Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
257 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Wrteam Eshop - Ecommerce / Store Website | 8/8/2022 | 8/7/2026 | A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter. | |
| Modificada | Media (4.8) | 0.80% | — | Ecommerce-project-with-php-and-mysqli-fruits-bazar Project Ecommerce-project-with-php-and-mysqli-fruits-bazar | 2/6/2022 | 17/6/2026 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar- 1.0 is vulnerable to Cross Site Scripting (XSS) in \admin\add_cata.php via the ctg_name parameters. | |
| Modificada | Crítica (9.8) | 1.6% | — | Ecommerce-project-with-php-and-mysqli-fruits-bazar Project Ecommerce-project-with-php-and-mysqli-fruits-bazar | 2/6/2022 | 17/6/2026 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in \search_product.php via the keyword parameters. | |
| Modificada | Crítica (9.8) | 3.6% | — | Ecommerce-website Project Ecommerce-website | 8/4/2022 | 17/6/2026 | Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (8.8) | 2.7% | — | Ecommerce-website Project Ecommerce-website | 8/4/2022 | 17/6/2026 | Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Media (6.1) | 0.79% | — | Ecommerce Codeigniter Bootstrap Project Ecommerce Codeigniter Bootstrap | 8/4/2022 | 17/6/2026 | Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title parameter in /vendor/views/add_product.php. | |
| Modificada | Media (4.8) | 0.99% | — | Ecommerce-website Project Ecommerce-website | 4/4/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_user at Ecommerce-Website v1.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username text field. | |
| Modificada | Alta (8.8) | 1.7% | — | Ecommerce-website Project Ecommerce-website | 4/4/2022 | 17/6/2026 | An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component. | |
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Implecode Ecommerce Product Catalog | 23/11/2021 | 17/6/2026 | The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Alta (8.8) | 0.65% | — | Spreecommerce Spree Auth Devise | 17/11/2021 | 17/6/2026 | spree_auth_devise is an open source library which provides authentication and authorization services for use with the Spree storefront framework by using an underlying Devise authentication framework. In affected versions spree_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All… | |
| Modificada | Media (6.1) | 0.84% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in application/modules/admin/views/ecommerce/products.php in Ecommerce-CodeIgniter-Bootstrap (Codeigniter 3.1.11, Bootstrap 3.3.7) allows remote attackers to inject arbitrary web script or HTML via the search_title parameter. | |
| Modificada | Alta (8.8) | 0.64% | — | Wpeasycart Shopping Cart & Ecommerce Store | 19/8/2021 | 17/6/2026 | The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.1.0. | |
| Modificada | Alta (7.5) | 65% | 💥 Exploit | Wp-ecommerce Easy WP Smtp | 14/12/2020 | 17/6/2026 | The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links.… | |
| Modificada | Media (6.5) | 1.1% | — | Spreecommerce Spree | 13/11/2020 | 17/6/2026 | Spree is a complete open source e-commerce solution built with Ruby on Rails. In Spree from version 3.7 and before versions 3.7.13, 4.0.5, and 4.1.12, there is an authorization bypass vulnerability. The perpetrator could query the API v2 Order Status endpoint with an empty string passed as an Order token. This is… | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/clothesshop, application/views/templates/greenlabel, and application/views/templates/redlabel. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php. | |
| Modificada | Crítica (9.8) | 2.1% | — | Soluzioneglobale Ecommerce CMS | 27/8/2020 | 17/6/2026 | SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php" | |
| Modificada | Crítica (9.8) | 2.2% | — | Webexcels Ecommerce CMS | 27/8/2020 | 17/6/2026 | Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter. | |
| Modificada | Media (6.1) | 0.92% | — | Webexcels Ecommerce CMS | 27/8/2020 | 17/6/2026 | Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has cross site scripting via the 'search.php' id parameter. |