Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
182 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.30% | — | Wpplugin Paypal & Stripe Add-on | 28/2/2024 | 17/6/2026 | The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.3 and in Contact Form 7 – PayPal & Stripe Add-on all versions up to, and including 2.1. This is due to missing or incorrect nonce validation on the… | |
| Modificada | Media (4.8) | 0.30% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 27/1/2024 | 17/6/2026 | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic redirect URL setting in all versions up to and including 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Modificada | Media (5.4) | 0.40% | — | Wpplugin Easy Paypal Shopping Cart | 16/11/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Scott Paterson Easy PayPal Shopping Cart plugin <= 1.1.10 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Wpplugin Paypal & Stripe Add-on | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on plugin <= 1.9.3 versions. | |
| Modificada | Alta (8.8) | 0.29% | — | Woocommerce Paypal Payments | 22/6/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce PayPal Payments plugin <= 2.0.4 versions. | |
| Modificada | Media (6.5) | 0.42% | — | Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe | 3/6/2023 | 17/6/2026 | The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function. This makes it possible… | |
| Modificada | Media (5.4) | 0.76% | — | Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe | 3/6/2023 | 17/6/2026 | The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 1.3.1 due to insufficient input sanitization… | |
| Modificada | Media (4.8) | 0.37% | — | Exquisite Paypal Donation Project Exquisite Paypal Donation | 3/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in DgCult Exquisite PayPal Donation plugin <= v2.0.0 versions. | |
| Modificada | Media (4.8) | 0.47% | — | Fullworksplugins Quick Paypal Payments | 2/5/2023 | 17/6/2026 | The Quick Paypal Payments WordPress plugin before 5.7.26.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.36% | — | Fullworksplugins Quick Paypal Payments | 25/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Trinitronic Nice Paypal Button Lite | 23/4/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in TriniTronic Nice PayPal Button Lite plugin <= 1.3.5 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Fullworksplugins Quick Paypal Payments | 7/4/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Fullworksplugins Quick Paypal Payments | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions. | |
| Modificada | Crítica (9.8) | 1.2% | — | 202-ecommerce Paypal | 31/3/2023 | 17/6/2026 | PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment support. A SQL injection vulnerability found in the PrestaShop paypal module from release from 3.12.0 to and including 3.16.3 allow a remote attacker to gain privileges, modify data, and potentially… | |
| Modificada | Media (5.3) | 0.55% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 16/3/2023 | 17/6/2026 | The WP Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.6.3 due to the plugin saving shopping cart data exports in a publicly accessible location (/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/). This makes it… | |
| Modificada | Media (5.4) | 0.47% | — | Donation Block FOR Paypal Project Donation Block FOR Paypal | 27/2/2023 | 17/6/2026 | The Donation Block For PayPal WordPress plugin before 2.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.1) | 0.56% | — | Paypal Braintree/sanitize-url | 24/2/2023 | 17/6/2026 | sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities. | |
| Modificada | Media (5.4) | 0.54% | — | Tipsandtricks-hq Easy Accept Payments FOR Paypal | 13/2/2023 | 17/6/2026 | The Easy Accept Payments for PayPal WordPress plugin before 4.9.10 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.48% | — | Wpplugin Easy Paypal BUY NOW Button | 13/2/2023 | 17/6/2026 | The Easy PayPal Buy Now Button WordPress plugin before 1.7.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (7.5) | 0.30% | — | Shopware Swagpaypal | 3/2/2023 | 17/6/2026 | SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, Credit card), the amount and item list sent to PayPal may not be identical to the one in the created order. The problem has been fixed with version… | |
| Modificada | Crítica (9.8) | 2.8% | — | Paypal Nemo-appium | 31/1/2023 | 17/6/2026 | Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium dependencies. | |
| Modificada | Media (5.4) | 0.53% | — | Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart | 23/1/2023 | 17/6/2026 | The WordPress Simple Shopping Cart WordPress plugin before 4.6.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege… | |
| Modificada | Media (5.4) | 0.48% | — | Noorsplugin Checkout FOR Paypal | 19/12/2022 | 17/6/2026 | The Checkout for PayPal WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.8) | 0.56% | — | Tipsandtricks-hq Donations VIA Paypal | 28/11/2022 | 17/6/2026 | The Donations via PayPal WordPress plugin before 1.9.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (6.1) | 1.4% | — | Paypal Braintree/sanitize-urlFedoraproject Fedora | 16/3/2022 | 17/6/2026 | The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function. |