Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
201 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Woocommerce Stripe Payment Gateway | 14/6/2023 | 17/6/2026 | Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin <= 7.4.0 versions. | |
| Modificada | Media (6.5) | 0.42% | — | Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe | 3/6/2023 | 17/6/2026 | The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function. This makes it possible… | |
| Modificada | Media (5.4) | 0.76% | — | Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe | 3/6/2023 | 17/6/2026 | The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 1.3.1 due to insufficient input sanitization… | |
| Modificada | Media (6.1) | 0.42% | — | Silverstripe Framework | 26/4/2023 | 17/6/2026 | Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an attacker can display a link to a third party website on a login screen by convincing a legitimate content author to follow a specially crafted link. Users should upgrade to… | |
| Modificada | Media (4.3) | 0.49% | — | Silverstripe Framework | 26/4/2023 | 17/6/2026 | Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, the GridField print view incorrectly validates the permission of DataObjects potentially allowing a content author to view records they are not authorised to access. Users… | |
| Modificada | Media (5.4) | 0.39% | — | Bigfork Silverstripe Form Capture | 3/4/2023 | 17/6/2026 | Silverstripe Form Capture provides a method to capture simple silverstripe forms and an admin interface for users. Starting in version 0.2.0 and prior to versions 1.0.2, 1.1.0, 2.2.5, and 3.1.1, improper escaping when presenting stored form submissions allowed for an attacker to perform a Cross-Site Scripting attack.… | |
| Modificada | Alta (7.5) | 1.1% | — | Silverstripe Graphql | 16/3/2023 | 17/6/2026 | `silverstripe/graphql` serves Silverstripe data as GraphQL representations. In versions 4.2.2 and 4.1.1, an attacker could use a specially crafted graphql query to execute a denial of service attack against a website which has a publicly exposed graphql endpoint. This mostly affects websites with particularly… | |
| Modificada | Alta (8.8) | 0.26% | — | Hmplugin Accept Stripe Donation - Aidwp | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin Accept Stripe Donation – AidWP plugin <= 3.1.5 versions. | |
| Modificada | Crítica (9.8) | 0.85% | — | Stripe Payment PRO | 1/3/2023 | 17/6/2026 | The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modificada | Media (4.3) | 0.23% | — | Checkoutplugins Stripe Payments FOR Woocommerce | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce plugin <= 1.4.10 leads to settings change. | |
| Modificada | Crítica (9.8) | 0.67% | — | Webbuildersgroup Silverstripe-kapost-bridge | 10/2/2023 | 17/6/2026 | A vulnerability was found in webbuilders-group silverstripe-kapost-bridge 0.3.3. It has been declared as critical. Affected by this vulnerability is the function index/getPreview of the file code/control/KapostService.php. The manipulation leads to sql injection. The attack can be launched remotely. Upgrading to… | |
| Modificada | Alta (7.5) | 0.54% | — | Silverstripe Subsites | 21/12/2022 | 17/6/2026 | Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions. | |
| Modificada | Media (5.4) | 0.48% | — | Noorsplugin WP Stripe Checkout | 19/12/2022 | 17/6/2026 | The WP Stripe Checkout WordPress plugin before 1.2.2.21 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.55% | — | Silverstripe Framework | 23/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3). | |
| Modificada | Media (5.4) | 0.56% | — | Silverstripe | 23/11/2022 | 17/6/2026 | Silverstripe silverstripe/cms through 4.11.0 allows XSS. | |
| Modificada | Media (5.4) | 0.63% | — | Silverstripe Framework | 23/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view. | |
| Modificada | Media (5.4) | 0.55% | — | Silverstripe Framework | 23/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2). | |
| Modificada | Media (5.4) | 0.51% | — | Silverstripe Framework | 23/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters. | |
| Modificada | Media (5.4) | 0.68% | — | Silverstripe Asset AdminSilverstripe AssetsSilverstripe Framework | 23/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin through 1.11.0 allow XSS. | |
| Modificada | Media (6.1) | 0.50% | — | Silverstripe Framework | 22/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build or /Security/login request. | |
| Modificada | Alta (8.8) | 0.77% | — | Silverstripe Framework | 21/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 allows SQL Injection. | |
| Modificada | Media (5.4) | 0.56% | — | Silverstripe Framework | 21/11/2022 | 17/6/2026 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 2 of 3). | |
| Modificada | Media (4.8) | 0.59% | — | Tipsandtricks-hq Accept Stripe | 17/7/2022 | 17/6/2026 | The Accept Stripe Payments WordPress plugin before 2.0.64 does not sanitize and escape some of its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.4) | 0.54% | — | Silverstripe | 29/6/2022 | 17/6/2026 | In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR). | |
| Modificada | Media (4.3) | 1.2% | — | Silverstripe Assets | 28/6/2022 | 17/6/2026 | Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to be published by changing an existing image short code on website content. |