Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.54%—Ohsoft CoffeezipAI22/7/20266/10/2026
An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
AplazadaCrítica (9.8)0.53%—HOT CoffeeAI17/6/20266/10/2026
Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.
AplazadaAlta (7.1)0.26%—Themegoods Craft CraftcoffeeAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Craft craftcoffee allows DOM-Based XSS.This issue affects Craft: from n/a through <= 2.3.6.
AnalizadaAlta (7.8)0.34%—Generalcoffee Fade IN28/10/202517/6/2026
An out-of-bounds write vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .fadein file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
AnalizadaAlta (7.8)0.34%—Generalcoffee Fade IN28/10/202517/6/2026
A use-after-free vulnerability exists in the XML parser functionality of GCC Productions Inc. Fade In 4.2.0. A specially crafted .xml file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
AnalizadaMedia (6.1)0.58%—Coffee-code Plugin Oficial15/5/202517/6/2026
The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.
AnalizadaMedia (4.8)0.26%—Coffee-code Plugin Oficial15/5/202517/6/2026
The Plugin Oficial WordPress plugin through 1.7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AplazadaMedia (5.9)0.29%—Coffeestudios POP UPAI7/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in coffeestudios Pop Up popup-seo-optimized allows Stored XSS.This issue affects Pop Up: from n/a through <= 0.1.
AnalizadaMedia (4.8)0.22%—Coffee Project Coffee9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allows Cross-Site Scripting (XSS).This issue affects Coffee: from 0.0.0 before 1.4.0.
AnalizadaMedia (5.3)0.40%—Coffee2code Custom Post Limits13/9/202417/6/2026
The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, 4.4.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web…
AnalizadaMedia (5.3)0.44%—Coffee2code Remember ME Controls6/9/202417/6/2026
The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the…
ModificadaMedia (5.3)0.48%—Coffee2code NO Update NAG12/8/202417/6/2026
The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.12. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web…
ModificadaMedia (4.3)0.27%—Buymeacoffee BUY ME A Coffee12/6/202417/6/2026
Missing Authorization vulnerability in Buy Me a Coffee.This issue affects Buy Me a Coffee: from n/a through 3.7.
ModificadaCrítica (9.8)0.61%—Coffee2code Commenter Emails7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in Scott Reilly Commenter Emails.This issue affects Commenter Emails: from n/a through 2.6.1.
ModificadaMedia (6.5)0.46%—Coffee-jumbo Project Coffee-jumbo18/9/20239/7/2026
An information leak in Coffee-jumbo v13.6.1 allows attackers to obtain the channel access token and send crafted messages.
ModificadaMedia (5.4)0.60%—Buymeacoffee BUY ME A Coffee14/7/202317/6/2026
The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.6 due to insufficient sanitization and escaping on the 'text value set via the bmc_post_reception action. This makes it possible for authenticated attackers, with…
ModificadaMedia (5.3)0.34%—Buymeacoffee BUY ME A Coffee11/7/202317/6/2026
The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the recieve_post, bmc_disconnect, name_post, and widget_post functions in versions up to, and including, 3.7. This makes it possible for unauthenticated attackers to…
ModificadaMedia (4.3)0.55%—Buymeacoffee BUY ME A Coffee11/7/202317/6/2026
The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the recieve_post, bmc_disconnect, name_post, and widget_post functions in versions up to, and including, 3.7. This makes it possible for authenticated attackers,…
ModificadaMedia (4.8)0.47%—Buymeacoffee BUY ME A Coffee10/7/202317/6/2026
The Buy Me a Coffee WordPress plugin before 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (6.1)0.65%—Coffee Shop POS System Project Coffee Shop POS System21/4/202317/6/2026
A vulnerability classified as problematic was found in Campcodes Coffee Shop POS System 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Users.php. The manipulation of the argument firstname leads to cross site scripting. The attack can be launched remotely. The exploit has been…
ModificadaCrítica (9.8)1.6%—Coffee Shop POS System Project Coffee Shop POS System21/4/202317/6/2026
A vulnerability classified as critical has been found in Campcodes Coffee Shop POS System 1.0. Affected is an unknown function of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
ModificadaAlta (7.5)0.61%—Coffee Shop POS System Project Coffee Shop POS System21/4/202317/6/2026
A vulnerability was found in Campcodes Coffee Shop POS System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/sales/manage_sale.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
ModificadaAlta (7.5)0.61%—Coffee Shop POS System Project Coffee Shop POS System21/4/202317/6/2026
A vulnerability was found in Campcodes Coffee Shop POS System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/products/manage_product.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…
ModificadaAlta (7.5)0.61%—Coffee Shop POS System Project Coffee Shop POS System21/4/202317/6/2026
A vulnerability was found in Campcodes Coffee Shop POS System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/products/view_product.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…
ModificadaAlta (7.5)0.61%—Coffee Shop POS System Project Coffee Shop POS System21/4/202317/6/2026
A vulnerability was found in Campcodes Coffee Shop POS System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/categories/manage_category.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been…