Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2528▼ 418 respecto a la semana anterior
Críticas / altas1311▲ 21 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.18% | — | Inspireui Mstore APIAI | 2/10/2026 | 2/10/2026 | The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-registerable account to change the status of their own unpaid order to a paid or fulfilled state and receive the goods without paying. | |
| Aplazada | Crítica (9.8) | 0.45% | — | Inspireui Mstore APIAI | 5/9/2026 | 8/9/2026 | The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid,… | |
| Aplazada | Media (6.5) | 0.17% | — | Inspireui Mstore APIAI | 29/8/2026 | 31/8/2026 | The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated user, including Subscribers, to mark arbitrary orders as paid without any payment… | |
| Aplazada | Media (6.5) | 0.17% | — | Inspireui Mstore APIAI | 29/8/2026 | 31/8/2026 | The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscribers, to mark arbitrary orders as completed and paid without any payment being made. | |
| Aplazada | Baja (2.1) | 0.47% | — | Calix GigaspireAI | 13/8/2026 | 14/8/2026 | A vulnerability has been found in Calix GigaSpire 26.1.0. The affected element is an unknown function of the file traceroute.cmd. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this… | |
| Aplazada | Baja (2.1) | 0.47% | — | Calix GigaspireAI | 13/8/2026 | 14/8/2026 | A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknown function of the file utilities_configurationsave.cgi of the component Web Management Interface. Executing a manipulation of the argument sessionKey can lead to denial of service. The attack can be launched remotely. The exploit has been published… | |
| Aplazada | Alta (8.1) | 0.37% | — | Inspireui Mstore APIAI | 13/8/2026 | 14/8/2026 | Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions. | |
| Aplazada | Alta (7.5) | 0.36% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept… | |
| Aplazada | Media (6.5) | 0.34% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information. | |
| Aplazada | Crítica (9.1) | 0.42% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free. | |
| Aplazada | Alta (8.1) | 0.38% | — | Inspireui Mstore APIAI | 7/8/2026 | 26/8/2026 | The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts. | |
| Aplazada | Media (6.5) | 0.27% | — | Inspireui Mstore APIAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MStore API: from n/a through <= 4.18.4. | |
| Aplazada | Media (6.5) | 0.46% | — | Inspireui Mstore APIAI | 17/6/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4. | |
| Aplazada | Crítica (9.3) | 0.59% | — | Inspireui Mstore APIAI | 10/5/2026 | 25/7/2026 | WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary names to the config_file endpoint to achieve remote code execution on the server. | |
| Aplazada | Media (5.5) | 0.59% | — | Eiceblue Spire-pdf-mcp-serverAI | 28/4/2026 | 24/7/2026 | A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spire_pdf_mcp/server.py of the component PDF File Handler. Executing a manipulation of the argument filepath can lead to path traversal. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.59% | — | Eiceblue Spire-doc-mcp-serverAI | 28/4/2026 | 24/7/2026 | A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file src/spire_doc_mcp/api/base.py. Performing a manipulation of the argument document_name results in path traversal. The attack can be initiated remotely. The exploit is now public and may be used. The… | |
| Aplazada | Media (4.3) | 0.36% | — | Inspireui Mstore APIAI | 9/4/2026 | 24/7/2026 | The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.18.3. This is due to the update_user_profile() function in controllers/flutter-user.php processing the 'meta_data' JSON parameter without any allowlist, blocklist, or validation of meta keys.… | |
| Aplazada | Alta (8.8) | 0.34% | — | Videospirecore Theme PluginAI | 11/2/2026 | 17/6/2026 | The 'Videospirecore Theme Plugin' plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.6. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated… | |
| Analizada | Media (4.3) | 0.29% | — | Inspireui Mstore API | 27/5/2025 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to, and including, 4.17.5. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (4.8) | 0.20% | — | Funaudiollm InspiremusicAI | 25/5/2025 | 17/6/2026 | A vulnerability was found in FunAudioLLM InspireMusic up to bf32364bcb0d136497ca69f9db622e9216b029dd. It has been classified as critical. Affected is the function load_state_dict of the file inspiremusic/cli/model.py of the component Pickle Data Handler. The manipulation leads to deserialization. An attack has to be… | |
| Analizada | Alta (7.3) | 0.34% | — | Inspireui Mstore API | 2/5/2025 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction of role when registering. This makes it possible for unauthenticated attackers to to register with the… | |
| Analizada | Media (5.4) | 0.33% | — | Inspireui Mstore API | 13/12/2024 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to, and including, 4.16.4 due to insufficient file type validation. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.46% | — | Inspireui Mstore API | 20/11/2024 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via the 'status_type' parameter in all versions up to, and including, 4.15.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Analizada | Media (6.5) | 0.38% | — | Inspireui Mstore API | 13/9/2024 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the plugin not checking that user registration is enabled prior to creating a user account through the register() function.… | |
| Analizada | Alta (8.8) | 0.78% | — | Inspireui Mstore API | 13/9/2024 | 17/6/2026 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function in all versions up to, and including, 4.15.3. This makes it possible for authenticated attackers, with subscriber-level… |