Implecode
Implecode Ecommerce Product Catalog: vulnerabilidades y CVE
Implecode Ecommerce Product Catalog tiene 16 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-96344 | Alta (7.2) | 0.54% | — | 30 sept 2026 | Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. |
| CVE-2026-76128 | Media (6.4) | 0.36% | — | 25 ago 2026 | The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 due to insufficient input sanitization and… |
| CVE-2026-57360 | Alta (7.1) | 0.25% | — | 2 jul 2026 | Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions. |
| CVE-2026-52693 | Crítica (9.3) | 0.40% | — | 15 jun 2026 | Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. |
| CVE-2025-49331 | Alta (7.2) | 0.52% | — | 17 jun 2025 | Deserialization of Untrusted Data vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Object Injection.This issue affects eCommerce Product Catalog: from n/a through <= 3.4.3. |
| CVE-2024-12771 | Alta (8.8) | 0.27% | — | 21 dic 2024 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.43. This is due to missing or incorrect nonce validation on… |
| CVE-2024-32558 | Alta (7.1) | 0.37% | — | 18 abr 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog allows Reflected XSS.This issue affects eCommerce Product Catalog: from n/a… |
| CVE-2024-32437 | Media (4.3) | 0.21% | — | 15 abr 2024 | Cross-Site Request Forgery (CSRF) vulnerability in impleCode eCommerce Product Catalog.This issue affects eCommerce Product Catalog: from n/a through 3.3.28. |
| CVE-2023-51688 | Alta (7.5) | 0.48% | — | 29 dic 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress.This issue affects eCommerce Product Catalog Plugin for WordPress: from n/a through… |
| CVE-2023-5979 | Media (6.5) | 0.28% | — | 4 dic 2023 | The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin pages, which could allow attackers to make logged-in users perform unwanted actions via CSRF… |
| CVE-2023-47839 | Media (5.4) | 0.41% | — | 23 nov 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress plugin <= 3.3.26 versions. |
| CVE-2021-4393 | Media (4.3) | 0.48% | — | 1 jul 2023 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.17. This is due to missing or incorrect nonce validation on the… |
| CVE-2021-4392 | Media (4.3) | 0.48% | — | 1 jul 2023 | The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.43. This is due to missing or incorrect nonce validation on the… |
| CVE-2023-25049 | Media (4.8) | 0.39% | — | 7 abr 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in impleCode eCommerce Product Catalog Plugin for WordPress plugin <= 3.3.4 versions. |
| CVE-2023-1470 | Media (4.8) | 0.38% | — | 17 mar 2023 | The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 3.3.8 due to insufficient input sanitization and… |
| CVE-2021-24875 | Media (6.1) | 1.7% | — | 23 nov 2021 | The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.