Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2667▼ 241 respecto a la semana anterior
Críticas / altas1361▲ 103 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.55% | — | Riaxe Product CustomizerAI | 16/4/2026 | 17/6/2026 | The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within 'product_data' of the /wp-json/InkXEProductDesignerLite/add-item-to-cart REST API endpoint in all versions up to, and including, 2.1.2. This is due to insufficient escaping on the user-supplied… | |
| Aplazada | Crítica (9.8) | 0.84% | — | Riaxe Product CustomizerAI | 16/4/2026 | 17/6/2026 | The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin registers an unauthenticated AJAX action ('wp_ajax_nopriv_install-imprint') that maps to the ink_pd_add_option() function. This function reads 'option' and 'opt_value' from… | |
| Aplazada | Media (5.3) | 0.57% | — | Riaxe Product CustomizerAI | 16/4/2026 | 17/6/2026 | The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.2. This is due to the plugin registering a REST API route at POST /wp-json/InkXEProductDesignerLite/customer/delete_customer without a permission_callback, causing WordPress to default to… | |
| Aplazada | Media (5.3) | 0.64% | — | Riaxe Product CustomizerAI | 8/4/2026 | 24/7/2026 | The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4 via the '/wp-json/InkXEProductDesignerLite/orders' REST API endpoint. The endpoint is registered with 'permission_callback' set to '__return_true', meaning no authentication or… | |
| Aplazada | Alta (7.5) | 0.38% | — | Vertim Neon Channel Product Customizer FreeAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in vertim Neon Channel Product Customizer Free neon-channel-product-customizer-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Neon Channel Product Customizer Free: from n/a through <= 2.0. | |
| Analizada | Media (5.4) | 0.30% | — | K2-service Product Customizer Light | 18/10/2024 | 17/6/2026 | The Product Customizer Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… |