Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.13% | — | Implecode Ecommerce Product CatalogAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Stored XSS.This issue affects eCommerce Product Catalog: from n/a through 3.6.2. | |
| Aplazada | Alta (7.2) | 0.37% | — | Implecode Ecommerce Product CatalogAI | 30/9/2026 | 30/9/2026 | Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. | |
| Aplazada | Alta (7.1) | 0.35% | — | Pixelyoursite EDD Product Catalog FeedAI | 8/9/2026 | 8/9/2026 | The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the wpeddpcf_delete_feed function in all versions up to, and including, 1.0.2. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.33% | — | Multivendorx Product Catalog Enquiry FOR WoocommerceAI | 8/9/2026 | 25/9/2026 | Incorrect Privilege Assignment vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX woocommerce-catalog-enquiry allows Privilege Escalation.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 6.1.5. | |
| Aplazada | Media (6.4) | 0.36% | — | Implecode Ecommerce Product CatalogAI | 25/8/2026 | 28/9/2026 | The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Alta (7.1) | 0.25% | — | Implecode Ecommerce Product CatalogAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Implecode Ecommerce Product CatalogAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. | |
| Aplazada | Alta (8.7) | 0.32% | — | Wpultimate Wordpress Ultimate Product CatalogAI | 15/6/2026 | 17/6/2026 | WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator roles to upload malicious files by exploiting the custom fields functionality. Attackers can upload PHP shells through the Products tab custom file… | |
| Aplazada | Alta (8.8) | 0.27% | — | Product Catalog 8AI | 9/6/2026 | 21/7/2026 | Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the selectedCategory parameter. Attackers can submit POST requests to the admin-ajax.php endpoint with the UpdateCategoryList… | |
| Aplazada | Media (5.1) | 0.28% | — | Ultimate Product CatalogueAI | 10/5/2026 | 25/7/2026 | Ultimate Product Catalogue 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the price parameter. Attackers can submit POST requests to post.php with HTML/JavaScript payloads in the price field to execute arbitrary code when the product… | |
| Aplazada | Media (4.3) | 0.13% | — | Implecode Product Catalog SimpleAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in impleCode Product Catalog Simple post-type-x.This issue affects Product Catalog Simple: from n/a through <= 1.8.4. | |
| Aplazada | Media (6.5) | 0.21% | — | Implecode Product Catalog SimpleAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode Product Catalog Simple post-type-x allows Stored XSS.This issue affects Product Catalog Simple: from n/a through <= 1.8.2. | |
| Aplazada | Alta (7.2) | 0.52% | — | Implecode Ecommerce Product CatalogAI | 17/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Object Injection.This issue affects eCommerce Product Catalog: from n/a through <= 3.4.3. | |
| Aplazada | Media (6.5) | 0.25% | — | Implecode Product Catalog SimpleAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode Product Catalog Simple post-type-x allows Stored XSS.This issue affects Product Catalog Simple: from n/a through <= 1.8.1. | |
| Aplazada | Crítica (9.3) | 0.59% | — | Origincode Product CatalogAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in origincode Product Catalog displayproduct allows SQL Injection.This issue affects Product Catalog: from n/a through <= 1.0.4. | |
| Analizada | Media (5.4) | 0.29% | — | Implecode Product Catalog Simple | 28/2/2025 | 17/6/2026 | The Product Catalog Simple plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_products shortcode in all versions up to, and including, 1.7.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (8.8) | 0.27% | — | Implecode Ecommerce Product CatalogAI | 21/12/2024 | 17/6/2026 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.43. This is due to missing or incorrect nonce validation on the 'customer_panel_password_reset' function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.4) | 0.51% | — | Multivendorx Product Catalog Enquiry FOR WoocommerceAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.2. | |
| Modificada | Crítica (9.1) | 0.32% | — | Multivendorx Product Catalog Mode FOR Woocommerce | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 5.0.5. | |
| Aplazada | Alta (7.1) | 0.37% | — | Implecode Ecommerce Product CatalogAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog allows Reflected XSS.This issue affects eCommerce Product Catalog: from n/a through 3.3.32. | |
| Aplazada | Media (4.3) | 0.20% | — | Etoilewebdesign Ultimate Product CatalogueAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Etoile Web Design Ultimate Product Catalogue.This issue affects Ultimate Product Catalogue: from n/a through 5.2.15. | |
| Aplazada | Media (4.3) | 0.21% | — | Implecode Ecommerce Product CatalogAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in impleCode eCommerce Product Catalog.This issue affects eCommerce Product Catalog: from n/a through 3.3.28. | |
| Analizada | Crítica (9.8) | 0.53% | — | Myprestamodules Product Catalog (csv, Excel) Import | 3/3/2024 | 17/6/2026 | SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods. | |
| Analizada | Crítica (9.1) | 0.79% | — | Myprestamodules Product Catalog (csv, Excel) Import | 27/2/2024 | 17/6/2026 | In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php. | |
| Modificada | Alta (7.5) | 0.48% | — | Implecode Ecommerce Product Catalog | 29/12/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress.This issue affects eCommerce Product Catalog Plugin for WordPress: from n/a through 3.3.26. |