Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

241 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.45%—Peprodev Ultimate Invoice17/3/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate Invoice: from n/a through 1.9.7.
ModificadaAlta (8.8)0.22%—Rednao Woocommerce PDF Invoice Builder16/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in RedNao WooCommerce PDF Invoice Builder.This issue affects WooCommerce PDF Invoice Builder: from n/a through 1.2.101.
ModificadaAlta (8.8)0.97%—Acowebs PDF Invoices AND Packing Slips FOR Woocommerce7/3/202417/6/2026
The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.7 via deserialization of untrusted input via the order_id parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
AnalizadaAlta (8.8)0.50%—Ethercreation Generate Barcode ON Invoice / Delivery Slip23/2/202417/6/2026
In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.
ModificadaAlta (7.2)0.58%—Wpovernight Woocommerce PDF Invoices& Packing Slips27/1/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce.This issue affects PDF Invoices & Packing Slips for WooCommerce: from n/a through 3.7.5.
ModificadaMedia (6.1)0.52%—Tychesoftwares Print Invoice & Delivery Notes FOR Woocommerce16/1/202417/6/2026
The Print Invoice & Delivery Notes for WooCommerce WordPress plugin before 4.7.2 is vulnerable to reflected XSS by echoing a GET value in an admin note within the WooCommerce orders page. This means that this vulnerability can be exploited for users with the edit_others_shop_orders capability. WooCommerce must be…
ModificadaMedia (6.1)0.27%—Usabilitydynamics Wp-invoice16/1/202417/6/2026
The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them
ModificadaMedia (6.5)0.38%—Webtoffee Woocommerce PDF Invoices, Packing Slips, Delivery Notes AND Shipping Labels3/1/202417/6/2026
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on theprint_packinglist action in all versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with…
ModificadaMedia (6.1)0.47%—Crmperks Integration FOR Woocommerce AND Zoho Crm, Books, Invoice, Inventory, Bigin19/12/202317/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin.This issue affects Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin: from n/a before 1.3.7.
ModificadaMedia (6.1)0.75%—Oretnom23 Simple Invoice Generator System10/12/202317/6/2026
A vulnerability was found in SourceCodester Simple Invoice Generator System 1.0 and classified as problematic. This issue affects some unknown processing of the file login.php. The manipulation of the argument cashier leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed…
ModificadaAlta (7.5)0.45%—E-invoice Project E-invoice27/10/202317/6/2026
Improper Protection for Outbound Error Messages and Alert Signals vulnerability in EDM Informatics E-invoice allows Account Footprinting. This issue affects E-invoice: before 2.1.
ModificadaMedia (6.1)0.33%—Rednao Woocommerce PDF Invoice Builder26/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao WooCommerce PDF Invoice Builder, Create invoices, packing slips and more plugin <= 1.2.102 versions.
ModificadaMedia (4.3)0.54%—Rednao Woocommerce PDF Invoice Builder31/8/202317/6/2026
The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the GetInvoiceDetail function in versions up to, and including, 1.2.89. This makes it possible for subscribers to view arbitrary invoices provided they can guess the order id and invoice…
ModificadaMedia (4.3)0.31%—Rednao Woocommerce PDF Invoice Builder31/8/202317/6/2026
The WooCommerce PDF Invoice Builder for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the SaveCustomField function in versions up to, and including, 1.2.90. This makes it possible for unauthenticated attackers to create invoice fields provided they can trick an admin into…
ModificadaMedia (4.8)0.49%—Rednao Woocommerce PDF Invoice Builder31/8/202317/6/2026
The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.90 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and…
ModificadaMedia (4.3)0.29%—Rednao Woocommerce PDF Invoice Builder31/8/202317/6/2026
The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.90. This is due to missing or incorrect nonce validation on the Save function. This makes it possible for unauthenticated attackers to make changes to invoices via a forged request…
ModificadaAlta (8.8)0.80%—Rednao Woocommerce PDF Invoice Builder31/8/202317/6/2026
The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in versions up to, and including, 1.2.89 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for subscribers or…
ModificadaAlta (7.5)0.54%—Infodrom E-invoice Approval System25/7/202317/6/2026
Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable. This issue affects E-Invoice Approval System: before v.20230701.
ModificadaCrítica (9.8)0.63%—Infodrom E-invoice Approval System25/7/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection. This issue affects E-Invoice Approval System: before v.20230701.
ModificadaMedia (6.1)2.2%💥 ExploitSquarepiginteractive Fusioninvoice25/5/202317/6/2026
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details.
ModificadaAlta (7.5)0.87%—Kiwiz Invoices Certification & PDF System Project Kiwiz Invoices Certification & PDF System15/5/202317/6/2026
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)
ModificadaMedia (4.3)0.23%—Wpovernight Woocommerce PDF Invoices& Packing Slips1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.
ModificadaMedia (6.1)0.53%—Invoiceplane7/2/202317/6/2026
Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.
ModificadaAlta (7.2)0.98%—WEB Invoice Project WEB Invoice2/1/202317/6/2026
The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit…
ModificadaAlta (7.2)0.98%—Mohanjith WEB Invoice2/1/202317/6/2026
The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit…
Orbitaley — Vulnerabilidades