Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3037▲ 563 respecto a la semana anterior
Críticas / altas1444▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.75%—WhmcsAI14/9/202618/9/2026
Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute arbitrary code.
AplazadaCrítica (9.1)0.14%—Paytr Virtual POS Iframe APIAIWhmcsAI9/9/20261/10/2026
Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API WHMCS Module: from v9.0.0 before v9.0.3.
AplazadaAlta (7.5)0.30%—Paytr Virtual POS Iframe APIAIPaytr Whmcs ModuleAI8/9/20261/10/2026
Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API WHMCS Module allows Black Box Reverse Engineering. This issue affects PayTR Virtual Pos iFrame API WHMCS Module: from v9.0.0 before v9.0.3.
AplazadaAlta (7.5)0.32%—Paytr Virtual POS Iframe APIAIWhmcsAI8/9/20261/10/2026
Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API WHMCS Module allows Input Data Manipulation. This issue affects PayTR Virtual Pos iFrame API WHMCS Module: from v9.0.0 before v9.0.3.
AplazadaAlta (8.2)0.47%—WhmcsAI2checkoutAI4/9/202614/9/2026
Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific…
AplazadaAlta (8.8)1.0%—I-plugins Whmcs BridgeAI8/7/20268/7/2026
The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all versions up to, and including, 6.9. This makes it possible for authenticated attackers, with Custom-level access and above, to upload arbitrary files on the affected site's…
AplazadaBaja (2.1)0.47%—Lagom Whmcs TemplateAI20/4/202617/6/2026
A vulnerability has been found in Lagom WHMCS Template up to 2.4.2. This impacts an unknown function of the component Datatables. The manipulation leads to resource consumption. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early…
AplazadaBaja (2)0.36%—Lagom Whmcs TemplateAI16/3/202617/6/2026
A vulnerability was found in Lagom WHMCS Template up to 2.3.7. Impacted is an unknown function of the component Datatables. The manipulation results in improperly controlled modification of object prototype attributes. It is possible to launch the attack remotely. The exploit has been made public and could be used.…
AplazadaMedia (5.9)0.21%—Voidcoders Void-visual-whmcs-elementAIWpbakery Visual ComposerAI24/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBakery Visual Composer WHMCS Elements void-visual-whmcs-element allows DOM-Based XSS.This issue affects WPBakery Visual Composer WHMCS Elements: from n/a through <= 1.0.4.3.
AplazadaMedia (6.5)0.16%—Voidthemes Void Elementor Whmcs ElementsAI22/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidthemes Void Elementor WHMCS Elements For Elementor Page Builder void-elementor-whmcs-elements.This issue affects Void Elementor WHMCS Elements For Elementor Page Builder: from n/a through <= 2.0.1.2.
AplazadaMedia (6.5)0.21%—Voidcoders Void-visual-whmcs-elementAIWpbakery Visual ComposerAI7/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBakery Visual Composer WHMCS Elements void-visual-whmcs-element allows Stored XSS.This issue affects WPBakery Visual Composer WHMCS Elements: from n/a through <= 1.0.4.3.
AnalizadaAlta (8.8)0.41%—Whmpress Whmcs Client Area28/2/202517/6/2026
The WHMPress - WHMCS Client Area plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the update_settings case in the /admin/ajax.php file in all versions up to, and including, 4.3-revision-3. This makes it possible for…
AnalizadaCrítica (9.8)3.3%—Whmpress Whmcs28/2/202517/6/2026
The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.3-revision-0 via the whmpress_domain_search_ajax_extended_results() function. This makes it possible for unauthenticated attackers to include and execute arbitrary files…
ModificadaMedia (5.4)0.51%—Voidcoders Wpbakery Visual Composer Whmcs Elements21/11/202417/6/2026
The WPBakery Visual Composer WHMCS Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's void_wbwhmcse_laouts_search shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
AplazadaMedia (5.4)0.35%—Virtuozzo Hybrid Server FOR Whmcs Open SourceAI14/11/202417/6/2026
Cross Site Scripting vulnerability in Virtuozzo Hybrid Server for WHMCS Open Source v.1.7.1 allows a remote attacker to obtain sensitive information via modification of the hostname parameter.
AplazadaMedia (6.5)0.32%—Voidcoders Void Elementor Whmcs Elements FOR Elementor Page BuilderAI18/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VoidCoders, innovs Void Elementor WHMCS Elements For Elementor Page Builder allows Stored XSS.This issue affects Void Elementor WHMCS Elements For Elementor Page Builder: from n/a through 2.0.
ModificadaMedia (6.1)0.99%—Microweber Whmcs4/3/202217/6/2026
Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.
ModificadaMedia (6.1)2.2%—I-plugins Whmcs Bridge28/2/202217/6/2026
The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back in admin dashboard, leading to a Reflected Cross-Site Scripting
ModificadaMedia (5.4)0.56%—I-plugins Whmcs Bridge18/1/202217/6/2026
The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter found in the ~/whmcs-bridge/bridge_cp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1. Due to missing authorization checks on the…
ModificadaCrítica (9.8)4.0%—Whmcssmarters WEB TV Player5/3/202017/6/2026
IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script.
ModificadaCrítica (9.9)1.3%—Softaculous Whmcs Reseller Module11/3/201717/6/2026
The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which allows remote authenticated users to control other virtual machines managed by Virtualizor by accessing a modified URL.
ModificadaAlta (7.5)2.2%—Whmcs Group PAY13/5/201316/6/2026
SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and earlier for WHMCS allows remote attackers to execute arbitrary SQL commands via the hash parameter.
ModificadaMedia (5)0.94%—Whmcs Whmcompletesolution14/1/201216/6/2026
submitticket.php in WHMCompleteSolution (WHMCS) 5.03 allows remote attackers to inject arbitrary code into a subject field via crafted ticket data, a different vulnerability than CVE-2011-5061. NOTE: the vendor disputes this issue, noting that some of the details overlap CVE-2011-5061, but that it "says it affects…
ModificadaAlta (7.5)2.2%—Whmcs Whmcompletesolution14/1/201216/6/2026
functions.php in WHMCompleteSolution (WHMCS) 4.0.x through 5.0.x allows remote attackers to trigger arbitrary code execution in the Smarty templating system by submitting a crafted ticket, related to improper handling of characters in the subject field.
ModificadaMedia (5)2.9%—Whmcs Whmcompletesolution14/12/201116/6/2026
Directory traversal vulnerability in clientarea.php in WHMCompleteSolution (WHMCS) 3.x.x allows remote attackers to read arbitrary files via an invalid action and a ../ (dot dot slash) in the templatefile parameter.