117/6/2026
The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (6.1)0.94%—Dreamfoxmedia Woocommerce Payment Gateway PER Category10/9/202117/6/2026
The WooCommerce Payment Gateway Per Category WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/includes/plugin_settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0.10.
ModificadaMedia (6.1)0.62%—Compassplus Tranzware E-commerce Payment Gateway19/3/202117/6/2026
index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vulnerability
ModificadaAlta (7.5)0.98%—Compassplus Tranzware E-commerce Payment Gateway19/3/202117/6/2026
/exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.
ModificadaMedia (6.1)1.1%💥 PoCTranzware Payment Gateway Project Tranzware Payment Gateway12/11/202017/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url (different vector than CVE-2020-28414).
ModificadaMedia (6.1)1.1%💥 PoCTranzware Payment Gateway Project Tranzware Payment Gateway12/11/202017/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url (different vector than CVE-2020-28415).
ModificadaMedia (6.1)4.2%💥 ExploitCybercompany Swipehq-payment-gateway-woocommerce27/12/201917/6/2026
Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for WooCommerce plugin 2.7.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.
ModificadaMedia (6.1)1.2%—Cybercompay Swipehq-payment-gateway-wp-e-commerce27/12/201917/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) api_key, (2) payment_page_url, (3) merchant_id, (4) api_url, or (5) currency parameter.
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaMedia (5.3)1.1%—Woocommerce Paypal Checkout Payment Gateway29/8/201917/6/2026
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be…
ModificadaMedia (5.3)1.2%—Woocommerce Payu India Payment Gateway29/8/201917/6/2026
/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering in the purchaseQuantity=1 parameter, as demonstrated by purchasing an item for lower than the intended price.
ModificadaMedia (6.5)5.9%💥 ExploitWoocommerce Paypal Checkout Payment Gateway21/3/201917/6/2026
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be…
ModificadaMedia (4.3)2.1%—Woocommerce Sagepay Direct Payment Gateway Project Woocommerce Sagepay Direct Payment Gateway2/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in pages/3DComplete.php in the WooCommerce SagePay Direct Payment Gateway plugin before 0.1.6.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) MD or (2) PARes parameter.
Orbitaley — Vulnerabilidades