Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
324 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.61% | — | Webnus Modern Events Calendar Lite | 17/1/2022 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS. | |
| Modificada | Media (4.3) | 0.35% | — | Theeventscalendar Eventcalendar | 17/1/2022 | 17/6/2026 | The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events | |
| Modificada | Media (6.1) | 0.81% | — | Theeventscalendar Eventcalendar | 17/1/2022 | 17/6/2026 | The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues | |
| Modificada | Alta (8.8) | 1.4% | — | E-dynamics Events Made Easy | 3/1/2022 | 17/6/2026 | The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As a result, users with a role as low as subscriber can call it and perform SQL injection attacks | |
| Modificada | Crítica (9.8) | 73% | 💥 Exploit | Webnus Modern Events Calendar Lite | 13/12/2021 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue | |
| Modificada | Media (6.1) | 0.82% | — | Webnus Modern Events Calendar Lite | 13/12/2021 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Crítica (9.8) | 7.3% | 💥 Exploit | Roundupwp Registrations FOR THE Events Calendar | 6/12/2021 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection. | |
| Modificada | Media (6.1) | 0.91% | — | Pixelite Events Manager | 1/12/2021 | 17/6/2026 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues | |
| Modificada | Alta (7.2) | 1.5% | — | Pixelite Events Manager | 1/12/2021 | 17/6/2026 | The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Roundupwp Registrations FOR THE Events Calendar | 29/11/2021 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (4.8) | 0.70% | — | E-dynamics Events Made Easy | 1/11/2021 | 17/6/2026 | The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (5.4) | 0.65% | — | Webnus Modern Events Calendar Lite | 1/11/2021 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users with access to adjust settings withing wp-admin. | |
| Modificada | Media (4.8) | 0.62% | — | Webnus Modern Events Calendar Lite | 4/10/2021 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (7.2) | 1.6% | — | Simple Events Calendar Project Simple Events Calendar | 23/8/2021 | 17/6/2026 | The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue | |
| Modificada | Media (6.1) | 0.83% | — | Community Events Project Community Events | 2/8/2021 | 17/6/2026 | The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator | |
| Modificada | Alta (8.8) | 1.5% | — | Webnus Modern Events Calendar Lite | 18/3/2021 | 17/6/2026 | Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue. | |
| Modificada | Media (5.4) | 0.75% | — | Webnus Modern Events Calendar Lite | 18/3/2021 | 17/6/2026 | Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not sanitise the mic_comment field (Notes on time) when adding/editing an event, allowing users with privilege as low as author to add events with a Cross-Site Scripting payload in them, which… | |
| Modificada | Alta (7.5) | 31% | 💥 Exploit | Webnus Modern Events Calendar Lite | 18/3/2021 | 17/6/2026 | Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example. | |
| Modificada | Alta (7.2) | 87% | 💥 Exploit | Webnus Modern Events Calendar Lite | 18/3/2021 | 17/6/2026 | Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request. | |
| Modificada | Media (6.1) | 0.49% | — | Designmasterevents Conference Management CMS | 27/8/2020 | 17/6/2026 | DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php' | |
| Modificada | Crítica (9.8) | 2.2% | — | Designmasterevents Conference Management | 27/8/2020 | 17/6/2026 | DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page. | |
| Modificada | Alta (7.2) | 0.98% | — | Gwesystems Jevents | 9/3/2020 | 17/6/2026 | JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action. | |
| Modificada | Media (5.4) | 1.0% | — | Webnus Modern Events Calendar Lite | 28/2/2020 | 17/6/2026 | Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allows remote authenticated users (with minimal permissions) to inject arbitrary JavaScript, HTML, or CSS via Ajax actions. This affects mec_save_notifications and import_settings. | |
| Modificada | Crítica (9.8) | 2.5% | — | Slub-dresden Slub Events | 16/10/2019 | 17/6/2026 | The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below, this results in Remote Code Execution. In versions later than 1.2.2, this can result in Denial of Service, since the web space can be filled up with… | |
| Modificada | Media (5.4) | 1.2% | — | Pixelite Events Manager | 16/10/2019 | 17/6/2026 | The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin. |