Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Swatchly - Woocommerce Variation Swatches FOR ProductsAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. | |
| Aplazada | Media (5.3) | 0.20% | — | Pure WC Variation SwatchesAI | 20/12/2025 | 17/6/2026 | The Pure WC Variation Swatches WordPress plugin through 1.1.7 does not have an authorization check when updating its settings, which could allow any authenticated users to update them. | |
| Aplazada | Media (5.4) | 0.33% | — | Gsplugins GS Variation Swatches FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in GS Plugins GS Variation Swatches for WooCommerce gs-woo-variation-swatches allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GS Variation Swatches for WooCommerce: from n/a through <= 3.0.4. | |
| Analizada | Media (4.3) | 0.19% | — | Variation Swatches FOR Woocommerce Project Variation Swatches FOR Woocommerce | 23/1/2025 | 17/6/2026 | The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its settings reset functionality. The issue exists in the settings_init() function, which processes a reset action based on specific query parameters in the… | |
| Analizada | Media (5.4) | 0.20% | — | Themehunk Variation Swatches | 9/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeHunk TH Variation Swatches allows Cross Site Request Forgery.This issue affects TH Variation Swatches: from n/a through 1.2.7. | |
| Modificada | Media (6.1) | 0.38% | — | Variation Swatches FOR Woocommerce Project Variation Swatches FOR Woocommerce | 27/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RadiusTheme Variation Swatches for WooCommerce plugin <= 2.3.7 versions. | |
| Modificada | Media (5.4) | 0.53% | — | Variation Swatches FOR Woocommerce Project Variation Swatches FOR Woocommerce | 14/12/2021 | 17/6/2026 | The Variation Swatches for WooCommerce WordPress plugin is vulnerable to Stored Cross-Site Scripting via several parameters found in the ~/includes/class-menu-page.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.1.1. Due to missing authorization checks on the… | |
| Modificada | Media (6.1) | 1.0% | — | Getwooplugins Woo-variation-swatches | 8/8/2019 | 17/6/2026 | The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter. |