Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

257 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2)60%💥 ExploitSpa-cart Ecommerce CMS26/8/202322/9/2026
A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used.…
ModificadaMedia (6.1)0.36%—Phpscriptpoint Ecommerce24/7/202317/6/2026
A vulnerability, which was classified as problematic, was found in phpscriptpoint Ecommerce 1.15. This affects an unknown part of the file /product.php. The manipulation of the argument id leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235209 was assigned to this…
ModificadaMedia (6.1)0.36%—Phpscriptpoint Ecommerce24/7/202317/6/2026
A vulnerability, which was classified as problematic, has been found in phpscriptpoint Ecommerce 1.15. Affected by this issue is some unknown functionality of the file /blog-single.php. The manipulation of the argument slug leads to cross site scripting. The attack may be launched remotely. The identifier of this…
ModificadaMedia (6.1)0.34%—Activeitzone Active Ecommerce CMS4/7/202317/6/2026
A vulnerability was found in Active It Zone Active eCommerce CMS 6.5.0. It has been declared as problematic. This vulnerability affects unknown code of the file /ecommerce/support_ticket of the component Create Ticket Page. The manipulation of the argument details with the input <script>alert(1)</script> leads to…
ModificadaMedia (4.3)0.48%—Implecode Ecommerce Product Catalog1/7/202317/6/2026
The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.17. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save manual digital orders…
ModificadaMedia (4.3)0.48%—Implecode Ecommerce Product Catalog1/7/202317/6/2026
The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.43. This is due to missing or incorrect nonce validation on the implecode_save_products_meta() function. This makes it possible for unauthenticated attackers to save…
ModificadaCrítica (9.8)4.5%💥 ExploitWp-ecommerce Easy WP Smtp7/6/202317/6/2026
The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated attackers to modify the plugins settings…
ModificadaAlta (7.5)3.6%💥 ExploitTshirtecommerce Custom Product Designer1/6/202317/6/2026
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter type in the /tshirtecommerce/fonts.php endpoint, to allow a remote attacker to traverse directories on the system in order to open files (without…
ModificadaAlta (7.5)3.6%💥 ExploitTshirtecommerce Custom Product Designer1/6/202317/6/2026
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with the POST parameter file_name in the tshirtecommerce/ajax.php?type=svg endpoint, to allow a remote attacker to traverse directories on the system in order to open files…
ModificadaMedia (5.4)0.39%—Lightspeedhq Ecwid Ecommerce Shopping Cart8/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.4 versions.
ModificadaMedia (4.8)0.39%—Implecode Ecommerce Product Catalog7/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress plugin <= 3.3.4 versions.
ModificadaCrítica (9.8)1.2%—202-ecommerce Paypal31/3/202317/6/2026
PrestaShop/paypal is an open source module for the PrestaShop web commerce ecosystem which provides paypal payment support. A SQL injection vulnerability found in the PrestaShop paypal module from release from 3.12.0 to and including 3.16.3 allow a remote attacker to gain privileges, modify data, and potentially…
ModificadaCrítica (9.8)3.3%💥 ExploitTshirtecommerce Custom Product Designer22/3/202317/6/2026
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions hookActionCartSave and updateCustomizationTable, which…
ModificadaCrítica (9.8)3.3%💥 ExploitTshirtecommerce Custom Product Designer22/3/202317/6/2026
An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could lead to a SQL injection. This is…
ModificadaMedia (4.8)0.38%—Implecode Ecommerce Product Catalog17/3/202317/6/2026
The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
ModificadaAlta (8.8)0.26%—Lightspeedhq Ecwid Ecommerce Shopping Cart14/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions.
ModificadaAlta (8.8)0.83%—202-ecommerce Administrative Mandate2/2/20239/7/2026
PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability.
ModificadaMedia (6.1)0.61%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap20/1/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php.
ModificadaAlta (8.8)1.5%—Wp-ecommerce Easy WP Smtp6/12/202217/6/2026
Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
ModificadaMedia (6.5)0.84%—Wp-ecommerce Easy WP Smtp6/12/202217/6/2026
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
ModificadaAlta (8.1)0.90%—Wp-ecommerce Easy WP Smtp6/12/202217/6/2026
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.
ModificadaMedia (6.1)0.49%—Ecommerce-website Project Ecommerce-website5/12/202217/6/2026
A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter.
ModificadaAlta (7.2)1.2%—Wp-ecommerce Easy WP Smtp31/10/202217/6/2026
The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
ModificadaMedia (4.3)0.58%—Lightspeedhq Ecwid Ecommerce Shopping Cart6/9/202217/6/2026
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options…
ModificadaMedia (6.1)0.59%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap18/8/202217/6/2026
Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php.