Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3055▲ 476 respecto a la semana anterior
Críticas / altas1430▲ 205 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
–

254 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.2)0.39%—MakecommerceAI30/9/202630/9/2026
Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.
AplazadaAlta (7.2)0.54%—Implecode Ecommerce Product CatalogAI30/9/202630/9/2026
Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.
Pendiente de análisisMedia (6.9)0.39%—Marcos Camara01 Ecommerce TemplateAI28/9/202629/9/2026
Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The…
AplazadaAlta (7)0.25%—Isotope EcommerceAIContaoAI23/9/202624/9/2026
Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate request-controlled identifiers and administrator-supplied values directly into SQL statements. Authenticated Contao backend users with Isotope module permissions can exploit conditional and time-based…
AplazadaAlta (8.2)0.38%—Isotope EcommerceAI23/9/202624/9/2026
Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, allowing unauthenticated attackers to guess identifiers. Guest orders lack ownership verification, enabling attackers to access order details including billing address, customer information, and…
AplazadaMedia (4.3)0.60%—Datalogics Ecommerce DeliveryAI19/9/202621/9/2026
The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.23%—Ibtana Ecommerce Product AddonsAI19/9/202621/9/2026
The Ibtana – Ecommerce Product Addons plugin for WordPress is vulnerable to unauthorized post meta modification due to a missing capability check on the 'iepa_use_gt_editor' AJAX action in all versions up to, and including, 0.4.7.7. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaMedia (4.9)0.27%—Shoppingcart Shopping Cart Ecommerce StoreAI1/9/20261/9/2026
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
AplazadaMedia (6.4)0.36%—Implecode Ecommerce Product CatalogAI25/8/202628/9/2026
The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaMedia (5.3)0.16%—Welcart EcommerceAI12/8/202626/8/2026
The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback: an unauthenticated request can flip an order from unpaid to settled purely from an order number and a status flag, with no signature, amount, or origin check. Because…
AplazadaCrítica (9.3)0.50%—ReadyecommerceAI10/8/20269/9/2026
ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the products endpoint is concatenated directly into a MySQL HAVING clause without parameterization in ProductController.php. Attackers can perform time-based blind SQL…
AplazadaMedia (5.1)0.24%—ReadyecommerceAI10/8/20269/9/2026
ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated customers to inject malicious HTML payloads through the chat and support ticket messaging systems by exploiting unsanitized rendering via the v-html directive in Messages.vue, RightChatSidebar.vue,…
AplazadaMedia (6.1)0.25%—Ecommerce Fruits BazarAI30/7/20261/10/2026
Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.
AplazadaCrítica (9.8)0.47%—Ecommerce-project-with-php-and-mysqli-fruits-bazarAI30/7/20261/10/2026
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.
AplazadaMedia (5.1)0.38%—Sourcecodester Pizzafy Ecommerce SystemAI19/7/202620/7/2026
A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely.
AplazadaMedia (6.5)0.22%—Quantumcloud Chatbot FOR Ecommerce WoowbotAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot for eCommerce &#8211; WoowBot woowbot-woocommerce-chatbot allows Stored XSS.This issue affects ChatBot for eCommerce &#8211; WoowBot: from n/a through <= 4.6.1.
AnalizadaCrítica (9.8)0.56%—Alternativecommerce10/7/20266/8/2026
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17.
AplazadaMedia (4.3)0.34%—DHL Ecommerce Benelux FOR WoocommerceAI9/7/20269/7/2026
The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing nonce verification on the create_label() and delete_label() functions in versions up to, and including, 2.2.3. These functions are wired to the…
AplazadaBaja (2.1)0.23%—Imhamzaazam EcommerceflaskAI6/7/20266/7/2026
A weakness has been identified in imhamzaazam ecommerceFlask up to cb7d9e24c30a99379651b7493b32048126ef402b. The affected element is an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for…
AplazadaBaja (2.1)0.33%—Codeastro Ecommerce WebsiteAI6/7/20266/7/2026
A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. Impacted is an unknown function of the file /customer/my_account.php?my_wishlist. The manipulation of the argument delete_wishlist results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may…
AplazadaBaja (2.1)0.33%—Codeastro Ecommerce WebsiteAI5/7/20266/7/2026
A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. The manipulation of the argument invoice_no results in sql injection. The attack can be executed remotely. The exploit…
AplazadaBaja (2.1)0.33%—Codeastro Ecommerce WebsiteAI4/7/20267/7/2026
A vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public…
AplazadaAlta (7.8)0.83%—Kirilkirkov Ecommerce-codeigniter-bootstrapAI4/7/20266/7/2026
A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7. The affected element is the function getCartItems in the library application/libraries/ShoppingCart.php. The manipulation of the argument shopping_cart leads to deserialization. The…
AplazadaMedia (5.3)0.48%—Kirilkirkov Ecommerce-codeigniter-bootstrapAI4/7/20266/7/2026
A weakness has been identified in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 23105f25dadf57b4314fc015a63a7c6e910c89df. Impacted is the function do_upload_others_images of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Image Manager. Executing a manipulation of the…
AplazadaMedia (5.5)0.62%—Kirilkirkov Ecommerce Codeigniter BootstrapAI4/7/20266/7/2026
A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. This issue affects some unknown processing of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Multi-Image Endpoint. Performing a manipulation of the…