Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

324 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.61%—Webnus Modern Events Calendar Lite17/1/202217/6/2026
The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.
ModificadaMedia (4.3)0.35%—Theeventscalendar Eventcalendar17/1/202217/6/2026
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events
ModificadaMedia (6.1)0.81%—Theeventscalendar Eventcalendar17/1/202217/6/2026
The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues
ModificadaAlta (8.8)1.4%—E-dynamics Events Made Easy3/1/202217/6/2026
The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As a result, users with a role as low as subscriber can call it and perform SQL injection attacks
ModificadaCrítica (9.8)73%💥 ExploitWebnus Modern Events Calendar Lite13/12/202117/6/2026
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue
ModificadaMedia (6.1)0.82%—Webnus Modern Events Calendar Lite13/12/202117/6/2026
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
ModificadaCrítica (9.8)7.3%💥 ExploitRoundupwp Registrations FOR THE Events Calendar6/12/202117/6/2026
The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.
ModificadaMedia (6.1)0.91%—Pixelite Events Manager1/12/202117/6/2026
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues
ModificadaAlta (7.2)1.5%—Pixelite Events Manager1/12/202117/6/2026
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
ModificadaMedia (6.1)1.2%💥 ExploitRoundupwp Registrations FOR THE Events Calendar29/11/202117/6/2026
The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
ModificadaMedia (4.8)0.70%—E-dynamics Events Made Easy1/11/202117/6/2026
The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (5.4)0.65%—Webnus Modern Events Calendar Lite1/11/202117/6/2026
The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users with access to adjust settings withing wp-admin.
ModificadaMedia (4.8)0.62%—Webnus Modern Events Calendar Lite4/10/202117/6/2026
The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (7.2)1.6%—Simple Events Calendar Project Simple Events Calendar23/8/202117/6/2026
The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue
ModificadaMedia (6.1)0.83%—Community Events Project Community Events2/8/202117/6/2026
The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
ModificadaAlta (8.8)1.5%—Webnus Modern Events Calendar Lite18/3/202117/6/2026
Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[post_id] POST parameter in the mec_fes_form AJAX action when logged in as an author+, leading to an authenticated SQL Injection issue.
ModificadaMedia (5.4)0.75%—Webnus Modern Events Calendar Lite18/3/202117/6/2026
Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not sanitise the mic_comment field (Notes on time) when adding/editing an event, allowing users with privilege as low as author to add events with a Cross-Site Scripting payload in them, which…
ModificadaAlta (7.5)31%💥 ExploitWebnus Modern Events Calendar Lite18/3/202117/6/2026
Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.
ModificadaAlta (7.2)87%💥 ExploitWebnus Modern Events Calendar Lite18/3/202117/6/2026
Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.
ModificadaMedia (6.1)0.49%—Designmasterevents Conference Management CMS27/8/202017/6/2026
DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php'
ModificadaCrítica (9.8)2.2%—Designmasterevents Conference Management27/8/202017/6/2026
DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.
ModificadaAlta (7.2)0.98%—Gwesystems Jevents9/3/202017/6/2026
JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action.
ModificadaMedia (5.4)1.0%—Webnus Modern Events Calendar Lite28/2/202017/6/2026
Multiple Stored Cross-site scripting (XSS) vulnerabilities in the Webnus Modern Events Calendar Lite plugin through 5.1.6 for WordPress allows remote authenticated users (with minimal permissions) to inject arbitrary JavaScript, HTML, or CSS via Ajax actions. This affects mec_save_notifications and import_settings.
ModificadaCrítica (9.8)2.5%—Slub-dresden Slub Events16/10/201917/6/2026
The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to the webserver. For versions 1.2.2 and below, this results in Remote Code Execution. In versions later than 1.2.2, this can result in Denial of Service, since the web space can be filled up with…
ModificadaMedia (5.4)1.2%—Pixelite Events Manager16/10/201917/6/2026
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.
Orbitaley — Vulnerabilidades