Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3055▲ 476 respecto a la semana anterior
Críticas / altas1430▲ 205 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
254 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.39% | — | MakecommerceAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | Implecode Ecommerce Product CatalogAI | 30/9/2026 | 30/9/2026 | Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions. | |
| Pendiente de análisis | Media (6.9) | 0.39% | — | Marcos Camara01 Ecommerce TemplateAI | 28/9/2026 | 29/9/2026 | Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The… | |
| Aplazada | Alta (7) | 0.25% | — | Isotope EcommerceAIContaoAI | 23/9/2026 | 24/9/2026 | Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administrator-supplied values directly into SQL statements. Authenticated Contao backend users with Isotope module permissions can exploit conditional and time-based… | |
| Aplazada | Alta (8.2) | 0.38% | — | Isotope EcommerceAI | 23/9/2026 | 24/9/2026 | Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, allowing unauthenticated attackers to guess identifiers. Guest orders lack ownership verification, enabling attackers to access order details including billing address, customer information, and… | |
| Aplazada | Media (4.3) | 0.60% | — | Datalogics Ecommerce DeliveryAI | 19/9/2026 | 21/9/2026 | The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.23% | — | Ibtana Ecommerce Product AddonsAI | 19/9/2026 | 21/9/2026 | The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (4.9) | 0.27% | — | Shoppingcart Shopping Cart Ecommerce StoreAI | 1/9/2026 | 1/9/2026 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Media (6.4) | 0.36% | — | Implecode Ecommerce Product CatalogAI | 25/8/2026 | 28/9/2026 | The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (5.3) | 0.16% | — | Welcart EcommerceAI | 12/8/2026 | 26/8/2026 | The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from unpaid to settled purely from an order number and a status flag, with no signature, amount, or origin check. Because… | |
| Aplazada | Crítica (9.3) | 0.50% | — | ReadyecommerceAI | 10/8/2026 | 9/9/2026 | ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in ProductController.php. Attackers can perform time-based blind SQL… | |
| Aplazada | Media (5.1) | 0.24% | — | ReadyecommerceAI | 10/8/2026 | 9/9/2026 | ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated customers to inject malicious HTML payloads through the chat and support ticket messaging systems by exploiting unsanitized rendering via the v-html directive in Messages.vue, RightChatSidebar.vue,… | |
| Aplazada | Media (6.1) | 0.25% | — | Ecommerce Fruits BazarAI | 30/7/2026 | 1/10/2026 | Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Ecommerce-project-with-php-and-mysqli-fruits-bazarAI | 30/7/2026 | 1/10/2026 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. | |
| Aplazada | Media (5.1) | 0.38% | — | Sourcecodester Pizzafy Ecommerce SystemAI | 19/7/2026 | 20/7/2026 | A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely. | |
| Aplazada | Media (6.5) | 0.22% | — | Quantumcloud Chatbot FOR Ecommerce WoowbotAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot for eCommerce – WoowBot woowbot-woocommerce-chatbot allows Stored XSS.This issue affects ChatBot for eCommerce – WoowBot: from n/a through <= 4.6.1. | |
| Analizada | Crítica (9.8) | 0.56% | — | Alternativecommerce | 10/7/2026 | 6/8/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17. | |
| Aplazada | Media (4.3) | 0.34% | — | DHL Ecommerce Benelux FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing nonce verification on the create_label() and delete_label() functions in versions up to, and including, 2.2.3. These functions are wired to the… | |
| Aplazada | Baja (2.1) | 0.23% | — | Imhamzaazam EcommerceflaskAI | 6/7/2026 | 6/7/2026 | A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affected element is an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Ecommerce WebsiteAI | 6/7/2026 | 6/7/2026 | A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishlist. The manipulation of the argument delete_wishlist results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Ecommerce WebsiteAI | 5/7/2026 | 6/7/2026 | A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. The manipulation of the argument invoice_no results in sql injection. The attack can be executed remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.33% | — | Codeastro Ecommerce WebsiteAI | 4/7/2026 | 7/7/2026 | A vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Aplazada | Alta (7.8) | 0.83% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 6/7/2026 | A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affected element is the function getCartItems in the library application/libraries/ShoppingCart.php. The manipulation of the argument shopping_cart leads to deserialization. The… | |
| Aplazada | Media (5.3) | 0.48% | — | Kirilkirkov Ecommerce-codeigniter-bootstrapAI | 4/7/2026 | 6/7/2026 | A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. Impacted is the function do_upload_others_images of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Image Manager. Executing a manipulation of the… | |
| Aplazada | Media (5.5) | 0.62% | — | Kirilkirkov Ecommerce Codeigniter BootstrapAI | 4/7/2026 | 6/7/2026 | A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. This issue affects some unknown processing of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Multi-Image Endpoint. Performing a manipulation of the… |