Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

1833 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.25%—Shoplentor PROAI23/7/202623/7/2026
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
AplazadaMedia (5.3)0.29%—Shoplentor PROAI23/7/202623/7/2026
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.
AplazadaMedia (6.4)0.32%—Mythemeshop WP ShortcodeAI23/7/202623/7/2026
The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and including, 1.4.17. This is due to insufficient input sanitization and output escaping in the mts_tabs() function, which outputs the title shortcode…
AplazadaMedia (5.3)0.44%—JoomshoppingAI22/7/202623/7/2026
Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.
AplazadaMedia (6.1)0.24%—HikashopAIJoomlaAI20/7/202623/7/2026
Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect.
AplazadaBaja (1.3)0.29%—Awesto Django-shopAI19/7/202620/7/2026
A vulnerability was identified in awesto django-shop up to 1.2.4. Affected is an unknown function of the file shop/models/inventory.py of the component Purchase Stock Handler. The manipulation leads to race condition. The attack is possible to be carried out remotely. The attack is considered to have high complexity.…
AplazadaCrítica (10)0.75%—Prestashop PS FacetedsearchAI17/7/202623/7/2026
PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, and the value of a slider filter, price or weight, is taken from the URL without sufficient validation and stored in an internal…
AplazadaMedia (4.3)0.41%—ShopwareAI17/7/202620/7/2026
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment in src/Core/Checkout/Payment/SalesChannel/HandlePaymentMethodRoute.php accepts a user-controlled orderId and forwards it to src/Core/Checkout/Payment/PaymentProcessor.php without verifying order…
AplazadaMedia (4.9)0.48%—ShopwareAI17/7/202617/7/2026
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via the media manager without SVG content sanitization in the upload pipeline from MediaUploadController to…
AplazadaMedia (6.5)0.39%—ShopwareAI17/7/202621/7/2026
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{transition} and similar transaction and delivery transition routes in src/Core/Checkout/Order/Api/OrderActionController.php do not declare PlatformRequest::ATTRIBUTE_ACL or…
AplazadaMedia (6.5)0.47%—ShopwareAI17/7/202618/7/2026
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the admin field, so a non-admin API user with user:create or user:update ACL permission can set admin: true…
AplazadaMedia (6.8)0.46%—ShopwareAI17/7/202617/7/2026
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering POST /api/_action/user/user-recovery, reading the password recovery hash through POST /api/search/user-recovery, and using PATCH…
AplazadaMedia (6.5)0.47%—ShopwareAI17/7/202617/7/2026
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API POST /api/_action/sync; the regular integration endpoint POST /api/integration blocks…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple AND Nice Shopping Cart ScriptAI14/7/202615/7/2026
A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now…
AplazadaAlta (7.1)0.32%—Themehunk Open ShopAI13/7/202613/7/2026
Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Open Shop: from n/a through <= 1.7.1.
AplazadaMedia (4.5)0.43%—PrestashopAI13/7/202613/7/2026
In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by inadequate validation of the ‘Alias’ parameter in the ‘Update your address’ function. This flaw allows an attacker to inject malicious expressions that are executed when the information is exported…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple AND Nice Shopping Cart ScriptAI9/7/20269/7/2026
A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of the file /login.php. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
AplazadaMedia (5.5)0.43%—Sourcecodester Simple AND Nice Shopping Cart ScriptAI4/7/20266/7/2026
A vulnerability was identified in SourceCodester Simple and Nice Shopping Cart Script 1.0. Affected is an unknown function of the file /admin/girlsproductdeletequery.php. Such manipulation of the argument user_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple AND Nice Shopping Cart ScriptAI4/7/20266/7/2026
A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /admin/mensproductdeletequery.php. This manipulation of the argument user_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple AND Nice Shopping Cart ScriptAI4/7/20266/7/2026
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been made public and…
AplazadaAlta (7.5)0.43%—Shopify ContributorAI2/7/20262/7/2026
Contributor Local File Inclusion in Shopify <= 1.0.0 versions.
AplazadaMedia (6.5)0.33%—Artisanworkshop Japanized FOR WoocommerceAI29/6/202629/6/2026
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
AplazadaMedia (4.3)0.27%—Shoppable Images LiteAI26/6/202626/6/2026
Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.
AnalizadaMedia (6.9)0.45%—Joomtech Easy Shop19/6/202621/8/2026
Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task set to ajax.loadImage, and a…
AplazadaCrítica (9.3)0.60%💥 PoCJTL ShopAI18/6/202623/6/2026
JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to read sensitive server-side values such…