Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

22 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.41%—Infor Storefront B2BAI30/1/202617/6/2026
Infor Storefront B2B 1.0 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'usr_name' parameter in login requests. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'usr_name' parameter to potentially extract or modify database…
AplazadaAlta (7.1)0.13%—Dactum Clickbank Niche StorefrontsAI28/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in dactum Clickbank WordPress Plugin (Niche Storefront) clickbank-niche-storefronts allows Stored XSS.This issue affects Clickbank WordPress Plugin (Niche Storefront): from n/a through <= 1.3.5.
AnalizadaMedia (4.3)0.29%—Vwthemes VW Storefront4/3/202517/6/2026
The VW Storefront theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vw_storefront_reset_all_settings() function in all versions up to, and including, 0.9.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset…
AnalizadaCrítica (9)0.62%—Selldone Storefront3/3/202517/6/2026
Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component
AplazadaAlta (7.1)0.37%—Dactum Clickbank StorefrontAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dactum ClickBank Storefront mycbgenie-clickbank-storefront allows Reflected XSS.This issue affects ClickBank Storefront: from n/a through <= 1.7.
AplazadaMedia (6.1)0.15%—Clickbank StorefrontAI6/12/202417/6/2026
The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing or incorrect nonce validation via the cs_menu page. This makes it possible for unauthenticated attackers to update settings and inject malicious…
AnalizadaMedia (6.5)0.57%—Saleor React-storefront20/3/202417/6/2026
Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymous users are able to access their data. The session is leaked through cache and can be accessed by anyone. Users should upgrade to a version…
ModificadaMedia (6.1)73%—Cloud Citrix Storefront17/1/202417/6/2026
Cross-site scripting (XSS)
ModificadaMedia (6.1)0.46%—Saleor React-storefront16/6/202317/6/2026
Cross-site Scripting (XSS) - DOM in GitHub repository saleor/react-storefront prior to c29aab226f07ca980cc19787dcef101e11b83ef7.
ModificadaMedia (6.1)0.48%—Citrix Storefront Server13/4/202217/6/2026
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
ModificadaMedia (4.8)0.62%—Wooassist Storefront Footer Text8/11/202117/6/2026
The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed.
ModificadaMedia (6.5)1.3%—Citrix Storefront Server18/9/202017/6/2026
Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
ModificadaMedia (5.3)15%—Divante Storefront-apiDivante Vue-storefront-api17/4/202017/6/2026
In Divante vue-storefront-api through 1.11.1 and storefront-api through 1.0-rc.1, as used in VueStorefront PWA, unexpected HTTP requests lead to an exception that discloses the error stack trace, with absolute file paths and Node.js module names.
AnalizadaAlta (7.5)30%⚠ Explotación activaCitrix Storefront Server29/8/201917/6/2026
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
ModificadaAlta (7.5)1.1%—Lagarde Storefront17/3/200816/6/2026
SQL injection vulnerability in SearchResults.aspx in LaGarde StoreFront 6 before SP8 allows remote attackers to execute arbitrary SQL commands via the CategoryId parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.8)3.2%—Storefront FOR Gallery Storefront Gallery18/4/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter to (1) mods/business_functions.php or (2) mods/ui_functions.php.
ModificadaMedia (5)2.6%—Esmi Paypal Storefront2/5/200516/6/2026
Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaAlta (7.5)1.3%—Esmi Paypal Storefront2/5/200516/6/2026
Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages parameter to pages.php or the (2) id2 parameter to products1.php.
ModificadaMedia (4.3)1.5%—Aspdotnetstorefront31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.
ModificadaAlta (9)1.7%—Aspdotnetstorefront31/12/200416/6/2026
Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.
ModificadaMedia (4.3)2.2%—Aspdotnetstorefront31/12/200416/6/2026
deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.
ModificadaAlta (7.5)1.0%—Lagarde Storefront18/8/200316/6/2026
SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.