Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.46%—Yshop CRMAI16/9/202624/9/2026
yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list permission to enumerate all users. Attackers with valid back-office credentials and a role…
AplazadaAlta (7.1)0.43%—Yshop-crmAI16/9/202624/9/2026
yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps. Attackers can invoke the DELETE /admin-api/crm/flow/delete-step endpoint without required permissions to remove…
AplazadaMedia (5.3)0.38%—Yshop-crmAI16/9/202623/9/2026
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers can retrieve approval chain topology, step ordering, approver identifiers, and personal information including…
AplazadaAlta (7.1)0.45%—Yshop-crmAI16/9/202623/9/2026
yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to retrieve operator names, display nicknames, client IP addresses, User-Agent…
AplazadaAlta (7.1)0.43%—Yshop CRMAI16/9/202624/9/2026
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim endpoint to reassign leads from other employees to themselves…
AplazadaMedia (5.3)0.35%—Yshop-crmAI16/9/202623/9/2026
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status. Attackers can invoke the GET /admin-api/product/store-product/sale endpoint with sequential product IDs to withdraw entire…
AplazadaAlta (7.1)0.43%—Yshop-crmAI16/9/202623/9/2026
yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/invoice/issue endpoint without required permissions to modify invoice status,…
AplazadaAlta (7.1)0.50%—Yshop-crmAI16/9/202623/9/2026
yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can invoke these endpoints to manipulate shared…
AplazadaMedia (5.3)0.36%—Yshop-crm Yshop CRMAI16/9/202623/9/2026
yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers. Attackers can invoke POST /admin-api/crm/customer/send-sms and POST /admin-api/crm/customer/send-mail with…
AplazadaMedia (6.1)0.25%—Guchengwuyue YshopmallAI9/9/202614/9/2026
yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files.
AnalizadaBaja (2.1)0.32%—Guchengwuyue Yshopmall8/2/202617/6/2026
A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out…
ModificadaBaja (2.1)0.39%—Guchengwuyue Yshopmall9/1/202617/6/2026
A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the…
AnalizadaAlta (7.2)0.44%—Guchengwuyue Yshopmall4/3/202517/6/2026
yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.
AnalizadaCrítica (9.8)1.0%—Guchengwuyue Yshopmall15/11/202417/6/2026
yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.
ModificadaMedia (5.3)0.44%—Wiloke Myshopkit26/2/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiloke WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit.This issue affects WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit: from n/a through 1.0.9.
ModificadaCrítica (9.8)0.68%—Boostmyshop9/2/202417/6/2026
SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php.
ModificadaMedia (6.1)0.44%—Myshopkit Winters20/10/202317/6/2026
The Winters theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they…
ModificadaMedia (6.1)0.79%—Foxy-shop Foxyshop11/7/202217/6/2026
The FoxyShop WordPress plugin before 4.8.2 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaAlta (8.1)1.5%—Tinyrise Tinyshop25/3/202217/6/2026
A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could let a malicious user delete any file such as install.lock to reinstall cms.
ModificadaMedia (6.1)0.95%—Tinyshop Project Tinyshop18/5/202117/6/2026
TinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. TinyShop allows XSS via the explain_first and again_explain parameters of the /evaluate/index.php page. The vulnerability may be exploited remotely, resulting in cross-site scripting (XSS) or…
ModificadaMedia (5.4)0.56%—Katyshop2 Project Katyshop27/5/202017/6/2026
Katyshop2 before 2.12 has multiple stored XSS issues.
ModificadaMedia (6.8)2.1%—Guillaume Gauvrit Pyshop6/8/201316/6/2026
pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.
ModificadaAlta (7.5)8.6%—Agtc Myshop6/5/200916/6/2026
AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto."
ModificadaAlta (7.5)1.0%—E107 Easyshop Plugin29/10/200816/6/2026
SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
ModificadaAlta (7.5)1.0%—Julien Desaunay Phpmyshop31/12/200316/6/2026
SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters.