Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

364 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.49%—Campcodes Online Shopping Portal19/5/202517/6/2026
A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /my-cart.php. The manipulation of the argument billingaddress leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…
AnalizadaMedia (6.9)0.51%—Campcodes Online Shopping Portal19/5/202517/6/2026
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. This issue affects some unknown processing of the file /my-account.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and…
AnalizadaMedia (6.9)0.54%—Campcodes Online Shopping Portal18/5/202517/6/2026
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
AnalizadaBaja (3.5)0.32%—Vk011 Real WP Shop Lite Ajax Ecommerce Shopping Cart15/5/202517/6/2026
The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…
AnalizadaMedia (5.4)0.28%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart1/5/202517/6/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' shortcode in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalizadaMedia (5.3)0.36%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart1/5/202517/6/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 via the 'process_payment_data' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the quantity of a…
AnalizadaMedia (6.5)0.41%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart1/5/202517/6/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.3 due to lack of randomization of a user controlled key. This makes it possible for unauthenticated attackers to access customer shopping carts and edit product links, add…
AplazadaAlta (7.5)0.53%—Wordpress Simple Shopping CartAI23/4/202517/6/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up to, and including, 5.1.2. This is due to a logic flaw involving the inconsistent use of parameters during the cart addition process. The plugin uses the parameter 'product_tmp_two' for computing a…
AplazadaAlta (8.2)0.40%—Wordpress Simple Shopping CartAI23/4/202517/6/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' parameter. This makes it possible for unauthenticated attackers to view potentially sensitive information and download a digital product without paying…
AplazadaMedia (6.5)0.40%—Ecwid Shopping CartAI4/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-cart allows Stored XSS.This issue affects Ecwid Shopping Cart: from n/a through <= 7.0.
AnalizadaMedia (6.9)0.62%—Code-projects Shopping Portal4/3/202517/6/2026
A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. This affects an unknown part of the file /Shopping/Admin/index.php of the component Login. The manipulation of the argument password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (6.9)0.65%—Codezips Online Shopping Website4/3/202517/6/2026
A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects some unknown processing of the file /cart_add.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may…
AnalizadaMedia (6.9)0.62%—Codezips Online Shopping Website3/3/202517/6/2026
A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unknown code of the file /success.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.3)0.52%—Phpgurukul Online Shopping Portal3/3/202517/6/2026
A vulnerability was found in PHPGurukul Online Shopping Portal 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /product-details.php. The manipulation of the argument quality/price/value/name/summary/review leads to sql injection. The attack can be launched…
AnalizadaBaja (3.4)0.36%—Webdesigner-profi Joomshopping25/2/202517/6/2026
A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the country management area in backend.
ModificadaMedia (5.3)0.42%—Phpgurukul Online Shopping Portal23/2/202517/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul/Campcodes Online Shopping Portal 2.1. This affects an unknown part of the file /search-result.php. The manipulation of the argument Product leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed…
AnalizadaMedia (4.3)0.18%—Lightspeedhq Ecwid Ecommerce Shopping Cart18/2/202517/6/2026
The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it possible for unauthenticated attackers to send…
AnalizadaAlta (8.8)0.76%—Phpgurukul Online Shopping Portal Project14/2/202517/6/2026
A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to execute arbitrary code via orderid POST request parameter.
ModificadaAlta (8.8)0.70%—Fabian Shopping Portal6/2/202517/6/2026
In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.
AplazadaMedia (5.3)0.35%—Shopping Cart Ecommerce StoreAI8/1/202517/6/2026
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible for unauthenticated attackers to modify order statuses.
AplazadaMedia (5.3)0.37%—Optimize Your Campaigns Google Shopping Google ADS Google AdwordsAI7/1/202517/6/2026
The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.1 due to the print_php_information.php being publicly accessible. This makes it possible for unauthenticated attackers to extract sensitive…
AplazadaMedia (6.4)0.37%—Fabian Simple Shopping CartAI24/12/202417/6/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' and 'wp_cart_display_product' shortcodes in all versions up to, and including, 5.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
AplazadaMedia (5.4)0.26%—Simple Ecommerce Shopping CartAI7/12/202417/6/2026
The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'save_settings', 'export_csv', and 'simpleecommcart-action' actions in all versions up to, and including, 3.1.2. This makes it possible for…
AplazadaMedia (6.1)0.30%—Simple Ecommerce Shopping Cart PluginAI7/12/202417/6/2026
The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘monthly_sales_current_year’ parameter in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.1)0.18%—Irish Cathal Continue Shopping From CartAI2/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Irish_Cathal Continue Shopping From Cart continue-shopping-from-cart-page allows Stored XSS.This issue affects Continue Shopping From Cart: from n/a through <= 1.3.
Orbitaley — Vulnerabilidades