Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Zaytech Smart Online Order FOR CloverAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. | |
| Aplazada | Alta (7.3) | 0.32% | — | Zaytech Smart Online Order FOR CloverAI | 27/5/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Retrieve Embedded Sensitive Data.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0. | |
| Aplazada | Alta (7.3) | 0.40% | — | Zaytech Smart Online Order FOR CloverAI | 27/5/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Authentication Bypass.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Zaytech Smart Online Order FOR CloverAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Stored XSS.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0. | |
| Aplazada | Media (4.3) | 0.11% | — | Zaytech Smart Online Order FOR CloverAI | 15/4/2026 | 5/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0. | |
| Modificada | Alta (8.8) | 0.42% | — | Zaytech Smart Online Order FOR Clover | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders.This issue affects Smart Online Order for Clover: from n/a through <= 1.5.6. | |
| Modificada | Crítica (9.8) | 0.62% | — | Zaytech Smart Online Order FOR Clover | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders.This issue affects Smart Online Order for Clover: from n/a through <= 1.5.6. | |
| Analizada | Media (6.1) | 0.40% | — | Zaytech Smart Online Order FOR Clover | 16/10/2024 | 17/6/2026 | The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (5.4) | 0.36% | — | Zaytech Smart Online Order FOR Clover | 15/10/2024 | 17/6/2026 | The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo_receipt_link shortcode in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (6.5) | 0.48% | — | Zaytech Smart Online Order FOR Clover | 21/8/2024 | 17/6/2026 | The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'moo_deactivateAndClean' function in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to deactivate the plugin and drop all plugin… | |
| Modificada | Media (4.3) | 0.35% | — | Zaytech Smart Online Order FOR Clover | 21/8/2024 | 17/6/2026 | The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.5.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update product and… | |
| Modificada | Alta (8.8) | 0.22% | — | Zaytech Smart Online Order FOR Clover | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Zaytech Smart Online Order for Clover.This issue affects Smart Online Order for Clover: from n/a through 1.5.5. | |
| Modificada | Media (5.4) | 0.34% | — | Zaytech Smart Online Order FOR Clover | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zaytech Smart Online Order for Clover allows Stored XSS.This issue affects Smart Online Order for Clover: from n/a through 1.5.5. | |
| Modificada | Media (6.1) | 0.33% | — | Zaytech Smart Online Order FOR Clover | 31/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zaytech Smart Online Order for Clover plugin <= 1.5.4 versions. |