Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.38% | — | Tychesoftwares Abandoned Cart Lite FOR WoocommerceAI | 16/7/2026 | 16/7/2026 | The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the automatic-login option is enabled. | |
| Aplazada | Media (4.3) | 0.14% | — | Flycart Abandoned Cart Lite FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions. | |
| Aplazada | Media (5.4) | 0.48% | — | Tychesoftwares Abandoned Cart Lite FOR WoocommerceAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in tychesoftwares Abandoned Cart Lite for WooCommerce woocommerce-abandoned-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Abandoned Cart Lite for WooCommerce: from n/a through <= 5.16.1. | |
| Modificada | Media (4.8) | 0.32% | — | Tychesoftwares Abandoned Cart Lite FOR Woocommerce | 16/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Abandoned Cart Lite for WooCommerce plugin <= 5.15.2 versions. | |
| Modificada | Media (4.3) | 0.38% | — | Tychesoftwares Abandoned Cart Lite FOR Woocommerce | 12/7/2023 | 17/6/2026 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.8.5. This is due to missing or incorrect nonce validation on the wcal_preview_emails() function. This makes it possible for unauthenticated attackers to generate email preview… | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Tychesoftwares Abandoned Cart Lite FOR WoocommerceTychesoftwares Abandoned Cart PRO FOR Woocommerce | 22/6/2023 | 17/6/2026 | The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 5.1.3 and 7.12.0 respectively, due to insufficient input sanitization and output escaping. This makes it possible… | |
| Modificada | Crítica (9.8) | 43% | 💥 PoC | Tychesoftwares Abandoned Cart Lite FOR Woocommerce | 8/6/2023 | 17/6/2026 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode through the plugin. This allows unauthenticated attackers to log in as… |