Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.8)0.83%—Kirilkirkov Ecommerce-codeigniter-bootstrapAI4/7/20266/7/2026
A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affected element is the function getCartItems in the library application/libraries/ShoppingCart.php. The manipulation of the argument shopping_cart leads to deserialization. The…
AplazadaMedia (5.3)0.48%—Kirilkirkov Ecommerce-codeigniter-bootstrapAI4/7/20266/7/2026
A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. Impacted is the function do_upload_others_images of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Image Manager. Executing a manipulation of the…
AplazadaBaja (2.1)0.49%—Kirilkirkov Ecommerce-codeigniter-bootstrapAI4/7/20267/7/2026
A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API Endpoint. This manipulation of the argument title/description causes cross site scripting.…
AplazadaBaja (2.1)0.46%—Kirilkirkov Ecommerce-codeigniter-bootstrapAI4/7/20266/7/2026
A vulnerability was found in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 95dfa8cebbb87ab46ae450643a07241274a74dce. Affected by this issue is the function setReferrer of the file application/core/MY_Controller.php of the component Trusted Backend Interface. The manipulation of the argument href results in open…
ModificadaMedia (5.3)0.52%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap5/7/202417/6/2026
A vulnerability classified as problematic has been found in CodeIgniter Ecommerce-CodeIgniter-Bootstrap up to 1998845073cf433bc6c250b0354461fbd84d0e03. This affects an unknown part. The manipulation of the argument search_title/catName/sub/name/categorie leads to cross site scripting. It is possible to initiate the…
ModificadaCrítica (9.8)1.7%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202424/8/2026
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.
AnalizadaCrítica (9.8)1.9%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202417/6/2026
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component.
AnalizadaAlta (8)1.1%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202417/6/2026
SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Orders_model.php component.
AnalizadaCrítica (9.8)1.9%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap29/4/202417/6/2026
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component.
ModificadaMedia (6.1)0.61%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap20/1/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php.
ModificadaMedia (6.1)0.59%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap18/8/202217/6/2026
Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php.
ModificadaMedia (6.1)0.84%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap1/10/202117/6/2026
Cross-site scripting (XSS) vulnerability in application/modules/admin/views/ecommerce/products.php in Ecommerce-CodeIgniter-Bootstrap (Codeigniter 3.1.11, Bootstrap 3.3.7) allows remote attackers to inject arbitrary web script or HTML via the search_title parameter.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/clothesshop, application/views/templates/greenlabel, and application/views/templates/redlabel.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php.
ModificadaMedia (6.1)0.68%—Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap3/9/202017/6/2026
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php.