Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.29%—Webtoffee Product Import Export FOR WoocommerceAI27/5/202617/6/2026
Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Import Export for WooCommerce: from n/a through 2.5.6.
AplazadaMedia (4.3)0.20%—Sidngr Import Export FOR WoocommerceAI4/11/202517/6/2026
The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_setting() function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update…
ModificadaMedia (6.1)0.13%—Sidngr Import Export FOR Woocommerce16/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Stored XSS.This issue affects Import Export For WooCommerce: from n/a through <= 1.6.2.
ModificadaAlta (7.2)0.89%💥 PoCWebtoffee Product Import Export FOR Woocommerce26/3/202517/6/2026
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.5.0 via deserialization of untrusted input from the 'form_data' parameter This makes it possible for authenticated attackers, with…
AnalizadaAlta (7.6)0.38%—Webtoffee Product Import Export FOR Woocommerce26/3/202517/6/2026
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.0 via the validate_file() Function. This makes it possible for authenticated attackers, with Administrator-level access and above, to…
AnalizadaMedia (6.5)0.42%—Webtoffee Product Import Export FOR Woocommerce26/3/202517/6/2026
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.5.0. This makes it possible for authenticated attackers, with…
AnalizadaMedia (4.9)0.79%—Webtoffee Product Import Export FOR Woocommerce26/3/202517/6/2026
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the…
AplazadaCrítica (9.9)1.5%💥 PoCSidngr Import Export FOR WoocommerceAI13/12/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Import Export For WooCommerce: from n/a through <= 1.6.2.
AplazadaAlta (8.5)0.40%—Vrinsoft CSV Product Import Export FOR WoocommerceAI17/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vrinsoft CSV Product Import Export for WooCommerce csv-wc-product-import-export.This issue affects CSV Product Import Export for WooCommerce: from n/a through <= 1.0.0.
ModificadaAlta (7.2)0.60%—Webtoffee Product Import Export FOR Woocommerce26/3/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.4.1.
ModificadaAlta (7.2)0.53%—Webtoffee Product Import Export FOR Woocommerce24/1/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.3.7.
ModificadaCrítica (9.8)0.70%—Webtoffee Product Reviews Import Export FOR Woocommerce7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee Product Reviews Import Export for WooCommerce.This issue affects Product Reviews Import Export for WooCommerce: from n/a through 1.4.8.
Orbitaley — Vulnerabilidades