Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
182 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.54% | — | Wpplugin Accept Donations With Paypal | 24/1/2022 | 17/6/2026 | The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog | |
| Modificada | Media (4.8) | 0.62% | — | Wpplugin Accept Donations With Paypal | 17/11/2021 | 17/6/2026 | The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created Buttons, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (4.3) | 0.47% | — | Wpplugin Accept Donations With Paypal | 1/11/2021 | 17/6/2026 | The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are internally stored as posts. The deletion of a button is not CSRF protected and there is no control to check if the deleted post was a button post. As a result, an attacker could make logged in admins… | |
| Modificada | Media (4.3) | 0.50% | — | Wpplugin Accept Donations With Paypal | 1/11/2021 | 17/6/2026 | The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which internally are posts. The process to create a new button is lacking a CSRF check. An attacker could use this to make an authenticated admin create a new button. Furthermore, one of the Button field is not… | |
| Modificada | Alta (7.5) | 1.5% | — | Sylius Paypal | 5/10/2021 | 17/6/2026 | sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was created with autoincremented payment id (/pay-with-paypal/{id}) and therefore it was easy to predict. The problem is that the Credit card form has prefilled "credit card… | |
| Modificada | Crítica (9.8) | 95% | 💥 Exploit | Ithemes Paypal PRO | 2/7/2020 | 17/6/2026 | The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection. | |
| Modificada | Media (5.3) | 1.0% | — | Idea Paypal-adaptive | 23/4/2020 | 17/6/2026 | paypal-adaptive through 0.4.2 manipulation of JavaScript objects resulting in Prototype Pollution. The PayPal function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Alta (8.8) | 0.85% | — | Ultra-prod Wordpress Ultra Simple Paypal Shopping Cart | 12/9/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (5.3) | 1.1% | — | Woocommerce Paypal Checkout Payment Gateway | 29/8/2019 | 17/6/2026 | cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be… | |
| Modificada | Media (6.1) | 0.95% | — | Webdevstudios Ithemes Paypal PRO | 28/8/2019 | 17/6/2026 | PayPal Pro Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |
| Modificada | Media (6.1) | 0.94% | — | Codepeople CP Contact Form With Paypal | 15/8/2019 | 17/6/2026 | The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition. | |
| Modificada | Media (5.4) | 0.80% | — | Codepeople CP Contact Form With Paypal | 9/8/2019 | 17/6/2026 | The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter. | |
| Modificada | Media (6.1) | 1.2% | — | Paypal Adaptive Payments SDK | 10/7/2019 | 17/6/2026 | paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution | |
| Modificada | Media (6.5) | 5.9% | 💥 Exploit | Woocommerce Paypal Checkout Payment Gateway | 21/3/2019 | 17/6/2026 | cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter Tampering in an amount parameter (such as amount_1), as demonstrated by purchasing an item for lower than the intended price. NOTE: The plugin author states it is true that the amount can be… | |
| Modificada | Media (5.4) | 0.80% | — | Paypal PHP Permissions SDK | 2/8/2018 | 17/6/2026 | paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution. | |
| Modificada | Media (5.4) | 0.80% | — | Paypal PHP Invoice SDK | 2/8/2018 | 17/6/2026 | paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution. | |
| Modificada | Media (5.9) | 1.2% | — | Paypal-ipn Project Paypal-ipn | 29/5/2018 | 17/6/2026 | paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal site or the sandbox. With a bit of time, an attacker could craft a request using the simulator that would fool any application which does not explicitly check for… | |
| Modificada | Alta (8.1) | 2.0% | — | Paypal | 27/4/2018 | 17/6/2026 | The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system. | |
| Modificada | Alta (7.4) | 1.8% | — | Paypal | 27/4/2018 | 17/6/2026 | WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information. | |
| Modificada | Media (6.1) | 1.8% | — | Codepeople Payment Form FOR Paypal PRO | 27/12/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the cal parameter. | |
| Modificada | Alta (7.2) | 2.0% | — | Cfpaypal CP Contact Form With Paypal | 30/9/2017 | 17/6/2026 | The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has SQL injection via the cp_contactformpp_id parameter to cp_contactformpp.php. | |
| Modificada | Alta (8.8) | 1.0% | — | Codepeople CP Contact Form With Paypal | 30/9/2017 | 17/6/2026 | The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php. | |
| Modificada | Media (6.1) | 1.2% | — | Paypal Merchant-sdk-php | 24/2/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter. | |
| Modificada | Media (5) | 16% | 💥 Exploit | Intelligent-it Paypal Currency Converter Basic FOR Woocommerce | 24/6/2015 | 17/6/2026 | Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before 1.4 for WordPress allows remote attackers to read arbitrary files via a full pathname in the requrl parameter. |