Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
200 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.24% | — | Easy Paypal Stripe BUY NOW ButtonAI | 2/10/2026 | 2/10/2026 | The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a client-supplied field, so an unauthenticated attacker sets an arbitrary lower price for a purchase. | |
| Aplazada | Alta (7.5) | 0.25% | — | WP Full StripeAI | 1/10/2026 | 3/10/2026 | Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions. | |
| Aplazada | Alta (8.6) | 0.27% | — | Jet-form-builder-stripe-gatewayAI | 23/9/2026 | 23/9/2026 | The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes. | |
| Aplazada | Media (5.3) | 0.38% | — | WT Stripe Payment Gateway Stripe FOR WoocommerceAI | 19/9/2026 | 21/9/2026 | The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only… | |
| Aplazada | Alta (8.2) | 0.71% | — | Stripe CheckoutAI | 14/9/2026 | 18/9/2026 | Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkout_sessions/route.ts), exposed at GET /api/stripe/checkout_sessions, in MarcosCamara01 Ecommerce Template before commit 91e273c allows a remote, unauthenticated attacker holding a valid Stripe… | |
| Aplazada | Media (5.3) | 0.34% | — | Paymentpluginsforstripe Payment Plugins FOR StripeAI | 9/9/2026 | 9/9/2026 | The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the billing details of any order, together with the secret that gates access to it, by… | |
| Aplazada | Media (5.3) | 0.30% | — | Accept Stripe PaymentsAI | 5/9/2026 | 8/9/2026 | The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who… | |
| Aplazada | Media (4.3) | 0.30% | — | Accept Stripe PaymentsAI | 5/9/2026 | 8/9/2026 | The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing. | |
| Aplazada | Media (4.3) | 0.25% | — | WP Full PAY Stripe Payment FormsAI | 29/8/2026 | 31/8/2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed portal session to cancel subscriptions belonging to other customers. Exploitation… | |
| Aplazada | Media (5.4) | 0.34% | — | Silverstripe VersionedAI | 28/8/2026 | 9/9/2026 | Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src/RestoreAction.php builds ArchiveAdmin restore notifications rendered as CAST_HTML and inserts $restoredItem->Title, $restoredItem->URLSegment, $restoredItem->CMSEditLink(), and… | |
| Aplazada | Alta (8.8) | 0.73% | — | Silverstripe UserformsAISilverstripe CMSAI | 27/8/2026 | 9/9/2026 | Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted as executable server-side code. An authenticated CMS user with permission to… | |
| Aplazada | Alta (7.2) | 1.0% | — | Silverstripe Advanced WorkflowAISilverstripeAI | 27/8/2026 | 9/9/2026 | Silverstripe Advanced Workflow is a highly configurable step-based workflow module. Prior to 6.4.5, 7.1.3, and 7.2.1, an attacker with permission to author the advanced workflow email template can place a specially crafted server-side template payload in NotifyUsersWorkflowAction.EmailTemplate. When… | |
| Aplazada | Media (4.3) | 0.25% | — | WP Full PAY Stripe Payment FormsAI | 26/8/2026 | 26/8/2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before acting on it, allowing a user with a confirmed portal session to cancel, reactivate or modify subscriptions belonging to other… | |
| Aplazada | Media (5.3) | 0.34% | — | WP Full PAY Stripe Payment FormsAI | 26/8/2026 | 26/8/2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal session has completed its confirmation step before returning data, allowing unauthenticated users to read another customer's subscription and billing information. | |
| Aplazada | Alta (7.1) | 0.25% | — | Stripe PaymentsAI | 24/8/2026 | 26/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Contact Form 7 Paypal AND Stripe Add-onAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | WP Full StripeAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Full Stripe Free <= 8.5.0 versions. | |
| Aplazada | Alta (8.6) | 0.57% | — | ChaskiqAIStripeAI | 11/8/2026 | 3/9/2026 | A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIntent GraphQL mutation. The mutation lacks authentication and authorization checks, exposing Stripe payment intent creation to… | |
| Aplazada | Baja (3.7) | 0.24% | — | Accept Paypal Stripe With Subscriptions FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the order marked as fully paid when the PayPal… | |
| Aplazada | Media (5.3) | 0.29% | — | Accept Paypal Stripe With Subscriptions FOR WoocommerceAI | 10/8/2026 | 26/8/2026 | The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a WooCommerce order by paying the full… | |
| Aplazada | Media (5.4) | 0.34% | — | Silverstripe CMSAI | 6/8/2026 | 8/9/2026 | Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when viewed using the page list view, because page titles are rendered into the breadcrumb trail without being escaped. This issue is fixed in 6.2.1. | |
| Aplazada | Alta (7.5) | 0.35% | — | WP Full PAY Stripe Payment FormsAI | 6/8/2026 | 26/8/2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by two unauthenticated payment-form AJAX actions, allowing an unauthenticated visitor — using a nonce that is embedded in every public page containing a payment form — to… | |
| Aplazada | Alta (7.1) | 0.31% | — | Better-auth StripeAI | 1/8/2026 | 8/9/2026 | @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the organization ID taken from the request query string against the authorizeReference callback, but the handler reads the… | |
| Aplazada | Alta (7.5) | 0.35% | — | Stripe FOR WoocommerceAI | 27/7/2026 | 27/7/2026 | Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions. | |
| Aplazada | Media (5.3) | 0.61% | — | Paymentplugins Payment Plugins FOR StripeAI | 24/7/2026 | 24/7/2026 | The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark arbitrary… |