Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.25% | — | Shoplentor PROAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Shoplentor PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions. | |
| Aplazada | Media (6.4) | 0.32% | — | Mythemeshop WP ShortcodeAI | 23/7/2026 | 23/7/2026 | The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and including, 1.4.17. This is due to insufficient input sanitization and output escaping in the mts_tabs() function, which outputs the title shortcode… | |
| Aplazada | Media (5.3) | 0.44% | — | JoomshoppingAI | 22/7/2026 | 23/7/2026 | Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller. | |
| Aplazada | Media (6.1) | 0.24% | — | HikashopAIJoomlaAI | 20/7/2026 | 23/7/2026 | Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect. | |
| Aplazada | Baja (1.3) | 0.29% | — | Awesto Django-shopAI | 19/7/2026 | 20/7/2026 | A vulnerability was identified in awesto django-shop up to 1.2.4. Affected is an unknown function of the file shop/models/inventory.py of the component Purchase Stock Handler. The manipulation leads to race condition. The attack is possible to be carried out remotely. The attack is considered to have high complexity.… | |
| Aplazada | Crítica (10) | 0.75% | — | Prestashop PS FacetedsearchAI | 17/7/2026 | 23/7/2026 | PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, and the value of a slider filter, price or weight, is taken from the URL without sufficient validation and stored in an internal… | |
| Aplazada | Media (4.3) | 0.41% | — | ShopwareAI | 17/7/2026 | 20/7/2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment in src/Core/Checkout/Payment/SalesChannel/HandlePaymentMethodRoute.php accepts a user-controlled orderId and forwards it to src/Core/Checkout/Payment/PaymentProcessor.php without verifying order… | |
| Aplazada | Media (4.9) | 0.48% | — | ShopwareAI | 17/7/2026 | 17/7/2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via the media manager without SVG content sanitization in the upload pipeline from MediaUploadController to… | |
| Aplazada | Media (6.5) | 0.39% | — | ShopwareAI | 17/7/2026 | 21/7/2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{transition} and similar transaction and delivery transition routes in src/Core/Checkout/Order/Api/OrderActionController.php do not declare PlatformRequest::ATTRIBUTE_ACL or… | |
| Aplazada | Media (6.5) | 0.47% | — | ShopwareAI | 17/7/2026 | 18/7/2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the admin field, so a non-admin API user with user:create or user:update ACL permission can set admin: true… | |
| Aplazada | Media (6.8) | 0.46% | — | ShopwareAI | 17/7/2026 | 17/7/2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering POST /api/_action/user/user-recovery, reading the password recovery hash through POST /api/search/user-recovery, and using PATCH… | |
| Aplazada | Media (6.5) | 0.47% | — | ShopwareAI | 17/7/2026 | 17/7/2026 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API POST /api/_action/sync; the regular integration endpoint POST /api/integration blocks… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 14/7/2026 | 15/7/2026 | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now… | |
| Aplazada | Alta (7.1) | 0.32% | — | Themehunk Open ShopAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Open Shop: from n/a through <= 1.7.1. | |
| Aplazada | Media (4.5) | 0.43% | — | PrestashopAI | 13/7/2026 | 13/7/2026 | In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation of the ‘Alias’ parameter in the ‘Update your address’ function. This flaw allows an attacker to inject malicious expressions that are executed when the information is exported… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 9/7/2026 | 9/7/2026 | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of the file /login.php. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 4/7/2026 | 6/7/2026 | A vulnerability was identified in SourceCodester Simple and Nice Shopping Cart Script 1.0. Affected is an unknown function of the file /admin/girlsproductdeletequery.php. Such manipulation of the argument user_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 4/7/2026 | 6/7/2026 | A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /admin/mensproductdeletequery.php. This manipulation of the argument user_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Simple AND Nice Shopping Cart ScriptAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been made public and… | |
| Aplazada | Alta (7.5) | 0.43% | — | Shopify ContributorAI | 2/7/2026 | 2/7/2026 | Contributor Local File Inclusion in Shopify <= 1.0.0 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Artisanworkshop Japanized FOR WoocommerceAI | 29/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions. | |
| Aplazada | Media (4.3) | 0.27% | — | Shoppable Images LiteAI | 26/6/2026 | 26/6/2026 | Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions. | |
| Analizada | Media (6.9) | 0.45% | — | Joomtech Easy Shop | 19/6/2026 | 21/8/2026 | Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task set to ajax.loadImage, and a… | |
| Aplazada | Crítica (9.3) | 0.60% | 💥 PoC | JTL ShopAI | 18/6/2026 | 23/6/2026 | JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to read sensitive server-side values such… |