Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (8.8) | 0.37% | — | Smart ManagerAI | 3/10/2026 | 3/10/2026 | The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Media (4.8) | 0.24% | — | Smart ManagerAI | 27/7/2026 | 27/7/2026 | The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid. | |
| Aplazada | Alta (7.1) | 0.25% | — | Smart ManagerAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | Storeapps Smart ManagerAI | 25/5/2026 | 24/7/2026 | Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0. | |
| Aplazada | Alta (7.6) | 0.83% | — | Storeapps Smart Manager FOR WP E CommerceAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce allows Blind SQL Injection.This issue affects Smart Manager: from n/a through <= 8.52.0. | |
| Aplazada | Media (4.3) | 0.29% | — | Storeapps Smart Manager FOR WP E CommerceAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in storeapps Smart Manager smart-manager-for-wp-e-commerce.This issue affects Smart Manager: from n/a through <= 8.45.0. | |
| Modificada | Alta (7.2) | 3.3% | — | Storeapps Smart Manager | 12/2/2024 | 17/6/2026 | The Smart Manager WordPress plugin before 8.28.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | |
| Modificada | Alta (7.1) | 0.22% | — | Samsung Smart Manager | 11/6/2021 | 17/6/2026 | Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege. |