Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.83% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 6/7/2026 | A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affected element is the function getCartItems in the library application/libraries/ShoppingCart.php. The manipulation of the argument shopping_cart leads to deserialization. The… | |
| Aplazada | Media (5.3) | 0.48% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 6/7/2026 | A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. Impacted is the function do_upload_others_images of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Image Manager. Executing a manipulation of the… | |
| Aplazada | Baja (2.1) | 0.49% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 7/7/2026 | A vulnerability was determined in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 49b20f53de2b7ec34e920b11c863f1491d911a04. This affects an unknown part of the file /index.php/api/product/set of the component Hidden REST API Endpoint. This manipulation of the argument title/description causes cross site scripting.… | |
| Aplazada | Baja (2.1) | 0.46% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 95dfa8cebbb87ab46ae450643a07241274a74dce. Affected by this issue is the function setReferrer of the file application/core/MY_Controller.php of the component Trusted Backend Interface. The manipulation of the argument href results in open… | |
| Modificada | Media (5.3) | 0.52% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 5/7/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in CodeIgniter Ecommerce-CodeIgniter-Bootstrap up to 1998845073cf433bc6c250b0354461fbd84d0e03. This affects an unknown part. The manipulation of the argument search_title/catName/sub/name/categorie leads to cross site scripting. It is possible to initiate the… | |
| Modificada | Crítica (9.8) | 1.7% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 29/4/2024 | 24/8/2026 | An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component. | |
| Analizada | Crítica (9.8) | 1.9% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 29/4/2024 | 17/6/2026 | An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component. | |
| Analizada | Alta (8) | 1.1% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 29/4/2024 | 17/6/2026 | SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the manageQuantitiesAndProcurement method of the Orders_model.php component. | |
| Analizada | Crítica (9.8) | 1.9% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 29/4/2024 | 17/6/2026 | An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component. | |
| Modificada | Media (6.1) | 0.61% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 20/1/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Ecommerce-CodeIgniter-Bootstrap thru commit d5904379ca55014c5df34c67deda982c73dc7fe5 (on Dec 27, 2022), allows attackers to execute arbitrary code via the languages and trans_load parameters in file add_product.php. | |
| Modificada | Media (6.1) | 0.59% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 18/8/2022 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before commit 56465f was discovered to contain a cross-site scripting (XSS) vulnerability via the function base_url() at /blog/blogpublish.php. | |
| Modificada | Media (6.1) | 0.84% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in application/modules/admin/views/ecommerce/products.php in Ecommerce-CodeIgniter-Bootstrap (Codeigniter 3.1.11, Bootstrap 3.3.7) allows remote attackers to inject arbitrary web script or HTML via the search_title parameter. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in _parts/header.php, within application/views/templates/clothesshop, application/views/templates/greenlabel, and application/views/templates/redlabel. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/vendor/views/add_product.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/publish.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/ecommerce/discounts.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/languages.php. | |
| Modificada | Media (6.1) | 0.68% | — | Ecommerce-codeigniter-bootstrap Project Ecommerce-codeigniter-bootstrap | 3/9/2020 | 17/6/2026 | Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/advanced_settings/adminUsers.php. |