Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
202 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.98% | — | Compassplus Tranzware E-commerce Payment Gateway | 19/3/2021 | 17/6/2026 | /exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser. | |
| Modificada | Alta (8.8) | 1.9% | — | Welcart E-commerce | 7/11/2020 | 17/6/2026 | The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usces_unserialize. There is not a complete POP chain. | |
| Modificada | Media (6.1) | 1.2% | — | Cybercompay Swipehq-payment-gateway-wp-e-commerce | 27/12/2019 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) api_key, (2) payment_page_url, (3) merchant_id, (4) api_url, or (5) currency parameter. | |
| Modificada | Media (6.8) | 0.84% | — | SAP E-commerce | 12/6/2019 | 17/6/2026 | An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout, by injecting an HTML code in the application that will be executed whenever the victim logs in to the application even on a different… | |
| Modificada | Media (6.1) | 1.3% | — | SAP E-commerce | 14/5/2019 | 17/6/2026 | SAP E-Commerce (Business-to-Consumer) application does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Fixed in the following components SAP-CRMJAV SAP-CRMWEB SAP-SHRWEB SAP-SHRJAV SAP-CRMAPP SAP-SHRAPP, versions 7.30, 7.31, 7.32, 7.33, 7.54. | |
| Modificada | Media (6.1) | 0.95% | — | Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+4 | 20/12/2017 | 17/6/2026 | The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,… | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Secure E-commerce Script Project Secure E-commerce Script | 13/12/2017 | 17/6/2026 | Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | E-commerce MLM Software Project E-commerce MLM Software | 13/12/2017 | 17/6/2026 | E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter. | |
| Modificada | Alta (7.5) | 24% | 💥 Exploit | Wpshopstyling WP E-commerce Shop Styling | 23/5/2017 | 17/6/2026 | Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to includes/download.php. | |
| Modificada | Media (6.5) | 1.8% | — | Welcart E-commerce | 25/6/2016 | 17/6/2026 | The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress mishandles sessions, which allows remote attackers to obtain access by leveraging knowledge of the e-mail address associated with an account. | |
| Modificada | Media (6.1) | 1.5% | — | Welcart E-commerce | 25/6/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-4826. | |
| Modificada | Media (6.1) | 1.5% | — | Welcart E-commerce | 25/6/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-4827. | |
| Modificada | Media (5.6) | 2.9% | — | Welcart E-commerce | 25/6/2016 | 17/6/2026 | The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted serialized data. | |
| Modificada | Media (6.3) | 1.6% | — | Welcart E-commerce | 29/12/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in admin.php in the Collne Welcart plugin before 1.5.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) search[column] or (2) switch parameter. | |
| Modificada | Media (4.3) | 2.0% | — | Welcart E-commerce | 24/7/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Welcart plugin before 1.4.18 for WordPress allow remote attackers to inject arbitrary web script or HTML via the usces_referer parameter to (1) classes/usceshop.class.php, (2) includes/edit-form-advanced.php, (3) includes/edit-form-advanced30.php, (4)… | |
| Modificada | Alta (7.5) | 2.3% | — | Welcart E-commerce | 13/1/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in the Welcart e-Commerce plugin 1.3.12 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) changeSort or (2) switch parameter in the usces_itemedit page to wp-admin/admin.php. | |
| Modificada | Media (4.3) | 2.0% | — | Welcart E-commerce | 13/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Welcart e-Commerce plugin 1.3.12 for WordPress allow remote attackers to inject arbitrary web script or HTML via (1) unspecified vectors related to purchase_limit or the (2) name, (3) intl, (4) nocod, or (5) time parameter in an add_delivery_method action to… | |
| Modificada | Alta (7.5) | 2.1% | — | Getshopped WP E-commerce | 8/10/2012 | 16/6/2026 | SQL injection vulnerability in the WP e-Commerce plugin before 3.8.7.6 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 2.2% | — | Getshopped WP E-commerce | 23/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in wpsc-admin/display-sales-logs.php in WP e-Commerce plugin 3.8.7.1 and possibly earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the custom_text parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Martin LEE Multi-lingual E-commerce System | 3/9/2010 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Multi-lingual E-Commerce System 0.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) checkout2-CYM.php, (2) checkout2-EN.php, (3) checkout2-FR.php, (4) cat-FR.php, (5) cat-EN.php, (6) cat-CYM.php, (7)… | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Creasito E-commerce Content Manager | 12/7/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) admin/checkuser.php and (2) checkuser.php. | |
| Modificada | Media (6.8) | 7.1% | 💥 Exploit | Instinct E-commerce Plugin | 18/5/2009 | 16/6/2026 | Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/plugins/wp-shopping-cart/. | |
| Modificada | Alta (7.5) | 1.7% | — | E107LabgabMy123tkshop E-commerce-suiteOpendb+4 | 30/4/2008 | 16/6/2026 | The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitTorrent 1.2.2, (4) TorrentFlux 2.3, (5) e107 0.7.11, (6) WebZE 0.5.9, (7) Open Media Collectors Database (aka OpenDb) 1.5.0b4, and (8) Labgab 1.1 uses a code_bg.jpg… | |
| Modificada | Media (4.3) | 1.0% | — | Work System E-commerce | 16/4/2008 | 16/6/2026 | Multgiple cross-site scripting (XSS) vulnerabilities in module/main.php in WORK system e-commerce 4.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) day, (2) month, and (3) year parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | My123tkshop E-commerce-suite | 20/12/2007 | 16/6/2026 | SQL injection vulnerability in shop/mainfile.php in 123tkShop 0.9.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded value of the admin parameter to shop/admin.php. |