Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

257 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)1.9%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202417/6/2026
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component.
AnalizadaAlta (8)1.1%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202417/6/2026
SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Orders_model.php component.
AnalizadaCrítica (9.8)1.9%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202417/6/2026
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component.
AnalizadaMedia (6.1)0.57%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability classified as problematic has been found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. This affects an unknown part of the file login.php. The manipulation of the argument txtAddress leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (6.1)0.57%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file prodInfo.php. The manipulation of the argument prodId leads to cross site scripting. The attack may be launched remotely. The…
ModificadaMedia (5.4)0.52%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file prodList.php. The manipulation of the argument prodType leads to cross site scripting. The attack can be launched remotely.…
ModificadaMedia (5.4)0.52%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been classified as problematic. Affected is an unknown function of the file search.php. The manipulation of the argument txtSearch leads to cross site scripting. It is possible to launch the attack remotely. The exploit has…
ModificadaAlta (8.8)0.66%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0 and classified as critical. This issue affects some unknown processing of the file prodInfo.php. The manipulation of the argument prodId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to…
AnalizadaAlta (7.5)0.60%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability has been found in Kashipara Online Furniture Shopping Ecommerce Website 1.0 and classified as critical. This vulnerability affects unknown code of the file prodList.php. The manipulation of the argument prodType leads to sql injection. The attack can be initiated remotely. The exploit has been…
AnalizadaAlta (7.5)0.60%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability, which was classified as critical, was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. This affects an unknown part of the file search.php. The manipulation of the argument txtSearch leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AplazadaAlta (7.1)0.37%—Implecode Ecommerce Product CatalogAI18/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog allows Reflected XSS.This issue affects eCommerce Product Catalog: from n/a through 3.3.32.
AplazadaMedia (4.3)0.21%—Implecode Ecommerce Product CatalogAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in impleCode eCommerce Product Catalog.This issue affects eCommerce Product Catalog: from n/a through 3.3.28.
AplazadaAlta (8.8)0.56%—Wpsafe Shopping Cart Ecommerce StoreAI12/4/202417/6/2026
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection via the 'productid' attribute of the ec_addtocart shortcode in all versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
AplazadaMedia (6.4)0.35%—Lightspeedhq Ecwid Ecommerce Shopping CartAI9/4/202417/6/2026
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.12.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
AnalizadaCrítica (9.8)0.68%—Codeastro Ecommerce Website9/3/202417/6/2026
A vulnerability classified as critical was found in CodeAstro Ecommerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file action.php of the component Search. The manipulation of the argument cat_id/brand_id/keyword leads to sql injection. The attack can be launched remotely. The exploit…
AplazadaBaja (2.4)0.48%—Bdtask Isshue Multi Store Ecommerce Shopping Cart SolutionAI3/3/202417/6/2026
A vulnerability, which was classified as problematic, was found in Bdtask Isshue Multi Store eCommerce Shopping Cart Solution 4.0. This affects an unknown part of the file /dashboard/Cinvoice/manage_invoice of the component Manage Sale Page. The manipulation of the argument Title leads to cross site scripting. It is…
ModificadaMedia (6.1)0.18%—Lightspeedhq Ecwid Ecommerce Shopping Cart28/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: from n/a through 6.12.4.
ModificadaMedia (5.3)0.42%—ZAO WP Ecommerce28/2/202417/6/2026
The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all versions up to, and including, 3.15.1. This makes it possible for unauthenticated attackers to create arbitrary posts with arbitrary content.
ModificadaAlta (7.5)0.72%—Wp-ecommerce WP Ecommerce28/2/202417/6/2026
The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
ModificadaMedia (4.3)0.22%—Lightspeedhq Ecwid Ecommerce Shopping Cart16/1/202417/6/2026
The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
ModificadaAlta (7.5)0.48%—Implecode Ecommerce Product Catalog29/12/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress.This issue affects eCommerce Product Catalog Plugin for WordPress: from n/a through 3.3.26.
ModificadaMedia (6.5)0.28%—Implecode Ecommerce Product Catalog4/12/202317/6/2026
The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin pages, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as delete all products
ModificadaMedia (5.4)0.41%—Implecode Ecommerce Product Catalog23/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress plugin <= 3.3.26 versions.
ModificadaAlta (8.8)0.25%—Multidots Enhanced Ecommerce Google Analytics FOR Woocommerce4/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Enhanced Ecommerce Google Analytics for WooCommerce plugin <= 3.7.1 versions.
ModificadaBaja (2.1)32%💥 ExploitSpa-cart Ecommerce CMS26/8/202322/9/2026
A vulnerability has been found in SPA-Cart eCommerce CMS 1.9.0.3. The impacted element is an unknown function of the file /search of the component GET Parameter Handler. Such manipulation of the argument filter[brandid] leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to…
Orbitaley — Vulnerabilidades