Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
105 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | — | — | Saveto Wishlist LiteAI | 3/10/2026 | 3/10/2026 | The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database. | |
| Aplazada | Alta (7.1) | 0.18% | — | Premmerce WishlistAI | 1/10/2026 | 1/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Premmerce WishlistAI | 1/10/2026 | 1/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions. | |
| Aplazada | Alta (7.6) | 0.38% | — | MC Woocommerce WishlistAI | 17/9/2026 | 17/9/2026 | Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. | |
| Aplazada | Media (5.3) | 0.34% | — | Prestashop BlockwishlistAI | 16/9/2026 | 22/9/2026 | PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers'… | |
| Aplazada | Media (5.3) | 0.30% | — | Moreconvert Woocommerce WishlistAI | 11/9/2026 | 11/9/2026 | The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Wishlistmember Wishlist MemberAI | 14/8/2026 | 14/8/2026 | The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and… | |
| Aplazada | Media (6.5) | 0.22% | — | Wishlistmember Wishlist Member XAI | 23/7/2026 | 23/7/2026 | Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mildainc MC Woocommerce WishlistAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Premmerce Wishlist FOR WoocommerceAI | 25/6/2026 | 25/6/2026 | Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions. | |
| Analizada | Alta (7.1) | 0.40% | — | Wdmtech Vwishlist | 19/6/2026 | 21/8/2026 | Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vproductid and userid parameters. Attackers can send POST requests to the component with crafted SQL payloads in these parameters to extract… | |
| Aplazada | Crítica (9.9) | 0.48% | — | Wishlistmember Wishlist MemberAI | 17/6/2026 | 17/6/2026 | Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. | |
| Aplazada | Media (4.3) | 0.26% | — | Wishlistmember Wishlist MemberAI | 17/6/2026 | 17/6/2026 | Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions. | |
| Aplazada | Alta (8.8) | 0.44% | — | Wishlistmember Wishlist MemberAI | 23/5/2026 | 23/7/2026 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Alta (8.8) | 0.44% | — | Wishlistmember Wishlist MemberAI | 23/5/2026 | 23/7/2026 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (8.8) | 0.45% | — | Wishlistmember Wishlist MemberAI | 23/5/2026 | 23/7/2026 | The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns the REST API Secret Key to… | |
| Aplazada | Alta (8.8) | 0.44% | — | Wishlistmember Wishlist MemberAI | 23/5/2026 | 23/7/2026 | The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the ajax_get_screen() function. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Analizada | Crítica (9.6) | 0.51% | — | Charm Wish | 7/5/2026 | 17/6/2026 | Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks. A malicious SCP client can read arbitrary files from the server, write arbitrary files to the server, and create directories… | |
| Aplazada | Media (5.3) | 0.33% | — | Moreconvert Woocommerce WishlistAI | 7/5/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Wishlist: from n/a through 4.12.0. | |
| Aplazada | Media (6.5) | 0.27% | — | Moreconvert Woocommerce WishlistAI | 10/4/2026 | 17/6/2026 | The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_title() AJAX handler before allowing wishlist renaming operations. The function only checks for a valid nonce, which is publicly exposed in the page source of the /wishlist/ page, making it possible… | |
| Aplazada | Media (5.3) | 0.29% | — | Nmerii NM Gift Registry AND Wishlist LiteAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in nmerii NM Gift Registry and Wishlist Lite nm-gift-registry-and-wishlist-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NM Gift Registry and Wishlist Lite: from n/a through <= 5.13. | |
| Aplazada | Alta (8.8) | 0.52% | — | Wishlistmember Wishlist Member XAI | 19/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This issue affects WishList Member X: from n/a through 3.29.0. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpclever WPC Smart WishlistAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WPClever WPC Smart Wishlist for WooCommerce woo-smart-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Smart Wishlist for WooCommerce: from n/a through <= 5.0.8. | |
| Aplazada | Media (6.5) | 0.26% | — | Addonify - Woocommerce WishlistAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Addonify Addonify – WooCommerce Wishlist addonify-wishlist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Addonify – WooCommerce Wishlist: from n/a through <= 2.0.15. | |
| Aplazada | Media (6.4) | 0.26% | — | Wish TO GOAI | 7/1/2026 | 17/6/2026 | The Wish To Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and including, 0.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access… |