Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.1) | 0.24% | — | Prestalife Product DesignerAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Lumise Product Designer <= 2.1.1 versions. | |
| Aplazada | Alta (7.5) | 0.90% | — | Product Designer APPAI | 30/9/2026 | 30/9/2026 | The Product Designer App plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.3 via the 'svg' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The… | |
| Aplazada | Alta (7.2) | 0.27% | — | Radykal Fancy Product DesignerAI | 25/9/2026 | 25/9/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Alta (7.2) | 0.21% | — | Radykal Fancy Product DesignerAI | 25/9/2026 | 25/9/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Alta (7.2) | 0.19% | — | Radykal Fancy Product DesignerAI | 25/9/2026 | 25/9/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (7.5) | 0.94% | — | Printcart WEB TO Print Product DesignerAI | 18/9/2026 | 18/9/2026 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain… | |
| Aplazada | Alta (7.5) | 0.35% | — | Shirt Product DesignerAI | 10/9/2026 | 10/9/2026 | Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions. | |
| Aplazada | Alta (8.6) | 0.44% | — | Printcart WEB TO Print Product DesignerAI | 27/7/2026 | 29/9/2026 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration files containing… | |
| Aplazada | Alta (7.5) | 0.46% | — | Lumise Product Designer FOR WoocommerceAI | 23/7/2026 | 23/7/2026 | The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX action in versions up to, and including, 2.1.1. This is due to insufficient escaping on the user-supplied parameters before… | |
| Aplazada | Crítica (9.1) | 1.2% | — | Printcart WEB TO Print Product DesignerAI | 3/7/2026 | 7/7/2026 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key'… | |
| Aplazada | Media (5.3) | 0.39% | — | Printcart WEB TO Print Product DesignerAI | 26/6/2026 | 30/9/2026 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker to retrieve the directory listing for arbitrary directories on the server. | |
| Aplazada | Crítica (9.3) | 0.28% | — | King-theme Lumise Product DesignerAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise Product Designer lumise allows Blind SQL Injection.This issue affects Lumise Product Designer: from n/a through < 2.0.9. | |
| Aplazada | Media (5.3) | 0.32% | — | Radykal Fancy Product DesignerAI | 16/1/2026 | 17/6/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.8. This is due to improper error handling in the PDF upload functionality that exposes server filesystem paths and stack traces in error messages. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.22% | — | SAP Product Designer WEB UIAISAP Business Server PagesAI | 13/1/2026 | 17/6/2026 | SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application. | |
| Aplazada | Media (6.5) | 0.18% | — | Radykal Fancy Product DesignerAI | 16/12/2025 | 17/6/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.4.8. This is due to a time-of-check/time-of-use (TOCTOU) race condition in the 'url' parameter of the fpd_custom_uplod_file AJAX action. The plugin validates the URL by calling… | |
| Aplazada | Media (5.9) | 0.31% | — | Radykal Fancy Product DesignerAI | 16/12/2025 | 17/6/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all versions up to, and including, 6.4.8. This is due to insufficient validation of user-supplied input in the 'url' parameter of the 'fpd_custom_uplod_file' AJAX action, which flows directly into the… | |
| Aplazada | Alta (7.2) | 0.25% | — | Radykal Fancy Product DesignerAI | 12/12/2025 | 17/6/2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping in the data-to-image.php and pdf-to-image.php files. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.29% | — | Printcart WEB TO Print Product Designer FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.8. | |
| Aplazada | Alta (8.5) | 0.29% | — | Printcart WEB TO Print Product Designer FOR WoocommerceAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows SQL Injection.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.0. | |
| Aplazada | Crítica (9.3) | 1.4% | — | Mystyleplatform Mystyle-custom-product-designerAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mystyleplatform MyStyle Custom Product Designer mystyle-custom-product-designer allows Blind SQL Injection.This issue affects MyStyle Custom Product Designer: from n/a through <= 3.21.1. | |
| Aplazada | Crítica (10) | 0.42% | — | Printcart WEB TO Print Product Designer FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows Upload a Web Shell to a Web Server.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.3.9. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Printcart WEB TO Print Product Designer FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce printcart-integration allows SQL Injection.This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through <= 2.4.0. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Vertim Neon Product Designer FOR WoocommerceAI | 11/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vertim Neon Product Designer neon-product-designer-for-woocommerce allows SQL Injection.This issue affects Neon Product Designer: from n/a through <= 2.2.0. | |
| Aplazada | Crítica (9) | 0.53% | — | Radykal Fancy Product DesignerAI | 21/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through <= 6.4.3. | |
| Aplazada | Crítica (9.3) | 16% | — | Radykal Fancy Product DesignerAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Product Designer fancy-product-designer.This issue affects Fancy Product Designer: from n/a through <= 6.4.3. |