Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1833 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.24% | — | Hasthemes ShoplentorAI | 27/5/2026 | 24/7/2026 | The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blockUniqId' block attribute in multiple Product Gride blocks in versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Baja (1.9) | 0.35% | — | Sourcecodester SUP Online ShoppingAI | 24/5/2026 | 23/7/2026 | A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The manipulation of the argument productName leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and… | |
| Aplazada | Media (5.5) | 0.41% | — | Projectworlds Online ART Gallery ShopAI | 24/5/2026 | 23/7/2026 | A flaw has been found in projectworlds Online Art Gallery Shop 1.0. Impacted is an unknown function of the file /admin/adminHome.php. Executing a manipulation of the argument social_linked can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. | |
| Aplazada | Media (5.3) | 0.13% | — | SmartshopAI | 23/5/2026 | 23/7/2026 | Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by tricking authenticated users into submitting malicious requests. Attackers can craft HTML forms targeting editprofile.php with hidden fields for email and password parameters that execute automatically when… | |
| Aplazada | Alta (8.8) | 0.33% | — | SmartshopAI | 23/5/2026 | 23/7/2026 | Smartshop 1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'searched' parameter in search.php. Attackers can send GET requests with malicious SQL payloads like SLEEP commands to extract sensitive database… | |
| Aplazada | Alta (8.8) | 0.33% | — | SmartshopAI | 23/5/2026 | 23/7/2026 | Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to product.php with union-based SQL injection payloads in the id parameter to extract sensitive database… | |
| Aplazada | Alta (8.8) | 0.33% | — | SmartshopAI | 23/5/2026 | 23/7/2026 | Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to category.php with UNION-based SQL injection payloads in the id parameter to extract sensitive database… | |
| Aplazada | Alta (7.3) | 0.31% | — | InnoshopAI | 19/5/2026 | 24/7/2026 | An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly access backend application interfaces, leading to further dangerous operations. | |
| Aplazada | Alta (7.5) | 0.52% | — | Prestashop UpsshippingAI | 18/5/2026 | 17/6/2026 | An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upsshipping/logs/, and /modules/upsshipping/lib/UPSBaseApi.php components | |
| Aplazada | Media (5.3) | 0.16% | — | Joomla JoomocshopAI | 17/5/2026 | 17/6/2026 | Joomla JoomOCShop 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML forms targeting account endpoints like /joomoc2/?route=account/edit and to modify user information or reset passwords… | |
| Aplazada | Crítica (9.3) | 0.42% | — | PrestashopAI | 14/5/2026 | 17/6/2026 | PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scripting (XSS) vulnerability in the PrestaShop back-office Customer Service view. An unauthenticated attacker can submit the public Contact Us form with a malicious email address. The payload is stored in… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester SUP Online ShoppingAI | 8/5/2026 | 17/6/2026 | A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the file /admin/replymsg.php. The manipulation of the argument msgid results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester SUP Online ShoppingAI | 8/5/2026 | 17/6/2026 | A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /admin/message.php. The manipulation of the argument seenid leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester SUP Online ShoppingAI | 8/5/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file wishlist.php. Executing a manipulation of the argument delwlistid can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester SUP Online ShoppingAI | 8/5/2026 | 17/6/2026 | A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the file /admin/viewmsg.php. Performing a manipulation of the argument msgid results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be… | |
| Aplazada | Media (5.5) | 0.69% | — | Innocommerce InnoshopAI | 2/5/2026 | 17/6/2026 | A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallServiceProvider::boot of the file innopacks/install/src/InstallServiceProvider.php of the component Installation Endpoint. The manipulation leads to improper authentication. Remote exploitation of the… | |
| Aplazada | Media (5.4) | 0.24% | — | ShopizerAI | 30/4/2026 | 17/6/2026 | Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer v3.2.5 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the getInputStream() or getReader() functions. | |
| Aplazada | Crítica (10) | 0.64% | — | ShopizerAI | 30/4/2026 | 17/6/2026 | A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request. | |
| Aplazada | Baja (2) | 0.33% | — | LikeshopAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in likeadmin-likeshop likeadmin_php up to 1.9.6. Affected by this issue is the function queryResult of the file server\app\adminapi\lists\tools\DataTableLists.php of the component dataTable Admin API. The manipulation leads to sql injection. The attack is possible to be carried out… | |
| Analizada | Alta (8.6) | 0.31% | — | Adobe Photoshop Installer | 15/4/2026 | 29/7/2026 | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation… | |
| Aplazada | Alta (8.4) | 0.56% | — | Codethat ShoppingcartAI | 15/4/2026 | 17/6/2026 | Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field | |
| Analizada | Alta (7.8) | 0.29% | — | Adobe Photoshop | 14/4/2026 | 28/8/2026 | Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this… | |
| Aplazada | Media (6.4) | 0.35% | — | Hasthemes ShoplentorAI | 14/4/2026 | 17/6/2026 | The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shortcode's button_text attribute in all versions up to, and including, 3.3.5. This is due to insufficient input sanitization and missing output escaping on user-supplied shortcode attributes. This makes… | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Computer AND Mobile Repair Shop Management SystemAI | 13/4/2026 | 17/6/2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/admin/clients/manage_client.php |