Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
521 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.19% | — | Webkul QloappsAI | 30/9/2026 | 1/10/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing… | |
| Aplazada | Media (5.1) | 0.19% | — | Webkul QloappsAI | 30/9/2026 | 1/10/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute… | |
| Aplazada | Media (5.1) | 0.18% | — | Webkul QloappsAI | 30/9/2026 | 30/9/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim… | |
| Aplazada | Media (5.1) | 0.18% | — | Webkul QloappsAI | 30/9/2026 | 1/10/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these… | |
| Aplazada | Baja (2.3) | 0.11% | — | Webkul UnopimAI | 29/9/2026 | 2/10/2026 | UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers can set X-Forwarded-Host to redirect JavaScript asset loading to their server, and… | |
| Aplazada | Baja (2) | 0.32% | — | Webkul BagistoAI | 28/9/2026 | 29/9/2026 | A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now… | |
| Aplazada | Media (5.1) | 0.14% | — | Webkul Krayin CRMAI | 24/9/2026 | 25/9/2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the web form description field. Attackers can craft a web form description containing… | |
| Aplazada | Media (5.1) | 0.14% | — | Webkul Krayin CRMAI | 24/9/2026 | 29/9/2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the product name field. Attackers can craft a product name containing double-brace template… | |
| Aplazada | Media (5.1) | 0.14% | — | Webkul Krayin CRMAI | 24/9/2026 | 30/9/2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person name field. Attackers can craft a person name containing double-brace template… | |
| Aplazada | Media (5.1) | 0.17% | — | Webkul Krayin CRMAI | 24/9/2026 | 24/9/2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead title field. Attackers can craft a lead title containing double-brace template… | |
| Aplazada | Alta (8.8) | 0.45% | — | Webkul BagistoAI | 15/9/2026 | 22/9/2026 | Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoint (route admin.settings.users.update, UserController::update()) does not verify… | |
| Aplazada | Alta (8.1) | 0.39% | — | Webkul BagistoAI | 15/9/2026 | 22/9/2026 | Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods. | |
| Aplazada | Media (6.5) | 0.46% | — | Webkul BagistoAI | 15/9/2026 | 22/9/2026 | An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components. | |
| Aplazada | Alta (8.8) | 0.66% | — | Webkul Krayin CRMAI | 14/9/2026 | 24/9/2026 | Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body,… | |
| Aplazada | Alta (7.1) | 0.42% | — | Webkul UnopimAI | 3/9/2026 | 23/9/2026 | UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, mint client credentials, and escalate permissions by exploiting missing authorization… | |
| Aplazada | Alta (8.6) | 0.63% | — | TinymceAIWebkul UnopimAI | 2/9/2026 | 28/9/2026 | UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due to missing file extension and MIME type validation. Attackers can upload a PHP web shell to the public storage disk and execute… | |
| Pendiente de análisis | Alta (8.8) | 0.29% | — | WebkitgtkAI | 31/8/2026 | 30/9/2026 | A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling. | |
| Pendiente de análisis | Alta (8.6) | 0.81% | — | Webkul QloapsAI | 25/8/2026 | 26/8/2026 | Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'Address.php' file. Fixed in 123c97c. | |
| Pendiente de análisis | Alta (8.6) | 0.81% | — | Webkul QloappsAI | 25/8/2026 | 26/8/2026 | Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'CustomerMessage.php' file. Fixed in 123c97c. | |
| Pendiente de análisis | Alta (8.6) | 0.98% | — | Webkul QloappsAI | 25/8/2026 | 26/8/2026 | Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c. | |
| Pendiente de análisis | Alta (8.8) | 0.29% | — | WebkitgtkAI | 24/8/2026 | 30/9/2026 | A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption. | |
| Aplazada | Baja (2.1) | 0.45% | — | Webkul BagistoAI | 18/8/2026 | 20/8/2026 | A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes basic cross site scripting. It is possible to initiate the attack… | |
| Aplazada | Baja (2.1) | 0.37% | — | Webkul BagistoAI | 18/8/2026 | 20/8/2026 | A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow. The attack may be performed from remote. The exploit is now public… | |
| Aplazada | Baja (2) | 0.43% | — | Webkul BagistoAI | 17/8/2026 | 20/8/2026 | A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.38% | — | Webkul BagistoAI | 17/8/2026 | 20/8/2026 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack can be executed remotely. The exploit is… |