Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

105 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaSin puntuar——Saveto Wishlist LiteAI3/10/20263/10/2026
The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.
AplazadaAlta (7.1)0.18%—Premmerce WishlistAI1/10/20261/10/2026
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
AplazadaAlta (7.1)0.18%—Premmerce WishlistAI1/10/20261/10/2026
Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.
AplazadaAlta (7.6)0.38%—MC Woocommerce WishlistAI17/9/202617/9/2026
Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
AplazadaMedia (5.3)0.34%—Prestashop BlockwishlistAI16/9/202622/9/2026
PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers'…
AplazadaMedia (5.3)0.30%—Moreconvert Woocommerce WishlistAI11/9/202611/9/2026
The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.
AplazadaCrítica (9.8)0.53%—Wishlistmember Wishlist MemberAI14/8/202614/8/2026
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and…
AplazadaMedia (6.5)0.22%—Wishlistmember Wishlist Member XAI23/7/202623/7/2026
Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.
AplazadaAlta (7.1)0.25%—Mildainc MC Woocommerce WishlistAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.
AplazadaCrítica (9.3)0.40%—Premmerce Wishlist FOR WoocommerceAI25/6/202625/6/2026
Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.
AnalizadaAlta (7.1)0.40%—Wdmtech Vwishlist19/6/202621/8/2026
Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vproductid and userid parameters. Attackers can send POST requests to the component with crafted SQL payloads in these parameters to extract…
AplazadaCrítica (9.9)0.48%—Wishlistmember Wishlist MemberAI17/6/202617/6/2026
Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.
AplazadaMedia (4.3)0.26%—Wishlistmember Wishlist MemberAI17/6/202617/6/2026
Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions.
AplazadaAlta (8.8)0.44%—Wishlistmember Wishlist MemberAI23/5/202623/7/2026
The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaAlta (8.8)0.44%—Wishlistmember Wishlist MemberAI23/5/202623/7/2026
The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaAlta (8.8)0.45%—Wishlistmember Wishlist MemberAI23/5/202623/7/2026
The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns the REST API Secret Key to…
AplazadaAlta (8.8)0.44%—Wishlistmember Wishlist MemberAI23/5/202623/7/2026
The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the ajax_get_screen() function. This makes it possible for authenticated attackers, with Subscriber-level access and…
AnalizadaCrítica (9.6)0.51%—Charm Wish7/5/202617/6/2026
Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks. A malicious SCP client can read arbitrary files from the server, write arbitrary files to the server, and create directories…
AplazadaMedia (5.3)0.33%—Moreconvert Woocommerce WishlistAI7/5/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Wishlist: from n/a through 4.12.0.
AplazadaMedia (6.5)0.27%—Moreconvert Woocommerce WishlistAI10/4/202617/6/2026
The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_title() AJAX handler before allowing wishlist renaming operations. The function only checks for a valid nonce, which is publicly exposed in the page source of the /wishlist/ page, making it possible…
AplazadaMedia (5.3)0.29%—Nmerii NM Gift Registry AND Wishlist LiteAI8/4/202624/7/2026
Missing Authorization vulnerability in nmerii NM Gift Registry and Wishlist Lite nm-gift-registry-and-wishlist-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NM Gift Registry and Wishlist Lite: from n/a through <= 5.13.
AplazadaAlta (8.8)0.52%—Wishlistmember Wishlist Member XAI19/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X: from n/a through 3.29.0.
AplazadaMedia (4.3)0.25%—Wpclever WPC Smart WishlistAI13/3/202617/6/2026
Missing Authorization vulnerability in WPClever WPC Smart Wishlist for WooCommerce woo-smart-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Smart Wishlist for WooCommerce: from n/a through <= 5.0.8.
AplazadaMedia (6.5)0.26%—Addonify - Woocommerce WishlistAI20/2/202617/6/2026
Missing Authorization vulnerability in Addonify Addonify – WooCommerce Wishlist addonify-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify – WooCommerce Wishlist: from n/a through <= 2.0.15.
AplazadaMedia (6.4)0.26%—Wish TO GOAI7/1/202617/6/2026
The Wish To Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and including, 0.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access…