Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.32% | — | Webkul BagistoAI | 28/9/2026 | 29/9/2026 | A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now… | |
| Aplazada | Alta (8.8) | 0.45% | — | Webkul BagistoAI | 15/9/2026 | 22/9/2026 | Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoint (route admin.settings.users.update, UserController::update()) does not verify… | |
| Aplazada | Alta (8.1) | 0.39% | — | Webkul BagistoAI | 15/9/2026 | 22/9/2026 | Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods. | |
| Aplazada | Media (6.5) | 0.46% | — | Webkul BagistoAI | 15/9/2026 | 22/9/2026 | An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components. | |
| Aplazada | Baja (2.1) | 0.45% | — | Webkul BagistoAI | 18/8/2026 | 20/8/2026 | A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes basic cross site scripting. It is possible to initiate the attack… | |
| Aplazada | Baja (2.1) | 0.37% | — | Webkul BagistoAI | 18/8/2026 | 20/8/2026 | A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow. The attack may be performed from remote. The exploit is now public… | |
| Aplazada | Baja (2) | 0.43% | — | Webkul BagistoAI | 17/8/2026 | 20/8/2026 | A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.38% | — | Webkul BagistoAI | 17/8/2026 | 20/8/2026 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack can be executed remotely. The exploit is… | |
| Aplazada | Baja (2) | 0.33% | — | Webkul BagistoAI | 17/8/2026 | 20/8/2026 | A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.40% | — | Webkul BagistoAI | 17/8/2026 | 20/8/2026 | A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration Management. The manipulation of the argument action results in authorization bypass. The attack may be launched… | |
| Aplazada | Baja (2.1) | 0.37% | — | Webkul BagistoAI | 17/8/2026 | 20/8/2026 | A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.41% | — | Webkul BagistoAI | 14/8/2026 | 14/8/2026 | A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (2) | 0.41% | — | Webkul BagistoAI | 14/8/2026 | 14/8/2026 | A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.41% | — | Webkul BagistoAI | 14/8/2026 | 18/8/2026 | A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID results in authorization bypass. The attack may be initiated remotely.… | |
| Aplazada | Baja (2) | 0.45% | — | Webkul BagistoAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is publicly available and might be used. The… | |
| Aplazada | Baja (2) | 0.43% | — | Webkul BagistoAI | 14/8/2026 | 18/8/2026 | A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authorization bypass. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Media (5.1) | 0.36% | — | Webkul BagistoAI | 9/7/2026 | 14/7/2026 | Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malicious payload in the first or last name field. The create.blade.php… | |
| Aplazada | Alta (8.7) | 1.8% | — | Webkul BagistoAI | 8/6/2026 | 23/7/2026 | This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the filename parameter to access arbitrary files outside the intended… | |
| Aplazada | Baja (2) | 0.33% | — | Webkul BagistoAI | 21/4/2026 | 17/6/2026 | A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of the component Custom Scripts Handler. This manipulation causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The… | |
| Aplazada | Baja (2.1) | 0.35% | — | Webkul BagistoAI | 21/4/2026 | 17/6/2026 | A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this… | |
| Analizada | Media (5.2) | 0.56% | — | Webkul Bagisto | 2/1/2026 | 17/6/2026 | Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Although the platform normally attempts to sanitize `<script>` tags, the filtering can be bypassed by manipulating the raw HTTP POST request… | |
| Analizada | Alta (7.3) | 1.4% | — | Webkul Bagisto | 2/1/2026 | 17/6/2026 | Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue. | |
| Analizada | Alta (7.4) | 0.51% | — | Webkul Bagisto | 2/1/2026 | 17/6/2026 | Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege user. Version 2.3.10 fixes the issue. | |
| Analizada | Alta (8.9) | 0.92% | — | Webkul Bagisto | 2/1/2026 | 17/6/2026 | Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a value to run in admin view. The issue can lead to remote code execution. Version 2.3.10 contains a… | |
| Analizada | Alta (7.1) | 0.30% | — | Webkul Bagisto | 2/1/2026 | 17/6/2026 | Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer order reorder function allows any authenticated customer to add items from another customer's order to their own shopping cart by manipulating the order ID parameter. This… |