Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2517▼ 428 respecto a la semana anterior
Críticas / altas1288▲ 1 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.7) | 0.28% | — | DokanAI | 21/8/2026 | 26/8/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance when recording a reverse-withdrawal payment, allowing a vendor to credit their reverse-withdrawal ledger with an arbitrary… | |
| Aplazada | Alta (7.2) | 0.25% | — | Wedevs DokanAI | 21/8/2026 | 26/8/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some of its admin REST API routes, checking only for a WooCommerce management capability instead of the Dokan: AI Powered WooCommerce Multivendor Marketplace Solution… | |
| Aplazada | Media (5.3) | 0.34% | — | DokanAI | 21/8/2026 | 26/8/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission configuration returned by one of its unauthenticated store REST endpoints, allowing any unauthenticated user to disclose a vendor's commission type and, when… | |
| Aplazada | Media (5.4) | 0.23% | — | DokanAI | 8/8/2026 | 26/8/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belongs to the requesting vendor before granting download permissions through one of its order REST endpoints, allowing an authenticated vendor to grant their own customer free… | |
| Aplazada | Media (5.3) | 0.29% | — | Wedevs DokanAI | 6/8/2026 | 12/8/2026 | Custom role Broken Access Control in Dokan <= 5.0.10 versions. | |
| Aplazada | Alta (8.8) | 0.69% | — | DokanAI | 5/8/2026 | 12/8/2026 | The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), which re-registers WooCommerce's customer CRUD routes under the… | |
| Aplazada | Media (4.3) | 0.25% | — | Wedevs DokanAI | 3/8/2026 | 26/8/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users with a Dokan vendor account to modify the product attributes and default attributes of any other vendor's products on the… | |
| Aplazada | Media (4.3) | 0.25% | — | Wedevs DokanAI | 3/8/2026 | 26/8/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status changes, allowing users with a Dokan vendor account to modify the status of any WooCommerce order on the marketplace, including orders… | |
| Aplazada | Alta (7.5) | 0.43% | — | Dokan PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions. | |
| Aplazada | Alta (7.1) | 0.29% | — | Wedevs Dokan PROAI | 23/7/2026 | 23/7/2026 | Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. | |
| Aplazada | Alta (7.5) | 0.40% | — | Dokan PROAI | 23/7/2026 | 23/7/2026 | Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wedevs Dokan PROAI | 23/7/2026 | 21/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs Dokan Pro allows Reflected XSS. This issue affects Dokan Pro: from n/a before 5.0.7. | |
| Aplazada | Alta (7.1) | 0.25% | — | Dokan-liteAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dokan, Inc. Dokan dokan-lite allows Reflected XSS.This issue affects Dokan: from n/a through <= 5.0.6. | |
| Aplazada | Alta (8.8) | 0.44% | — | Wedevs DokanAI | 1/7/2026 | 1/7/2026 | The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including, 5.0.4. This is due to the `update_capabilities()` REST handler accepting arbitrary capability strings from the request body and passing them directly to… | |
| Aplazada | Media (4.3) | 0.47% | — | DokanAI | 27/6/2026 | 29/6/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.38% | — | Wedevs DokanAI | 27/6/2026 | 29/6/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Product SKU in all versions up to, and including, 5.0.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Dokan PROAI | 26/6/2026 | 26/6/2026 | Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions. | |
| Aplazada | Media (6.5) | 0.38% | — | Dokan PROAI | 25/6/2026 | 26/6/2026 | The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Alta (7.5) | 0.46% | — | Dokan PROAI | 25/6/2026 | 29/6/2026 | The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.24% | — | Wedevs DokanAI | 18/6/2026 | 18/6/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.3 via the change_order_status, add_order_note, delete_order_note, add_shipping_tracking_info,… | |
| Aplazada | Alta (8.8) | 0.42% | — | DokanAI | 15/6/2026 | 17/6/2026 | Customer Privilege Escalation in Dokan <= 5.0.2 versions. | |
| Aplazada | Media (5.3) | 0.44% | — | Wedevs DokanAI | 2/5/2026 | 17/6/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.1 via the '/dokan/v1/stores/{id}/reviews' REST API endpoint. This is due to the 'prepare_reviews_for_response' method including reviewer… | |
| Aplazada | Alta (8.8) | 0.52% | — | Dokan-liteAI | 25/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: from n/a through <= 4.2.4. | |
| Analizada | Alta (7.5) | 0.43% | — | Amcoders Dokans | 3/2/2026 | 17/6/2026 | Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file. The exposed file contains Laravel application encryption key (APP_KEY), database credentials, SMTP/SendGrid API credentials, and… | |
| Aplazada | Alta (8.1) | 0.30% | — | Wedevs DokanAI | 20/1/2026 | 17/6/2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/settings` REST API endpoint due to missing validation on a user-controlled… |