Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.46% | — | Yshop CRMAI | 16/9/2026 | 24/9/2026 | yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list permission to enumerate all users. Attackers with valid back-office credentials and a role… | |
| Aplazada | Alta (7.1) | 0.43% | — | Yshop-crmAI | 16/9/2026 | 24/9/2026 | yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps. Attackers can invoke the DELETE /admin-api/crm/flow/delete-step endpoint without required permissions to remove… | |
| Aplazada | Media (5.3) | 0.38% | — | Yshop-crmAI | 16/9/2026 | 23/9/2026 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers can retrieve approval chain topology, step ordering, approver identifiers, and personal information including… | |
| Aplazada | Alta (7.1) | 0.45% | — | Yshop-crmAI | 16/9/2026 | 23/9/2026 | yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to retrieve operator names, display nicknames, client IP addresses, User-Agent… | |
| Aplazada | Alta (7.1) | 0.43% | — | Yshop CRMAI | 16/9/2026 | 24/9/2026 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can invoke the lead-claim endpoint to reassign leads from other employees to themselves… | |
| Aplazada | Media (5.3) | 0.35% | — | Yshop-crmAI | 16/9/2026 | 23/9/2026 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status. Attackers can invoke the GET /admin-api/product/store-product/sale endpoint with sequential product IDs to withdraw entire… | |
| Aplazada | Alta (7.1) | 0.43% | — | Yshop-crmAI | 16/9/2026 | 23/9/2026 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/invoice/issue endpoint without required permissions to modify invoice status,… | |
| Aplazada | Alta (7.1) | 0.50% | — | Yshop-crmAI | 16/9/2026 | 23/9/2026 | yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer auto-recycling policy. Attackers can invoke these endpoints to manipulate shared… | |
| Aplazada | Media (5.3) | 0.36% | — | Yshop-crm Yshop CRMAI | 16/9/2026 | 23/9/2026 | yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers. Attackers can invoke POST /admin-api/crm/customer/send-sms and POST /admin-api/crm/customer/send-mail with… | |
| Aplazada | Media (6.1) | 0.25% | — | Guchengwuyue YshopmallAI | 9/9/2026 | 14/9/2026 | yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files. | |
| Analizada | Baja (2.1) | 0.32% | — | Guchengwuyue Yshopmall | 8/2/2026 | 17/6/2026 | A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out… | |
| Modificada | Baja (2.1) | 0.39% | — | Guchengwuyue Yshopmall | 9/1/2026 | 17/6/2026 | A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the… | |
| Analizada | Alta (7.2) | 0.44% | — | Guchengwuyue Yshopmall | 4/3/2025 | 17/6/2026 | yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface. | |
| Analizada | Crítica (9.8) | 1.0% | — | Guchengwuyue Yshopmall | 15/11/2024 | 17/6/2026 | yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files. | |
| Modificada | Media (5.3) | 0.44% | — | Wiloke Myshopkit | 26/2/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiloke WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit.This issue affects WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit: from n/a through 1.0.9. | |
| Modificada | Crítica (9.8) | 0.68% | — | Boostmyshop | 9/2/2024 | 17/6/2026 | SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php. | |
| Modificada | Media (6.1) | 0.44% | — | Myshopkit Winters | 20/10/2023 | 17/6/2026 | The Winters theme for WordPress is vulnerable to Reflected Cross-Site Scripting via prototype pollution in versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they… | |
| Modificada | Media (6.1) | 0.79% | — | Foxy-shop Foxyshop | 11/7/2022 | 17/6/2026 | The FoxyShop WordPress plugin before 4.8.2 does not sanitise and escape a parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (8.1) | 1.5% | — | Tinyrise Tinyshop | 25/3/2022 | 17/6/2026 | A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could let a malicious user delete any file such as install.lock to reinstall cms. | |
| Modificada | Media (6.1) | 0.95% | — | Tinyshop Project Tinyshop | 18/5/2021 | 17/6/2026 | TinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. TinyShop allows XSS via the explain_first and again_explain parameters of the /evaluate/index.php page. The vulnerability may be exploited remotely, resulting in cross-site scripting (XSS) or… | |
| Modificada | Media (5.4) | 0.56% | — | Katyshop2 Project Katyshop2 | 7/5/2020 | 17/6/2026 | Katyshop2 before 2.12 has multiple stored XSS issues. | |
| Modificada | Media (6.8) | 2.1% | — | Guillaume Gauvrit Pyshop | 6/8/2013 | 16/6/2026 | pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation. | |
| Modificada | Alta (7.5) | 8.6% | — | Agtc Myshop | 6/5/2009 | 16/6/2026 | AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto." | |
| Modificada | Alta (7.5) | 1.0% | — | E107 Easyshop Plugin | 29/10/2008 | 16/6/2026 | SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary SQL commands via the category_id parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Julien Desaunay Phpmyshop | 31/12/2003 | 16/6/2026 | SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands via the (1) identifiant and (2) password parameters. |