« Volver al listado

Shopfiles

Shopfiles Ebook Store: vulnerabilidades y CVE

Shopfiles Ebook Store tiene 16 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE16
Últimos 12 meses3
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-59529Alta (7.5)0.39%—27 jul 2026
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
CVE-2026-65453Media (5.3)0.29%—23 jul 2026
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
CVE-2026-65452Media (5.3)0.31%—23 jul 2026
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
CVE-2025-8113Media (6.1)0.22%—16 ago 2025
The Ebook Store WordPress plugin before 5.8015 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.
CVE-2025-54702Media (4.3)0.13%—14 ago 2025
Cross-Site Request Forgery (CSRF) vulnerability in motov.net Ebook Store ebook-store allows Cross Site Request Forgery.This issue affects Ebook Store: from n/a through <= 5.8013.
CVE-2025-7437Crítica (9.8)1.3%—24 jul 2025
The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions up to, and including, 5.8012. This makes it possible…
CVE-2025-7486Media (4.4)0.23%—21 jul 2025
The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Order Details in all versions up to, and including, 5.8012 due to insufficient input sanitization and output escaping. This makes…
CVE-2025-49862Media (5.9)0.20%—17 jun 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in motov.net Ebook Store ebook-store allows Stored XSS.This issue affects Ebook Store: from n/a through <= 5.8008.
CVE-2025-47589Media (6.5)0.25%—7 may 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in motov.net Ebook Store ebook-store allows DOM-Based XSS.This issue affects Ebook Store: from n/a through <= 5.8009.
CVE-2024-12262Media (6.1)0.45%—21 dic 2024
The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all versions up to, and including, 5.8001 due to insufficient input sanitization and output escaping. This…
CVE-2024-11287Media (6.1)0.36%—21 dic 2024
The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.8001. This makes it…
CVE-2023-22701Crítica (9.8)1.0%—9 dic 2024
Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ebook Store: from n/a through 5.775.
CVE-2024-6567Media (5.3)0.45%—2 ago 2024
The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001. This is due to the plugin utilizing fpdi-protection and not preventing direct access to test files…
CVE-2024-23501Media (4.8)0.34%—29 feb 2024
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shopfiles Ltd Ebook Store allows Stored XSS.This issue affects Ebook Store: from n/a through 5.788.
CVE-2023-45602Media (6.1)0.34%—18 oct 2023
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.785 versions.
CVE-2023-22690Media (4.8)0.37%—15 may 2023
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.775 versions.