Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Berocket Advanced Ajax Product FiltersAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. | |
| Aplazada | Media (6.4) | 0.33% | — | Berocket Brands FOR WoocommerceAI | 24/7/2026 | 24/7/2026 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (4.4) | 0.31% | — | Berocket Brands FOR WoocommerceAI | 23/7/2026 | 23/7/2026 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and… | |
| Aplazada | Media (6.4) | 0.33% | — | Berocket Brands FOR WoocommerceAI | 23/7/2026 | 23/7/2026 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (5.4) | 0.23% | — | Berocket Advanced Ajax Product FiltersAI | 11/6/2026 | 29/9/2026 | Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Advanced AJAX Product Filters: from n/a through 1.6.3.3. | |
| Aplazada | Alta (8.8) | 0.48% | — | Berocket Advanced Ajax Product FiltersAI | 18/2/2026 | 17/6/2026 | The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.9.6 via deserialization of untrusted input in the shortcode_check function within the Live Composer compatibility layer. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.5) | 0.25% | — | Berocket Brands FOR WoocommerceAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Blind SQL Injection.This issue affects Brands for WooCommerce: from n/a through <= 3.8.6.3. | |
| Aplazada | Media (4.3) | 0.16% | — | Berocket Sequential Order Numbers FOR WoocommerceAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in BeRocket Sequential Order Numbers for WooCommerce sequential-order-numbers-for-woocommerce allows Cross Site Request Forgery.This issue affects Sequential Order Numbers for WooCommerce: from n/a through <= 3.6.2. | |
| Analizada | Media (6.1) | 0.29% | — | Berocket Advanced Ajax Product Filters | 28/2/2025 | 17/6/2026 | The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 1.6.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (5.3) | 0.50% | — | Berocket Brands FOR WoocommerceAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brands for WooCommerce: from n/a through <= 3.8.2.2. | |
| Modificada | Media (6.1) | 0.45% | — | Berocket Advanced Ajax Product Filters | 16/1/2024 | 17/6/2026 | The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it in the page, leading to reflected Cross-Site Scripting issue. | |
| Modificada | Media (4.8) | 0.39% | — | Elightup Erocket | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in eLightUp eRocket plugin <= 1.2.4 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Berocket Brands FOR Woocommerce | 18/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in BeRocket Brands for WooCommerce plugin <= 3.7.0.6 versions. | |
| Modificada | Media (6.1) | 0.55% | — | Berocket Stockists Manager FOR Woocommerce | 6/9/2022 | 17/6/2026 | The Stockists Manager for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.2.1. This is due to missing nonce validation on the stockist_settings_main() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and… | |
| Modificada | Media (5.4) | 0.59% | — | Servicerocket Linking | 7/6/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in Linking. This affects an unknown part of the component New Windows Macro. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Media (6.1) | 0.88% | — | Berocket Advanced Product Labels FOR Woocommerce | 14/3/2022 | 17/6/2026 | The Advanced Product Labels for WooCommerce WordPress plugin before 1.2.3.7 does not sanitise and escape the tax_color_set_type parameter before outputting it back in the berocket_apl_color_listener AJAX action's response, leading to a Reflected Cross-Site Scripting |