Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (7.2) | 0.26% | — | Joomla Easy StoreAI | 23/9/2026 | 23/9/2026 | Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated core Joomla mail configuration (fromname, mailfrom) in configuration.php without… | |
| En análisis | Alta (8.6) | 0.31% | — | Joomshaper Easy StoreAI | 23/9/2026 | 23/9/2026 | Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php hardcoded return true;, bypassing Joomla component-level and asset-level ACL permission checks. Any authenticated backend user could… | |
| En análisis | Alta (7.2) | 0.17% | — | Joomshaper Easy StoreAI | 23/9/2026 | 23/9/2026 | Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF tokens inside the products() action. All other administrative AJAX endpoints (orders, coupons, media, customers,… | |
| En análisis | Alta (8.6) | 0.28% | — | Joomshaper Easy StoreAIJoomlaAI | 23/9/2026 | 25/9/2026 | Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdate) took input IDs and directly concatenated them into raw SQL IN (...) clauses in… | |
| En análisis | Alta (8.6) | 0.28% | — | Joomshaper Easy StoreAI | 23/9/2026 | 25/9/2026 | Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The media deletion endpoint (administrator/index.php?option=com_easystore&task=media.deleteImage) parsed the ids parameter as a comma-separated string and imploded it directly into… | |
| En análisis | Media (5.3) | 0.17% | — | Joomshaper Easy StoreAI | 23/9/2026 | 23/9/2026 | Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 - The product review submission endpoint (index.php?option=com_easystore&task=product.addReview) accepted submissions without verifying an anti-CSRF token (the check had been… | |
| En análisis | Alta (8.2) | 0.33% | — | Joomshaper Easy StoreAI | 23/9/2026 | 23/9/2026 | Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest checkout records solely by supplying an email address. The server returned complete shipping details (full name, phone number,… | |
| Aplazada | Crítica (9.3) | 1.0% | — | Joomshaper Easy StoreAI | 23/7/2026 | 23/7/2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead to an unauthenticated SQL injection in easystore, allowing full DB read access including credentials and sessions. | |
| Aplazada | Crítica (9.2) | 0.42% | — | Joomshaper Easy StoreAI | 23/7/2026 | 23/7/2026 | Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access checks allow logged in users to retreive order and customer information of any order in the system. | |
| Aplazada | Alta (8.7) | 0.43% | — | Joomshaper Easy StoreAI | 23/7/2026 | 23/7/2026 | Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment information, including states, are processed from client side input, enabling unauthenticated attackers to manipulate payment and order states of arbritrary orders. | |
| Aplazada | Media (5.1) | 0.51% | — | Real Easy StoreAI | 28/5/2025 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Real Easy Store. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the keyword parameter in /index.php?a=search. This vulnerability can be exploited to steal sensitive user data,… |