Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.18% | — | UPI QR Code Payment GatewayAI | 5/10/2026 | 6/10/2026 | The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it claims to confirm, allowing unauthenticated attackers to mark an arbitrary order as paid without making any payment. | |
| Aplazada | Alta (8.1) | 0.39% | — | Taskingai QR Code GeneratorAI | 2/10/2026 | 2/10/2026 | In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter. | |
| Aplazada | Baja (2.1) | 0.27% | — | Sourcecodester Smart Attendance System With QR Code ScannerAI | 23/9/2026 | 23/9/2026 | A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signup.php of the component Self-Registration. Performing a manipulation of the argument full_name results in cross site scripting. Remote exploitation of the attack… | |
| Aplazada | Baja (2) | 0.40% | — | Codeastro QR Code Attendance Management SystemAI | 20/9/2026 | 21/9/2026 | A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of the file app/Controllers/UserController.php. The manipulation of the argument role_id results in improper privilege management. The attack can be executed remotely. The exploit is now public and may be… | |
| Aplazada | Media (5.4) | 0.29% | — | UPI QR Code Payment GatewayAI | 25/6/2026 | 25/6/2026 | Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions. | |
| Aplazada | Media (6.5) | 0.29% | — | Knitpay UPI QR Code Payment Gateway FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in knitpay UPI QR Code Payment Gateway for WooCommerce upi-qr-code-payment-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UPI QR Code Payment Gateway for WooCommerce: from n/a through <= 1.5.1. | |
| Aplazada | Alta (8.1) | 0.50% | — | Magic Login Mail OR QR CodeAI | 14/2/2026 | 17/6/2026 | The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugin storing the magic login QR code image with a predictable, static filename (QR_Code.png) in the publicly accessible WordPress uploads directory during the… | |
| Aplazada | Media (5.9) | 0.16% | — | Devsbrain Flex QR Code GeneratorAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Devsbrain Flex QR Code Generator flex-qr-code-generator allows DOM-Based XSS.This issue affects Flex QR Code Generator: from n/a through <= 1.2.10. | |
| Aplazada | Media (6.4) | 0.26% | — | QR Code FOR Woocommerce Order Emails PDF Invoices Packing SlipsAI | 7/1/2026 | 17/6/2026 | The QR Code for WooCommerce order emails, PDF invoices, packing slips plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and including, 1.9.42 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Analizada | Alta (7.3) | 0.20% | — | Angeljudesuarez Covid Tracking System Using Qr-code | 17/12/2025 | 17/6/2026 | A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using QR-Code v1.0. The reason for this issue is that attackers inject malicious code from the parameter 'id' and use it directly in SQL queries without the need for appropriate cleaning or validation. | |
| Aplazada | Crítica (9.8) | 0.73% | 💥 PoC | Flex QR Code GeneratorAI | 6/12/2025 | 17/6/2026 | The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_qr_code() function in all versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which… | |
| Aplazada | Media (4.3) | 0.15% | — | USB QR Code Scanner FOR WoocommerceAI | 11/11/2025 | 17/6/2026 | The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation on the settings page. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request… | |
| Aplazada | Crítica (9.8) | 0.92% | 💥 PoC | Flex QR Code GeneratorAI | 15/10/2025 | 17/6/2026 | The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in thesave_qr_code_to_db() function in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which… | |
| Aplazada | Alta (7.1) | 0.15% | — | Olar Marius Vasaio Vasaio QR CodeAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Olar Marius Vasaio QR Code vasaio-qr-code allows Stored XSS.This issue affects Vasaio QR Code: from n/a through <= 1.2.5. | |
| Aplazada | Alta (7.1) | 0.29% | — | Bappa MAL QR Code FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bappa Mal QR Code for WooCommerce wc-qr-codes allows Reflected XSS.This issue affects QR Code for WooCommerce: from n/a through <= 1.2.0. | |
| Aplazada | Media (4.3) | 0.19% | — | Goaskle QR Code TAG FOR WCAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in www.15.to QR Code Tag for WC qr-code-tag-for-wc-from-goaskle-com allows Cross Site Request Forgery.This issue affects QR Code Tag for WC: from n/a through <= 1.9.42. | |
| Aplazada | Media (6.5) | 0.37% | — | Luke America WCS QR Code GeneratorAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luke America WCS QR Code Generator wcs-qr-code-generator allows Stored XSS.This issue affects WCS QR Code Generator: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.37% | — | Mobstac QR Code GeneratorAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mobstac QR Code Generator qrcode-wprhe allows DOM-Based XSS.This issue affects QR Code Generator: from n/a through <= 1.2.6. | |
| Aplazada | Media (6.5) | 0.21% | — | Roberto Bottalico QR Code AND Barcode Scanner ReaderAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roberto Bottalico Qr Code and Barcode Scanner Reader qr-code-and-barcode-scanner-reader allows Stored XSS.This issue affects Qr Code and Barcode Scanner Reader: from n/a through <= 1.0.0. | |
| Aplazada | Media (4.3) | 0.47% | — | Stanislav Kuznetsov QR Code Mecard Vcard GeneratorAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Stanislav Kuznetsov QR code MeCard/vCard generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects QR code MeCard/vCard generator: from n/a through 1.6.0. | |
| Aplazada | Media (6.5) | 0.25% | — | Shawfactor LH QR CodesAI | 11/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shawfactor LH QR Codes lh-qr-codes allows Stored XSS.This issue affects LH QR Codes: from n/a through <= 1.06. | |
| Modificada | Alta (7.2) | 0.33% | — | Wordpress Thanh Toan Quet MA QR Code TU Dong | 25/9/2024 | 17/6/2026 | The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute for certain HTML… | |
| Analizada | Media (5.3) | 0.45% | — | Rems QR Code Attendance System | 26/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Attendance System 1.0. This issue affects some unknown processing of the file /endpoint/delete-student.php. The manipulation of the argument student/attendance leads to cross site scripting. The attack may be initiated… | |
| Analizada | Media (5.3) | 0.41% | — | Rems QR Code Bookmark System | 25/8/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester QR Code Bookmark System 1.0. Affected is an unknown function of the file /endpoint/update-bookmark.php of the component Parameter Handler. The manipulation of the argument tbl_bookmark_id/name/url leads to cross site scripting. It is possible… | |
| Analizada | Media (5.3) | 0.41% | — | Rems QR Code Bookmark System | 25/8/2024 | 17/6/2026 | A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /endpoint/delete-bookmark.php. The manipulation of the argument bookmark leads to cross site scripting. The attack may be initiated remotely. The exploit has… |