Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.36%—Product Feed ManagerAI17/9/202617/9/2026
Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
AplazadaAlta (8.1)0.39%—Product Feed Manager FOR WoocommerceAI31/7/202626/8/2026
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.
AplazadaAlta (7.1)0.25%—Product Feed ManagerAI27/7/202627/7/2026
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
AplazadaMedia (6.1)0.38%—Webappick Product Feed Manager FOR WoocommerceAI16/7/202616/7/2026
The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 7.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaMedia (5.5)0.42%—Rextheme Product Feed ManagerAI15/4/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RexTheme Product Feed Manager.This issue affects Product Feed Manager: from n/a through 7.3.15.