Zaytech
Zaytech Smart Online Order FOR Clover: vulnerabilidades y CVE
Zaytech Smart Online Order FOR Clover tiene 14 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses5
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-66700 | Alta (7.1) | 0.25% | — | 13 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions. |
| CVE-2026-42746 | Alta (7.3) | 0.32% | — | 27 may 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Retrieve Embedded Sensitive Data.This issue affects Smart Online Order for Clover:… |
| CVE-2026-42745 | Alta (7.3) | 0.40% | — | 27 may 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Authentication Bypass.This issue affects Smart Online Order for Clover: from… |
| CVE-2026-42738 | Alta (7.1) | 0.25% | — | 27 may 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Stored XSS.This issue affects Smart Online Order… |
| CVE-2025-15635 | Media (4.3) | 0.11% | — | 15 abr 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders allows Cross Site Request Forgery.This issue affects Smart Online Order for Clover: from n/a through <= 1.6.0. |
| CVE-2024-43254 | Alta (8.8) | 0.42% | — | 1 nov 2024 | Missing Authorization vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders.This issue affects Smart Online Order for Clover: from n/a through <= 1.5.6. |
| CVE-2024-43253 | Crítica (9.8) | 0.62% | — | 1 nov 2024 | Missing Authorization vulnerability in ZAYTECH Smart Online Order for Clover clover-online-orders.This issue affects Smart Online Order for Clover: from n/a through <= 1.5.6. |
| CVE-2024-8787 | Media (6.1) | 0.40% | — | 16 oct 2024 | The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to,… |
| CVE-2024-9895 | Media (5.4) | 0.36% | — | 15 oct 2024 | The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo_receipt_link shortcode in all versions up to, and including, 1.5.7 due to insufficient input… |
| CVE-2024-7032 | Media (6.5) | 0.48% | — | 21 ago 2024 | The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'moo_deactivateAndClean' function in all versions up to, and including, 1.5.6.… |
| CVE-2024-7030 | Media (4.3) | 0.35% | — | 21 ago 2024 | The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.5.6. This makes it… |
| CVE-2024-31238 | Alta (8.8) | 0.22% | — | 12 abr 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Zaytech Smart Online Order for Clover.This issue affects Smart Online Order for Clover: from n/a through 1.5.5. |
| CVE-2024-29115 | Media (5.4) | 0.34% | — | 19 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zaytech Smart Online Order for Clover allows Stored XSS.This issue affects Smart Online Order for Clover: from n/a… |
| CVE-2023-46312 | Media (6.1) | 0.33% | — | 31 oct 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zaytech Smart Online Order for Clover plugin <= 1.5.4 versions. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.