Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.31% | — | WelcartAI | 3/10/2026 | 6/10/2026 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Settlement Notification Parameters in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Alta (8.8) | 0.57% | — | WelcartAI | 5/9/2026 | 8/9/2026 | The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenticated attackers can store arbitrary 'reserve' key/value pairs as order… | |
| Aplazada | Alta (7.2) | 0.34% | — | WelcartAI | 1/9/2026 | 1/9/2026 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' parameter in all versions up to, and including, 2.12.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (5.4) | 0.30% | — | WelcartAI | 21/8/2026 | 29/9/2026 | The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier from a user-supplied request parameter, allowing an unauthenticated attacker to fixate a shop member's session and take over their customer account after the victim logs in… | |
| Aplazada | Media (6.5) | 0.41% | — | Image Uploader FOR WelcartAI | 15/8/2026 | 20/8/2026 | The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.25% | — | Welcart E-commerceAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions. | |
| Aplazada | Media (5.3) | 0.16% | — | Welcart EcommerceAI | 12/8/2026 | 26/8/2026 | The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from unpaid to settled purely from an order number and a status flag, with no signature, amount, or origin check. Because… | |
| Aplazada | Media (5.4) | 0.23% | — | Welcart E CommerceAI | 12/8/2026 | 26/8/2026 | The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it on the product pages, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of any visitor viewing the product page. | |
| Aplazada | Media (6.5) | 0.40% | — | Welcart E-commerceAI | 6/8/2026 | 26/8/2026 | The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its custom shop-management roles) to perform SQL injection attacks. | |
| Aplazada | Media (6.5) | 0.33% | — | WelcartAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions. | |
| Aplazada | Media (4.3) | 0.18% | 💥 PoC | Friendly Functions FOR WelcartAI | 24/1/2026 | 17/6/2026 | The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce validation on the settings page. This makes it possible for unauthenticated attackers to update plugin settings via a forged request… | |
| Aplazada | Media (5.3) | 0.24% | — | Welcart E CommerceAI | 13/11/2025 | 17/6/2026 | The Welcart e-Commerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'usces_export' action in all versions up to, and including, 2.11.24. This makes it possible for unauthenticated attackers to access configured payment credentials (ex. PayPal api secret) ,… | |
| Aplazada | Media (4.3) | 0.24% | — | Welcart Usc-e-shopAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Welcart e-Commerce: from n/a through <= 2.11.24. | |
| Aplazada | Media (5.5) | 0.25% | — | WelcartAI | 22/10/2025 | 17/6/2026 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'order_mail' setting in versions up to, and including, 2.11.22. This is due to insufficient sanitization on the order_mail field and a lack of escaping on output. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.28% | — | WelcartAI | 8/10/2025 | 17/6/2026 | The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all versions up to, and including, 2.11.21 due to insufficient escaping on the user supplied value and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.5) | 0.25% | — | WelcartAI | 10/9/2025 | 17/6/2026 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 2.11.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject… | |
| Aplazada | Media (5.9) | 0.18% | — | Welcart E-commerceAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Stored XSS.This issue affects Welcart e-Commerce: from n/a through <= 2.11.20. | |
| Aplazada | Alta (7.2) | 0.48% | — | Welcart E-commerceAI | 20/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Object Injection.This issue affects Welcart e-Commerce: from n/a through <= 2.11.16. | |
| Aplazada | Media (5.9) | 0.19% | — | Welcart E-commerceAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Stored XSS.This issue affects Welcart e-Commerce: from n/a through <= 2.11.16. | |
| Modificada | Media (6.5) | 0.54% | — | Welcart E-commerce | 9/6/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Path Traversal.This issue affects Welcart e-Commerce: from n/a through <= 2.11.13. | |
| Analizada | Alta (8.8) | 0.46% | — | Welcart E-commerce | 1/4/2025 | 17/6/2026 | Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker who can access websites created using the product. | |
| Analizada | Media (6.1) | 0.36% | — | Welcart E-commerce | 12/2/2025 | 17/6/2026 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 2.11.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.1) | 0.28% | — | Friendly Functions FOR WelcartAI | 21/11/2024 | 17/6/2026 | The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to inject malicious web scripts via a… | |
| Analizada | Media (6.1) | 0.26% | — | Welcart E-commerce | 18/9/2024 | 17/6/2026 | Welcart e-Commerce prior to 2.11.2 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser. | |
| Analizada | Alta (8.8) | 0.48% | — | Welcart E-commerce | 18/9/2024 | 17/6/2026 | SQL injection vulnerability in Welcart e-Commerce prior to 2.11.2 allows an attacker who can login to the product to obtain or alter the information stored in the database. |