Welcart
Welcart E-commerce: vulnerabilidades y CVE
Welcart E-commerce tiene 41 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE41
Últimos 12 meses2
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-27539 | Alta (7.1) | 0.25% | — | 13 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions. |
| CVE-2026-16065 | Media (6.5) | 0.40% | — | 6 ago 2026 | The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL statement, allowing users with the Editor role and above (including its… |
| CVE-2025-58984 | Media (5.9) | 0.18% | — | 9 sept 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Stored XSS.This issue affects Welcart e-Commerce: from n/a through… |
| CVE-2025-54012 | Alta (7.2) | 0.48% | — | 20 ago 2025 | Deserialization of Untrusted Data vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Object Injection.This issue affects Welcart e-Commerce: from n/a through <= 2.11.16. |
| CVE-2025-54013 | Media (5.9) | 0.19% | — | 16 jul 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Stored XSS.This issue affects Welcart e-Commerce: from n/a through… |
| CVE-2025-47511 | Media (6.5) | 0.54% | — | 9 jun 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Path Traversal.This issue affects Welcart e-Commerce: from n/a through <=… |
| CVE-2025-27130 | Alta (8.8) | 0.46% | — | 1 abr 2025 | Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker who can… |
| CVE-2025-0511 | Media (6.1) | 0.36% | — | 12 feb 2025 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 2.11.9 due to insufficient input sanitization and output escaping.… |
| CVE-2024-45366 | Media (6.1) | 0.26% | — | 18 sept 2024 | Welcart e-Commerce prior to 2.11.2 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser. |
| CVE-2024-42404 | Alta (8.8) | 0.48% | — | 18 sept 2024 | SQL injection vulnerability in Welcart e-Commerce prior to 2.11.2 allows an attacker who can login to the product to obtain or alter the information stored in the database. |
| CVE-2024-32144 | Media (4.3) | 0.34% | — | 11 jun 2024 | Missing Authorization vulnerability in Welcart Inc. Welcart e-Commerce.This issue affects Welcart e-Commerce: from n/a through 2.9.14. |
| CVE-2023-50847 | Alta (7.2) | 0.53% | — | 28 dic 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Collne Inc. Welcart e-Commerce.This issue affects Welcart e-Commerce: from n/a through 2.9.3. |
| CVE-2023-6120 | Baja (2.7) | 0.46% | — | 9 dic 2023 | The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.6 via the upload_certificate_file function. This makes it possible for administrators to upload… |
| CVE-2023-5953 | Alta (8.8) | 0.48% | — | 4 dic 2023 | The Welcart e-Commerce WordPress plugin before 2.9.5 does not validate files to be uploaded, as well as does not have authorisation and CSRF in an AJAX action handling such upload. As a result, any authenticated users,… |
| CVE-2023-5952 | Crítica (9.8) | 1.3% | — | 4 dic 2023 | The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog |
| CVE-2023-5951 | Media (6.1) | 0.47% | — | 4 dic 2023 | The Welcart e-Commerce WordPress plugin before 2.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege… |
| CVE-2023-43614 | Media (6.1) | 0.80% | — | 27 sept 2023 | Cross-site scripting vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script. |
| CVE-2023-43610 | Alta (8.8) | 1.2% | — | 27 sept 2023 | SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations. |
| CVE-2023-43493 | Media (4.9) | 0.98% | — | 27 sept 2023 | SQL injection vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with author or higher privilege to obtain sensitive information. |
| CVE-2023-43484 | Media (6.1) | 0.80% | — | 27 sept 2023 | Cross-site scripting vulnerability in Item List page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script. |
| CVE-2023-41962 | Media (6.1) | 0.73% | — | 27 sept 2023 | Cross-site scripting vulnerability in Credit Card Payment Setup page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script in the page. |
| CVE-2023-41233 | Media (6.1) | 0.73% | — | 27 sept 2023 | Cross-site scripting vulnerability in Item List page registration process of Welcart e-Commerce versions 2.7 to 2.8.21 allows a remote unauthenticated attacker to inject an arbitrary script. |
| CVE-2023-40219 | Alta (7.2) | 1.2% | — | 27 sept 2023 | Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor or higher privilege to upload an arbitrary file to an unauthorized directory. |
| CVE-2021-4375 | Media (4.3) | 0.60% | — | 7 jun 2023 | The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the usces_download_system_information() function in versions up to, and including, 2.2.7. This makes… |
| CVE-2021-4355 | Media (5.3) | 0.81% | — | 7 jun 2023 | The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the download_orderdetail_list(), change_orderlist(), and download_member_list() functions called via… |
| CVE-2023-22705 | Media (6.1) | 0.43% | — | 29 mar 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Collne Inc. Welcart e-Commerce plugin <= 2.8.10 versions. |
| CVE-2022-4655 | Media (5.4) | 0.47% | — | 16 ene 2023 | The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting… |
| CVE-2022-4237 | Alta (8.8) | 1.1% | — | 2 ene 2023 | The Welcart e-Commerce WordPress plugin before 2.8.6 does not validate user input before using it in file_exist() functions via various AJAX actions available to any authenticated users, which could allow users with a… |
| CVE-2022-4236 | Media (6.5) | 0.80% | — | 2 ene 2023 | The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file via an AJAX action available to any authenticated users, which could allow users with a… |
| CVE-2022-4140 | Alta (7.5) | 2.9% | — | 2 ene 2023 | The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.