Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

3237 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—Product Variations Swatches FOR WoocommerceAI3/9/20264/9/2026
Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.
AnalizadaBaja (3.7)0.26%—Centarro Commerce Cybersource2/9/202616/9/2026
Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.
AnalizadaCrítica (9.1)0.40%—Centarro Commerce Paypal2/9/20268/9/2026
Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
AplazadaMedia (5.3)0.31%—Wpswings Ultimate Gift Cards FOR WoocommerceAI2/9/20262/9/2026
Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.
AplazadaAlta (7.5)0.42%—Appchee Woocommerce Product AttachmentAI2/9/20262/9/2026
Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.
AplazadaAlta (7.1)0.25%—Upsell Order Bump Offer FOR WoocommerceAI2/9/20262/9/2026
Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.
AplazadaMedia (4.9)0.27%—Shoppingcart Shopping Cart Ecommerce StoreAI1/9/20261/9/2026
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
AplazadaAlta (8.8)0.51%—Cusrev Customer Reviews FOR WoocommerceAI30/8/202631/8/2026
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
AplazadaCrítica (9.8)0.40%—Custom User Registration Fields FOR WoocommerceAI29/8/20261/9/2026
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in…
AplazadaAlta (7.2)0.42%—Cusrev Customer Reviews FOR WoocommerceAI28/8/202628/8/2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review comment text. The plugin accepts review…
AplazadaMedia (6.1)0.25%—Dayneks Software Industry AND Trade INC E-commerce PlatformAI28/8/202631/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue affects E-Commerce Platform: through 28082026. NOTE: The vendor was contacted early about this disclosure but did not…
AplazadaMedia (5.4)0.23%—Akilli Ticaret Software Technologies LTD E-commerce PackAI28/8/20262/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects E-Commerce Pack: from 4.5.001 before 4.6.001.
AplazadaMedia (4.3)0.28%—Softtr Informatics Technology Trading Limited E-commerce PackAI27/8/202628/8/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS). This issue affects E-Commerce Pack: before 5.03.01.49.
AplazadaAlta (8.5)0.36%—Woocart Suggestion Engine FOR WoocommerceAI27/8/202628/8/2026
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
AplazadaAlta (7.1)0.25%—Music Player FOR WoocommerceAI27/8/202628/8/2026
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
AplazadaAlta (8.6)0.36%—Mobile APP FOR WoocommerceAI27/8/202628/8/2026
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
Pendiente de análisisCrítica (9.3)0.23%—Google Vertex AI Search FOR CommerceAIGoogle BigqueryAI26/8/202631/8/2026
A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform allows an attacker knowing the victim's project number to obtain read/write access to staged data and error logs using predictable bucket names. This…
AplazadaAlta (7.5)0.32%—Woocommerce LotteryAI26/8/202626/8/2026
The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, 2.2.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
AplazadaMedia (6.5)0.27%—Wpswings Return Refund AND Exchange FOR WoocommerceAI26/8/202626/8/2026
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX actions it exposes to unauthenticated users, allowing them to read private order messages, post messages and attachments in the customer's name, and cancel return…
Pendiente de análisisCrítica (9.8)0.29%—Drupal Commerce ElavonAI25/8/202628/8/2026
Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.
AplazadaMedia (6.4)0.36%—Implecode Ecommerce Product CatalogAI25/8/202628/9/2026
The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaAlta (8.6)0.53%—Woocommerce File ApprovalAI24/8/202624/8/2026
Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
AplazadaMedia (4.3)0.28%—Woocommerce BookingsAI23/8/202626/8/2026
The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.
AplazadaMedia (6.5)0.87%—Webtoffee Woocommerce PDF Invoices Packing Slips Delivery Notes Shipping LabelsAI23/8/202624/8/2026
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaCrítica (9.8)0.71%—Automation WEB Platform Notifications AND OTP FOR WoocommerceAI21/8/202624/8/2026
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly…
Orbitaley — Vulnerabilidades