Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.5) | 0.32% | — | Vk011 Real WP Shop Lite Ajax Ecommerce Shopping Cart | 15/5/2025 | 17/6/2026 | The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite… | |
| Analizada | Media (4.3) | 0.18% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 18/2/2025 | 17/6/2026 | The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.12.27. This is due to missing or incorrect nonce validation on the ecwid_deactivate_feedback() function. This makes it possible for unauthenticated attackers to send… | |
| Aplazada | Media (5.4) | 0.26% | — | Simple Ecommerce Shopping CartAI | 7/12/2024 | 17/6/2026 | The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'save_settings', 'export_csv', and 'simpleecommcart-action' actions in all versions up to, and including, 3.1.2. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.30% | — | Simple Ecommerce Shopping Cart PluginAI | 7/12/2024 | 17/6/2026 | The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘monthly_sales_current_year’ parameter in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.35% | — | Lightspeedhq Ecwid Ecommerce Shopping CartAI | 9/4/2024 | 17/6/2026 | The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.12.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Aplazada | Baja (2.4) | 0.48% | — | Bdtask Isshue Multi Store Ecommerce Shopping Cart SolutionAI | 3/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Bdtask Isshue Multi Store eCommerce Shopping Cart Solution 4.0. This affects an unknown part of the file /dashboard/Cinvoice/manage_invoice of the component Manage Sale Page. The manipulation of the argument Title leads to cross site scripting. It is… | |
| Modificada | Media (6.1) | 0.18% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 28/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: from n/a through 6.12.4. | |
| Modificada | Media (4.3) | 0.22% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 16/1/2024 | 17/6/2026 | The Ecwid Ecommerce Shopping Cart WordPress plugin before 6.12.5 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | |
| Modificada | Media (5.4) | 0.39% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 8/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.4 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 14/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart plugin <= 6.11.3 versions. | |
| Modificada | Media (4.3) | 0.58% | — | Lightspeedhq Ecwid Ecommerce Shopping Cart | 6/9/2022 | 17/6/2026 | The Ecwid Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.10.23. This is due to missing or incorrect nonce validation on the ecwid_update_plugin_params function. This makes it possible for unauthenticated attackers to update plugin options… | |
| Modificada | Alta (7.5) | 22% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 29/12/2017 | 17/6/2026 | The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism." | |
| Modificada | Media (4.3) | 3.4% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 14/5/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to hijack the authentication of administrators for requests that conduct directory traversal attacks via the… | |
| Modificada | Media (4) | 9.1% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 14/5/2015 | 17/6/2026 | Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to… | |
| Modificada | Media (4.3) | 6.4% | 💥 Exploit | Thecartpress Ecommerce Shopping Cart | 14/5/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote attackers to inject arbitrary web script or HTML via the (1) billing_firstname, (2) billing_lastname, (3) billing_company,… | |
| Modificada | Alta (7.5) | 1.3% | — | Neturf Ecommerce Shopping Cart | 23/9/2012 | 16/6/2026 | SQL injection vulnerability in search.php in Neturf eCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the SearchFor parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Bazaarbuilder Ecommerce Shopping Cart | 2/2/2009 | 16/6/2026 | SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php. |