Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.1) | — | — | Tomlister Payflex Payment GatewayAI | 6/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: from n/a through 2.7.1. | |
| Recibida | Media (5.3) | — | — | Deema Payment GatewayAI | 6/10/2026 | 6/10/2026 | The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, and does not check the payment status or amount, allowing unauthenticated users to have orders marked as paid without any payment being taken. | |
| Recibida | Media (5.3) | — | — | Deema Payment GatewayAI | 6/10/2026 | 6/10/2026 | The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by default, allowing unauthenticated attackers to mark an unpaid order as paid, or to cancel or refund an existing order. | |
| Recibida | Media (5.3) | 0.18% | — | UPI QR Code Payment GatewayAI | 5/10/2026 | 5/10/2026 | The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment. | |
| Aplazada | Media (5.3) | 0.18% | — | Paytm Payment GatewayAI | 2/10/2026 | 2/10/2026 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has not been configured, which is its state immediately after activation, allowing unauthenticated attackers to change the status of arbitrary orders,… | |
| Aplazada | Alta (7.5) | 0.18% | — | Paytm Payment GatewayAI | 1/10/2026 | 1/10/2026 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection… | |
| Aplazada | Alta (7.5) | 0.22% | — | Paytm Payment GatewayAI | 1/10/2026 | 1/10/2026 | The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin page, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to store scripts… | |
| Aplazada | Media (6.5) | 0.25% | — | Conekta Payment GatewayAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions. | |
| Aplazada | Media (6.5) | 0.19% | — | Payplus Payment GatewayAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions. | |
| Aplazada | Media (5.3) | 0.18% | — | Sumit Payment GatewayAI | 23/9/2026 | 24/9/2026 | The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment. | |
| Aplazada | Media (5.3) | 0.16% | — | Angelleye Payment Gateway FOR Paypal ON WoocommerceAI | 21/9/2026 | 22/9/2026 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own… | |
| Aplazada | Media (5.3) | 0.38% | — | WT Stripe Payment Gateway Stripe FOR WoocommerceAI | 19/9/2026 | 21/9/2026 | The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only… | |
| Aplazada | Baja (3.7) | 0.14% | — | Robokassa Payment Gateway FOR WoocommerceAI | 17/9/2026 | 18/9/2026 | The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold… | |
| Aplazada | Crítica (10) | 0.50% | — | Cryptopayment GatewayAI | 13/9/2026 | 14/9/2026 | The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored… | |
| Aplazada | Media (5.9) | 0.16% | — | Payment Gateway PaypayAI | 11/9/2026 | 11/9/2026 | The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as paid, or to cancel or fail them. | |
| Aplazada | Media (6.5) | 0.33% | — | Robokassa Payment Gateway FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions. | |
| Aplazada | Media (5.3) | 0.16% | — | Epayco Payment GatewayAI | 4/9/2026 | 8/9/2026 | The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark orders as paid without a valid gateway signature. | |
| Aplazada | Media (5.3) | 0.33% | — | Conekta Payment GatewayAI | 22/8/2026 | 26/8/2026 | The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as paid without payment. | |
| Aplazada | Media (6.5) | 0.42% | — | Piraeus Bank Woocommerce Payment GatewayAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Duitku Payment GatewayAI | 18/8/2026 | 20/8/2026 | Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Clink Bitcoin Lightning Payment GatewayAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | |
| Aplazada | Media (5.3) | 0.16% | — | Paypal Payment Gateway FOR WoocommerceAI | 12/8/2026 | 26/8/2026 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an order in its PayPal return handler: it reads attacker-controlled parameters, performs no amount comparison and no order-ownership check, and completes the order even when the… | |
| Aplazada | Alta (7.5) | 0.19% | — | Redyx Payment Gateway FOR Redsys AND Woocommerce LiteAI | 6/8/2026 | 26/8/2026 | The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own… | |
| Aplazada | Alta (7.5) | 0.36% | — | Clover Payment Gateway BY ZaytechAI | 27/7/2026 | 27/7/2026 | The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary orders as paid by… | |
| Aplazada | Alta (7.5) | 0.35% | — | Payment Gateway FOR PaypalAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions. |