Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

397 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.65%—Codezips Online Shopping Website4/3/202517/6/2026
A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects some unknown processing of the file /cart_add.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may…
AnalizadaMedia (6.9)0.62%—Codezips Online Shopping Website3/3/202517/6/2026
A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unknown code of the file /success.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.3)0.52%—Phpgurukul Online Shopping Portal3/3/202517/6/2026
A vulnerability was found in PHPGurukul Online Shopping Portal 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /product-details.php. The manipulation of the argument quality/price/value/name/summary/review leads to sql injection. The attack can be launched…
AnalizadaBaja (3.4)0.36%—Webdesigner-profi Joomshopping25/2/202517/6/2026
A SQL injection vulnerability in the JoomShopping component versions 1.0.0-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the country management area in backend.
ModificadaMedia (5.3)0.42%—Phpgurukul Online Shopping Portal23/2/202517/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul/Campcodes Online Shopping Portal 2.1. This affects an unknown part of the file /search-result.php. The manipulation of the argument Product leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed…
AnalizadaMedia (4.3)0.18%—Lightspeedhq Ecwid Ecommerce Shopping Cart18/2/202517/6/2026
The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it possible for unauthenticated attackers to send…
AnalizadaAlta (8.8)0.76%—Phpgurukul Online Shopping Portal Project14/2/202517/6/2026
A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to execute arbitrary code via orderid POST request parameter.
ModificadaAlta (8.8)0.70%—Fabian Shopping Portal6/2/202517/6/2026
In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.
AplazadaMedia (5.3)0.35%—Shopping Cart Ecommerce StoreAI8/1/202517/6/2026
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook function in all versions up to, and including, 5.7.8. This makes it possible for unauthenticated attackers to modify order statuses.
AplazadaMedia (5.3)0.37%—Optimize Your Campaigns Google Shopping Google ADS Google AdwordsAI7/1/202517/6/2026
The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.1 due to the print_php_information.php being publicly accessible. This makes it possible for unauthenticated attackers to extract sensitive…
AplazadaMedia (6.4)0.37%—Fabian Simple Shopping CartAI24/12/202417/6/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' and 'wp_cart_display_product' shortcodes in all versions up to, and including, 5.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
AplazadaMedia (5.4)0.26%—Simple Ecommerce Shopping CartAI7/12/202417/6/2026
The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'save_settings', 'export_csv', and 'simpleecommcart-action' actions in all versions up to, and including, 3.1.2. This makes it possible for…
AplazadaMedia (6.1)0.30%—Simple Ecommerce Shopping Cart PluginAI7/12/202417/6/2026
The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘monthly_sales_current_year’ parameter in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.1)0.18%—Irish Cathal Continue Shopping From CartAI2/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Irish_Cathal Continue Shopping From Cart continue-shopping-from-cart-page allows Stored XSS.This issue affects Continue Shopping From Cart: from n/a through <= 1.3.
ModificadaAlta (7.5)0.86%💥 PoCAdonesevangelista Agri-trading Online Shopping System14/11/202417/6/2026
A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the quant parameter when adding a product to the cart. By setting the quantity value to -0, an attacker can exploit a flaw in the application's total…
ModificadaAlta (8.8)0.52%💥 PoCNikoarroyocuraza Online Furniture Shopping Project13/11/202417/6/2026
A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
AnalizadaMedia (5.3)0.51%—Projectworlds Free Download Online Shopping System11/11/202417/6/2026
A vulnerability was found in Project Worlds Free Download Online Shopping System up to 192.168.1.88. It has been rated as critical. This issue affects some unknown processing of the file /online-shopping-webvsite-in-php-master/success.php. The manipulation of the argument id leads to sql injection. The attack may be…
AplazadaAlta (7.1)0.27%—Firework Shoppable Live VideoAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefan Backor Firework Shoppable Live Video firework-videos allows Reflected XSS.This issue affects Firework Shoppable Live Video: from n/a through <= 6.3.
AnalizadaMedia (5.3)0.39%—Phpgurukul Online Shopping Portal4/11/202417/6/2026
A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/two_tables.php. The manipulation of the argument scripts leads to cross site scripting. The attack can be…
AnalizadaMedia (5.3)0.43%—Phpgurukul Online Shopping Portal4/11/202417/6/2026
A vulnerability, which was classified as problematic, has been found in PHPGurukul Online Shopping Portal 2.0. Affected by this issue is some unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/js_data.php. The manipulation of the argument scripts leads to cross site…
AnalizadaMedia (5.3)0.40%—Phpgurukul Online Shopping Portal4/11/202417/6/2026
A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/html_table.php. The manipulation of the argument scripts leads to cross site scripting. The…
AnalizadaMedia (5.3)0.40%—Phpgurukul Online Shopping Portal4/11/202417/6/2026
A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. Affected is an unknown function of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/empty_table.php. The manipulation of the argument scripts leads to cross site scripting. It is possible to launch…
AnalizadaMedia (5.3)0.40%—Phpgurukul Online Shopping Portal4/11/202417/6/2026
A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dymanic_table.php. The manipulation of the argument scripts leads to cross site scripting. The…
AnalizadaMedia (5.3)0.39%—Phpgurukul Online Shopping Portal4/11/202417/6/2026
A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. This vulnerability affects unknown code of the file admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data_two_headers.php. The manipulation of the argument scripts leads to cross site scripting. The…
AnalizadaMedia (5.3)0.38%—Phpgurukul Online Shopping Portal4/11/202417/6/2026
A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data_th.php. The manipulation of the argument scripts leads to cross site scripting. The attack can be…