Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (4.3) | 0.16% | — | Helpdesk Support Ticket System FOR WoocommerceAI | 3/10/2026 | 3/10/2026 | The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level… | |
| Aplazada | Crítica (9.8) | 0.95% | — | Customer Support Ticket System HelpdeskAI | 23/7/2026 | 23/7/2026 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.26% | — | Perfect Support Ticketing & Document Management SystemAI | 16/7/2026 | 16/7/2026 | Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets by bypassing intended authorization checks. Attackers can add or remove any user,… | |
| Aplazada | Media (5.1) | 0.24% | — | Perfect Support Ticketing AND Document Management SystemAI | 16/7/2026 | 18/7/2026 | Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in… | |
| Aplazada | Crítica (9.8) | 0.45% | — | Support Ticket Management SystemAI | 17/6/2026 | 30/9/2026 | Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions. | |
| Aplazada | Alta (8.6) | 0.53% | — | Vanquish Woocommerce-support-ticket-systemAI | 25/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerce-support-ticket-system allows Path Traversal.This issue affects WooCommerce Support Ticket System: from n/a through < 18.5. | |
| Aplazada | Alta (7.5) | 0.37% | — | Wpfactory Helpdesk Support Ticket System FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.2. | |
| Aplazada | Media (6.5) | 0.26% | — | Elextensions Elex Wordpress Helpdesk Customer Support Ticket SystemAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ELEX WordPress HelpDesk & Customer Ticketing System: from n/a through <= 3.3.5. | |
| Aplazada | Alta (8.2) | 0.28% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.8. | |
| Aplazada | Media (5.3) | 0.22% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 23/12/2025 | 17/6/2026 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.9. | |
| Aplazada | Crítica (10) | 0.45% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 6/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code Inclusion.This issue affects HAPPY: from n/a through <= 1.0.7. | |
| Aplazada | Crítica (10) | 0.43% | — | Plugify Support Ticket System FOR WoocommerceAI | 6/11/2025 | 30/9/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Plugify Support Ticket System for WooCommerce (Premium) support-ticket-system-for-woocommerce allows Using Malicious Files.This issue affects Support Ticket System for WooCommerce (Premium): from n/a through <= 2.0.7. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpfactory Helpdesk Support Ticket System FOR WoocommerceAI | 22/9/2025 | 1/10/2026 | Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.1. | |
| Aplazada | Media (6.5) | 0.23% | — | Villatheme Happy Helpdesk Support Ticket SystemAI | 5/9/2025 | 17/6/2026 | Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.6. | |
| Aplazada | Alta (7.1) | 0.24% | — | Themepassion Support TicketAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Support Ticket support-ticket allows Reflected XSS.This issue affects Support Ticket: from n/a through <= 1.9. | |
| Aplazada | Crítica (9.8) | 0.45% | — | Themepassion Support TicketAI | 20/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in themepassion Support Ticket support-ticket allows Privilege Escalation.This issue affects Support Ticket: from n/a through <= 1.9. | |
| Aplazada | Media (6.5) | 0.33% | — | Solaplugins Sola Support TicketAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in SolaPlugins Sola Support Ticket allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sola Support Ticket: from n/a through 3.17. | |
| Analizada | Media (5.4) | 0.24% | — | Vanquish Woocommerce Support Ticket System | 1/2/2025 | 17/6/2026 | The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on the 'ajax_delete_message', 'ajax_get_customers_partial_list', and 'ajax_get_admins_list' functions in all versions up to, and including, 17.8. This makes it possible for… | |
| Aplazada | Alta (8.5) | 0.49% | — | Ydesignservices YDS Support Ticket SystemAI | 18/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ydesignservices YDS Support Ticket System yds-support-ticket-system allows SQL Injection.This issue affects YDS Support Ticket System: from n/a through <= 1.0. | |
| Analizada | Crítica (9.8) | 0.85% | — | Vanquish Woocommerce Support Ticket System | 9/11/2024 | 17/6/2026 | The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_manage_file_chunk_upload() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Analizada | Alta (8.1) | 0.93% | — | Vanquish Woocommerce Support Ticket System | 9/11/2024 | 17/6/2026 | The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Analizada | Crítica (9.1) | 1.0% | — | Vanquish Woocommerce Support Ticket System | 9/11/2024 | 17/6/2026 | The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the… | |
| Aplazada | Alta (7.5) | 0.45% | — | Videowhisper Contact FormsAIVideowhisper Live SupportAIVideowhisper CRMAIVideowhisper Video MessagesAI+1 | 17/10/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in videowhisper Contact Forms, Live Support, CRM, Video Messages live-support-tickets allows Retrieve Embedded Sensitive Data.This issue affects Contact Forms, Live Support, CRM, Video Messages: from n/a through <= 1.10.2. | |
| Modificada | Alta (8.8) | 0.39% | — | Ydesignservices YDS Support Ticket System | 23/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in YDS Support Ticket System plugin <= 1.0 at WordPress. | |
| Modificada | Media (4.8) | 0.64% | — | Emarketdesign Customer Service Software & Support Ticket System | 18/10/2021 | 17/6/2026 | The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fields before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. |