Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.45% | — | Zipmoney Payments FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary WordPress options. This can be used to… | |
| Aplazada | Media (5.4) | 0.27% | — | Ycf1998 Money-posAI | 9/9/2026 | 10/9/2026 | money-pos 1.0 contains a stored Cross-Site Scripting (XSS) vulnerability. When processing returns, the backend fails to filter or escape the goodsName parameter, directly concatenating it into the order log description; the frontend subsequently renders this content using v-html. An attacker with product creation… | |
| Aplazada | Media (5.3) | 0.29% | — | Themoneytizer THE MoneytizerAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in lvaudore The Moneytizer the-moneytizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Moneytizer: from n/a through <= 10.0.10. | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex MoneyflowAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX MoneyFlow moneyflow allows PHP Local File Inclusion.This issue affects MoneyFlow: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.19% | — | Itex ImoneyAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in itex iMoney imoney allows Reflected XSS.This issue affects iMoney: from n/a through <= 0.36. | |
| Analizada | Media (4.9) | 0.22% | — | Whisper.money Whisper Money | 19/1/2026 | 17/6/2026 | Whisper Money is a personal finance application. Versions prior to 0.1.5 have an insecure direct object reference vulnerability. A user can update/create account balances in other users' bank accounts. Version 0.1.5 fixes the issue. | |
| Aplazada | Alta (8.6) | 0.42% | — | MoneyspaceAI | 7/1/2026 | 17/6/2026 | The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.13.9. This is due to the plugin storing full payment card details (PAN, card holder name, expiry month/year, and CVV) in WordPress post_meta using base64_encode(), and then embedding these values… | |
| Aplazada | Media (6.5) | 0.19% | — | Themoneytizer THE MoneytizerAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lvaudore The Moneytizer the-moneytizer allows DOM-Based XSS.This issue affects The Moneytizer: from n/a through <= 10.0.9. | |
| Analizada | Crítica (10) | 0.86% | — | Ycf1998 Money-pos | 7/11/2025 | 17/6/2026 | Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) allows a remote attacker to execute arbitrary code via the orderby parameter | |
| Modificada | Baja (2.1) | 0.45% | — | Harry0703 Moneyprinterturbo | 11/10/2025 | 17/6/2026 | A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_music of the file app/controllers/v1/music.py of the component API Endpoint. Executing a manipulation of the argument File can lead to path traversal. The attack may be performed from remote. The… | |
| Analizada | Media (5.5) | 0.84% | — | Harry0703 Moneyprinterturbo | 15/9/2025 | 17/6/2026 | A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download_video/stream_video of the file app/controllers/v1/video.py of the component URL Handler. The manipulation of the argument file_path leads to path traversal. The attack can be initiated remotely. The… | |
| Analizada | Media (6.3) | 0.31% | — | Harry0703 Moneyprinterturbo | 15/9/2025 | 17/6/2026 | wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd. | |
| Analizada | Media (6.9) | 0.68% | — | Harry0703 Moneyprinterturbo | 20/7/2025 | 17/6/2026 | A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue is the function verify_token of the file app/controllers/base.py of the component API Endpoint. The manipulation leads to missing authentication. The attack may be launched remotely. | |
| Analizada | Media (5.3) | 0.46% | — | Harry0703 Moneyprinterturbo | 20/7/2025 | 17/6/2026 | A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this vulnerability is the function download_video/delete_video of the file app/controllers/v1/video.py. The manipulation leads to path traversal. The attack can be launched remotely. | |
| Analizada | Media (5.3) | 0.40% | — | Harry0703 Moneyprinterturbo | 20/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in harry0703 MoneyPrinterTurbo up to 1.2.6. Affected is the function upload_bgm_file of the file app/controllers/v1/video.py of the component File Extension Handler. The manipulation of the argument File leads to unrestricted upload. It is possible to launch… | |
| Aplazada | Media (6.5) | 0.19% | — | Raise THE MoneyAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Raise The Money Raise The Money raise-the-money allows DOM-Based XSS.This issue affects Raise The Money: from n/a through <= 5.2. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Web-money-manager-exAI | 24/10/2024 | 17/6/2026 | Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the `TrDeleteArr` parameter, which is directly incorporated into an SQL query. | |
| Aplazada | Crítica (9.8) | 1.1% | — | Money Manager EX WebappAI | 24/10/2024 | 17/6/2026 | Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated attacker to upload arbitrary files,… | |
| Modificada | Media (5.4) | 0.20% | — | Themoneytizer THE Moneytizer | 6/6/2024 | 17/6/2026 | The The Moneytizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.6.3. This is due to missing or incorrect nonce validation on multiple AJAX functions. This makes it possible for unauthenticated attackers to to update and retrieve billing and bank details,… | |
| Modificada | Alta (8.1) | 0.39% | — | Themoneytizer THE Moneytizer | 6/6/2024 | 17/6/2026 | The The Moneytizer plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX functions in the /core/core_ajax.php file in all versions up to, and including, 9.6.3. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.32% | — | Themoneytizer THE MoneytizerAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Moneytizer allows Stored XSS.This issue affects The Moneytizer: from n/a through 9.5.20. | |
| Modificada | Alta (8) | 1.8% | — | Techvill Paymoney | 14/9/2022 | 17/6/2026 | PayMoney 3.3 is vulnerable to Client Side Remote Code Execution (RCE). The vulnerability exists on the reply ticket function and upload the malicious file. A calculator will open when the victim who download the file open the RTF file. | |
| Modificada | Media (5.4) | 0.60% | — | Techvill Paymoney | 14/9/2022 | 17/6/2026 | PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under "Message" field with "description" parameter with the specially crafted payload to gain Stored XSS. The XSS then will prompt after that or can be access from the view ticket function. | |
| Modificada | Media (5.4) | 0.50% | — | Techvill Paymoney | 26/7/2022 | 17/6/2026 | Paymoney v3.3 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the first_name and last_name parameters. | |
| Modificada | Alta (8.8) | 1.4% | — | Money Transfer Management System Project Money Transfer Management System | 10/6/2022 | 17/6/2026 | A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin role via any URL. |