Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

364 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.57%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability classified as problematic has been found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. This affects an unknown part of the file login.php. The manipulation of the argument txtAddress leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (6.1)0.57%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file prodInfo.php. The manipulation of the argument prodId leads to cross site scripting. The attack may be launched remotely. The…
ModificadaMedia (5.4)0.52%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file prodList.php. The manipulation of the argument prodType leads to cross site scripting. The attack can be launched remotely.…
ModificadaMedia (5.4)0.52%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been classified as problematic. Affected is an unknown function of the file search.php. The manipulation of the argument txtSearch leads to cross site scripting. It is possible to launch the attack remotely. The exploit has…
ModificadaAlta (8.8)0.66%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0 and classified as critical. This issue affects some unknown processing of the file prodInfo.php. The manipulation of the argument prodId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to…
AnalizadaAlta (7.5)0.60%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability has been found in Kashipara Online Furniture Shopping Ecommerce Website 1.0 and classified as critical. This vulnerability affects unknown code of the file prodList.php. The manipulation of the argument prodType leads to sql injection. The attack can be initiated remotely. The exploit has been…
AnalizadaAlta (7.5)0.60%—Aditya88 Online Furniture Shopping Ecommerce Website23/4/202417/6/2026
A vulnerability, which was classified as critical, was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. This affects an unknown part of the file search.php. The manipulation of the argument txtSearch leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AplazadaAlta (8.8)0.56%—Wpsafe Shopping Cart Ecommerce StoreAI12/4/202417/6/2026
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection via the 'productid' attribute of the ec_addtocart shortcode in all versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
AplazadaMedia (6.4)0.35%—Lightspeedhq Ecwid Ecommerce Shopping CartAI9/4/202417/6/2026
The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.12.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
AnalizadaMedia (6.1)0.51%—Campcodes Online Shopping System23/3/202417/6/2026
A vulnerability classified as problematic was found in Campcodes Online Shopping System 1.0. This vulnerability affects unknown code of the file /offersmail.php. The manipulation of the argument email leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and…
AplazadaBaja (2.4)0.48%—Bdtask Isshue Multi Store Ecommerce Shopping Cart SolutionAI3/3/202417/6/2026
A vulnerability, which was classified as problematic, was found in Bdtask Isshue Multi Store eCommerce Shopping Cart Solution 4.0. This affects an unknown part of the file /dashboard/Cinvoice/manage_invoice of the component Manage Sale Page. The manipulation of the argument Title leads to cross site scripting. It is…
AnalizadaCrítica (9.8)0.79%—Surya2developer Online Shopping System29/2/202417/6/2026
A vulnerability has been found in Surya2Developer Online Shopping System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Parameter Handler. The manipulation of the argument password with the input nochizplz'+or+1%3d1+limit+1%23…
ModificadaMedia (6.1)0.18%—Lightspeedhq Ecwid Ecommerce Shopping Cart28/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: from n/a through 6.12.4.
ModificadaMedia (4.8)0.30%—Tipsandtricks-hq Wordpress Simple Paypal Shopping Cart27/1/202417/6/2026
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the automatic redirect URL setting in all versions up to and including 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
ModificadaMedia (4.3)0.22%—Lightspeedhq Ecwid Ecommerce Shopping Cart16/1/202417/6/2026
The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
AnalizadaMedia (5.4)0.63%—Nayem-howlader SUP Online Shopping21/11/202317/6/2026
Cross Site Scripting in SUP Online Shopping v.1.0 allows a remote attacker to execute arbitrary code via the Name, Email and Address parameters in the Register New Account component.
ModificadaMedia (5.4)0.40%—Wpplugin Easy Paypal Shopping Cart16/11/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Scott Paterson Easy PayPal Shopping Cart plugin <= 1.1.10 versions.
ModificadaAlta (8.8)1.6%💥 PoCSimple AND Nice Shopping Cart Script Project Simple AND Nice Shopping Cart Script6/10/202317/6/2026
File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary code via the upload function in the edit profile component.
ModificadaAlta (7.5)0.67%—Phpjabbers PHP Shopping Cart21/9/202317/6/2026
Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter.
ModificadaAlta (8.8)1.4%💥 PoCPhpgurukul Online Shopping Portal18/8/202317/6/2026
Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username field, enabling SQL Injection attacks.
ModificadaMedia (6.8)0.40%—Cmscommander WP Shopping Pages7/8/202317/6/2026
The WP Shopping Pages WordPress plugin through 1.14 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
ModificadaAlta (8.8)1.1%💥 PoCPhpgurukul Online Shopping Portal1/8/202317/6/2026
Online Shopping Portal Project v3.1 was discovered to contain a SQL injection vulnerability via the Email parameter at /shopping/login.php.
ModificadaCrítica (9.1)0.68%—Phpgurukul Online Shopping Portal10/7/202317/6/2026
A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Registration Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely.…
ModificadaAlta (7.5)0.60%—Sanchitkmr Shopping Website7/7/202317/6/2026
A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file check_availability.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
ModificadaAlta (8.8)0.94%—Sanchitkmr Shopping Website4/7/202317/6/2026
A vulnerability has been found in SourceCodester Shopping Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public…