Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
3237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Product Variations Swatches FOR WoocommerceAI | 3/9/2026 | 4/9/2026 | Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. | |
| Analizada | Baja (3.7) | 0.26% | — | Centarro Commerce Cybersource | 2/9/2026 | 16/9/2026 | Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0. | |
| Analizada | Crítica (9.1) | 0.40% | — | Centarro Commerce Paypal | 2/9/2026 | 8/9/2026 | Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3. | |
| Aplazada | Media (5.3) | 0.31% | — | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 2/9/2026 | 2/9/2026 | Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Appchee Woocommerce Product AttachmentAI | 2/9/2026 | 2/9/2026 | Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Upsell Order Bump Offer FOR WoocommerceAI | 2/9/2026 | 2/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions. | |
| Aplazada | Media (4.9) | 0.27% | — | Shoppingcart Shopping Cart Ecommerce StoreAI | 1/9/2026 | 1/9/2026 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Alta (8.8) | 0.51% | — | Cusrev Customer Reviews FOR WoocommerceAI | 30/8/2026 | 31/8/2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Crítica (9.8) | 0.40% | — | Custom User Registration Fields FOR WoocommerceAI | 29/8/2026 | 1/9/2026 | The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in… | |
| Aplazada | Alta (7.2) | 0.42% | — | Cusrev Customer Reviews FOR WoocommerceAI | 28/8/2026 | 28/8/2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review comment text. The plugin accepts review… | |
| Aplazada | Media (6.1) | 0.25% | — | Dayneks Software Industry AND Trade INC E-commerce PlatformAI | 28/8/2026 | 31/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue affects E-Commerce Platform: through 28082026. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Aplazada | Media (5.4) | 0.23% | — | Akilli Ticaret Software Technologies LTD E-commerce PackAI | 28/8/2026 | 2/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects E-Commerce Pack: from 4.5.001 before 4.6.001. | |
| Aplazada | Media (4.3) | 0.28% | — | Softtr Informatics Technology Trading Limited E-commerce PackAI | 27/8/2026 | 28/8/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS). This issue affects E-Commerce Pack: before 5.03.01.49. | |
| Aplazada | Alta (8.5) | 0.36% | — | Woocart Suggestion Engine FOR WoocommerceAI | 27/8/2026 | 28/8/2026 | Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Music Player FOR WoocommerceAI | 27/8/2026 | 28/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. | |
| Aplazada | Alta (8.6) | 0.36% | — | Mobile APP FOR WoocommerceAI | 27/8/2026 | 28/8/2026 | Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions. | |
| Pendiente de análisis | Crítica (9.3) | 0.23% | — | Google Vertex AI Search FOR CommerceAIGoogle BigqueryAI | 26/8/2026 | 31/8/2026 | A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This… | |
| Aplazada | Alta (7.5) | 0.32% | — | Woocommerce LotteryAI | 26/8/2026 | 26/8/2026 | The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Media (6.5) | 0.27% | — | Wpswings Return Refund AND Exchange FOR WoocommerceAI | 26/8/2026 | 26/8/2026 | The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return… | |
| Pendiente de análisis | Crítica (9.8) | 0.29% | — | Drupal Commerce ElavonAI | 25/8/2026 | 28/8/2026 | Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*. | |
| Aplazada | Media (6.4) | 0.36% | — | Implecode Ecommerce Product CatalogAI | 25/8/2026 | 28/9/2026 | The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Alta (8.6) | 0.53% | — | Woocommerce File ApprovalAI | 24/8/2026 | 24/8/2026 | Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions. | |
| Aplazada | Media (4.3) | 0.28% | — | Woocommerce BookingsAI | 23/8/2026 | 26/8/2026 | The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products. | |
| Aplazada | Media (6.5) | 0.87% | — | Webtoffee Woocommerce PDF Invoices Packing Slips Delivery Notes Shipping LabelsAI | 23/8/2026 | 24/8/2026 | The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Aplazada | Crítica (9.8) | 0.71% | — | Automation WEB Platform Notifications AND OTP FOR WoocommerceAI | 21/8/2026 | 24/8/2026 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly… |