Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
1829 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.1) | — | — | ShopclassAI | 2/10/2026 | 2/10/2026 | Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is enabled. Attackers can submit malicious JavaScript, which ItemActions.php saves without tag stripping, causing it to execute… | |
| Aplazada | Media (6.8) | 0.15% | — | Wpshopmart Tabs ResponsiveAI | 2/10/2026 | 2/10/2026 | The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager to store JavaScript that executes when any user, including an administrator, views the product page. | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode PET Shop Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of the argument filter leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode PET Shop Management SystemAI | 2/10/2026 | 2/10/2026 | A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may… | |
| Aplazada | Alta (8.8) | 0.47% | — | Wpclever WPC Shop AS A CustomerAI | 1/10/2026 | 1/10/2026 | The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated… | |
| Aplazada | Alta (7.1) | 0.18% | — | Trusted Shops Easy Integration FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions. | |
| Aplazada | Media (6.8) | 0.18% | — | Bishopfox SliverAI | 29/9/2026 | 30/9/2026 | Sliver C2 framework version 1.7.7 and earlier contains an unhandled panic vulnerability in the operator gRPC handler that allows an attacker controlling a compromised implant to crash the entire teamserver by returning a malformed or empty Download response. Attackers can send zero-length or 1-3 byte data payloads… | |
| Aplazada | Media (5.5) | 0.42% | — | ShopxoAIBaidu UeditorAI | 24/9/2026 | 24/9/2026 | A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the component Ueditor Upload Interface. The manipulation of the argument path_type results in path traversal. It is possible to launch the attack remotely. The… | |
| Aplazada | Alta (7.2) | 0.40% | — | Reycob Shop ManagerAI | 23/9/2026 | 23/9/2026 | Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions. | |
| Aplazada | Media (6.1) | 0.37% | — | Hasthemes ShoplentorAI | 18/9/2026 | 19/9/2026 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query-String Parameter Name in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (9) | 0.81% | — | Wpshopgermany IT Recht KanzleiAI | 17/9/2026 | 18/9/2026 | The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to validate it, allowing unauthenticated attackers to predict the token and use the access… | |
| Aplazada | Media (5.3) | 0.34% | — | Prestashop BlockwishlistAI | 16/9/2026 | 22/9/2026 | PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers'… | |
| Aplazada | Media (5.3) | 0.34% | — | Prestashop PsgdprAI | 16/9/2026 | 22/9/2026 | PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs. | |
| Aplazada | Alta (7.1) | 0.46% | — | Yshop CRMAI | 16/9/2026 | 24/9/2026 | yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list permission to enumerate all users. Attackers with valid back-office credentials and a role… | |
| Aplazada | Alta (7.1) | 0.43% | — | Yshop-crmAI | 16/9/2026 | 24/9/2026 | yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps. Attackers can invoke the DELETE /admin-api/crm/flow/delete-step endpoint without required permissions to remove… | |
| Aplazada | Media (5.3) | 0.38% | — | Yshop-crmAI | 16/9/2026 | 23/9/2026 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers can retrieve approval chain topology, step ordering, approver identifiers, and personal information including… | |
| Aplazada | Alta (7.1) | 0.45% | — | Yshop-crmAI | 16/9/2026 | 23/9/2026 | yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to retrieve operator names, display nicknames, client IP addresses, User-Agent… | |
| Aplazada | Alta (7.1) | 0.43% | — | Yshop CRMAI | 16/9/2026 | 24/9/2026 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim endpoint to reassign leads from other employees to themselves… | |
| Aplazada | Media (5.3) | 0.35% | — | Yshop-crmAI | 16/9/2026 | 23/9/2026 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status. Attackers can invoke the GET /admin-api/product/store-product/sale endpoint with sequential product IDs to withdraw entire… | |
| Aplazada | Alta (7.1) | 0.43% | — | Yshop-crmAI | 16/9/2026 | 23/9/2026 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/invoice/issue endpoint without required permissions to modify invoice status,… | |
| Aplazada | Alta (7.1) | 0.50% | — | Yshop-crmAI | 16/9/2026 | 23/9/2026 | yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can invoke these endpoints to manipulate shared… | |
| Aplazada | Media (5.3) | 0.36% | — | Yshop-crm Yshop CRMAI | 16/9/2026 | 23/9/2026 | yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers. Attackers can invoke POST /admin-api/crm/customer/send-sms and POST /admin-api/crm/customer/send-mail with… | |
| Aplazada | Media (6.5) | 0.43% | — | ShopperAI | 15/9/2026 | 30/9/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Discounts/DiscountCalculator.php and vendor/shopper/cart/src/Pipelines/Calculate.php… | |
| Aplazada | Media (6.5) | 0.39% | — | ShopperAI | 15/9/2026 | 30/9/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used by sibling sub-forms. An authenticated staff user with browse_products can invoke… | |
| Aplazada | Alta (8.1) | 0.50% | — | ShopperAI | 15/9/2026 | 30/9/2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable because it lacks the Livewire Locked attribute. Any authenticated admin-panel user,… |