Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

364 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Phpgurukul Online Shopping Portal18/2/202217/6/2026
Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.
ModificadaCrítica (9.8)0.97%—Projectworlds Online-shopping-webvsite-in-php23/1/202217/6/2026
Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.
ModificadaMedia (4.3)0.45%—Projectworlds Online Shopping System22/12/202117/6/2026
In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.
ModificadaCrítica (9.8)1.1%—Projectworlds Online Shopping System22/12/202117/6/2026
Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.
ModificadaMedia (6.1)0.58%—Shopping Portal Project Shopping Portal5/11/202117/6/2026
Multiple Cross Site Scripting (XSS) vulnerabilities exists in PHPGurukul Shopping v3.1 via the (1) callback parameter in (a) server_side/scripts/id_jsonp.php, (b) server_side/scripts/jsonp.php, and (c) scripts/objects_jsonp.php, the (2) value parameter in examples_support/editable_ajax.php, and the (3) PHP_SELF…
ModificadaAlta (7.5)1.5%—Phpgurukul Online Shopping Portal27/10/202117/6/2026
An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.
ModificadaCrítica (9.8)52%💥 ExploitOnline-shopping-system-advanced Project Online-shopping-system-advanced1/10/202117/6/2026
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php cat_id parameter. Using a post request does not sanitize the user input.
ModificadaAlta (7.5)10%💥 ExploitOnline-shopping-system-advanced Project Online-shopping-system-advanced1/10/202117/6/2026
An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId parameter. Using a post request does not sanitize the user input.
ModificadaAlta (8.8)0.63%—Simple-e-commerce-shopping-cart Project Simple-e-commerce-shopping-cart13/9/202117/6/2026
The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check for the uploaded Downloadable Digital product file, allowing any file, such as PHP to be uploaded by an administrator. Furthermore, as there is no CSRF in place, attackers could also make a logged…
ModificadaAlta (8.8)0.64%—Wpeasycart Shopping Cart & Ecommerce Store19/8/202117/6/2026
The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the ~/admin/inc/wp_easycart_admin_initial_setup.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.1.0.
ModificadaCrítica (9.1)5.2%💥 ExploitPeel Shopping30/7/202117/6/2026
PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQL query in order to affect the execution of predefined SQL commands. Upon a successful SQL injection attack, an attacker can read sensitive data from the database and possibly modify database data.
ModificadaCrítica (9.8)2.8%—Basic Shopping Cart Project Basic Shopping Cart30/7/202117/6/2026
A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin.
ModificadaAlta (7.5)2.1%—Online Shopping Alphaware Project Online Shopping Alphaware2/6/202117/6/2026
The id paramater in Online Shopping Alphaware 1.0 has been discovered to be vulnerable to an Error-Based blind SQL injection in the /alphaware/details.php path. This allows an attacker to retrieve all databases.
ModificadaMedia (5.4)1.6%💥 PoCPeel Shopping12/2/202117/6/2026
A Stored Cross Site Scripting(XSS) Vulnerability was discovered in PEEL SHOPPING 9.3.0 and 9.4.0, which are publicly available. The user supplied input containing polyglot payload is echoed back in javascript code in HTML response. This allows an attacker to input malicious JavaScript which can steal cookie, redirect…
ModificadaCrítica (9.8)3.3%—Online Shopping Alphaware Project Online Shopping Alphaware17/8/202017/6/2026
A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters.
ModificadaMedia (6.5)0.43%—Peel Shopping9/1/202017/6/2026
Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user.
ModificadaAlta (7.2)1.9%—Firestormplugins Fs-shopping-cart13/9/201917/6/2026
The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter.
ModificadaAlta (8.8)0.85%—Ultra-prod Wordpress Ultra Simple Paypal Shopping Cart12/9/201917/6/2026
Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaAlta (8.8)0.82%—Peel Shopping30/6/201917/6/2026
Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter.
ModificadaMedia (4.8)0.67%—Peel Shopping28/12/201817/6/2026
Peel shopping peel-shopping_9_1_0 version contains a Cross Site Scripting (XSS) vulnerability that can result in an authenticated user injecting java script code in the "Site Name EN" parameter. This attack appears to be exploitable if the malicious user has access to the administration account.
ModificadaMedia (5.9)0.52%—Shein-fashion Shopping Online12/7/201817/6/2026
The Shein Group Ltd. "SHEIN - Fashion Shopping" app -- aka shein fashion-shopping/id878577184 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)22%💥 ExploitThecartpress Ecommerce Shopping Cart29/12/201717/6/2026
The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism."
ModificadaMedia (4.3)3.4%💥 ExploitThecartpress Ecommerce Shopping Cart14/5/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the…
ModificadaMedia (4)9.1%💥 ExploitThecartpress Ecommerce Shopping Cart14/5/201517/6/2026
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to…
ModificadaMedia (4.3)6.4%💥 ExploitThecartpress Ecommerce Shopping Cart14/5/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote attackers to inject arbitrary web script or HTML via the (1) billing_firstname, (2) billing_lastname, (3) billing_company,…
Orbitaley — Vulnerabilidades