Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.26% | — | Community EventsAI | 18/2/2026 | 17/6/2026 | The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ce_venue_name' parameter in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above,… | |
| Aplazada | Media (4.3) | 0.30% | — | EventprimeAI | 18/2/2026 | 17/6/2026 | The EventPrime plugin for WordPress is vulnerable to unauthorized post modification due to missing authorization checks in all versions up to, and including, 4.2.8.4. This is due to the save_frontend_event_submission function accepting a user-controlled event_id parameter and updating the corresponding event post… | |
| Aplazada | Media (5.3) | 0.40% | 💥 PoC | EventprimeAI | 17/2/2026 | 17/6/2026 | The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including, 4.2.8.4. This is due to the plugin registering the upload_file_media AJAX action as publicly accessible (nopriv-enabled) without implementing any authentication, authorization, or nonce… | |
| Aplazada | Media (6.4) | 0.26% | — | Theeventscalendar Shortcode AND BlockAI | 10/2/2026 | 17/6/2026 | The The Events Calendar Shortcode & Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ecs-list-events` shortcode `message` attribute in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Analizada | Media (5.5) | 0.38% | — | Admerc Event Management System | 9/2/2026 | 17/6/2026 | A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/manage_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (6.4) | 0.28% | — | Events Listing WidgetAI | 6/2/2026 | 17/6/2026 | The Events Listing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Event URL' parameter in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Aplazada | Media (6.5) | 0.15% | — | Brian Hogg THE Events Calendar ShortcodeAI | 3/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Hogg The Events Calendar Shortcode & Block the-events-calendar-shortcode allows Stored XSS.This issue affects The Events Calendar Shortcode & Block: from n/a through <= 3.1.1. | |
| Aplazada | Alta (8.8) | 0.42% | — | Magepeopleteam WpeventlyAI | 3/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.0.8. | |
| Aplazada | Media (4.3) | 0.13% | — | Magepeopleteam WpeventlyAIMagepeopleteam Mage-eventpressAI | 3/2/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam WpEvently mage-eventpress allows Cross Site Request Forgery.This issue affects WpEvently: from n/a through <= 5.1.1. | |
| Aplazada | Media (6.1) | 0.20% | — | Timeline Event HistoryAI | 24/1/2026 | 17/6/2026 | The Timeline Event History plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `id` parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (4.3) | 0.25% | — | Multidots Fraud Prevention FOR WoocommerceAI | 23/1/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers allows Retrieve Embedded Sensitive Data.This issue affects Fraud Prevention For Woocommerce: from n/a through <= 2.3.2. | |
| Aplazada | Media (5.3) | 0.21% | — | Metagauss EventprimeAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.8.0. | |
| Aplazada | Alta (8.5) | 0.37% | — | Fooevents FOR WoocommerceAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FooEvents FooEvents for WooCommerce fooevents allows SQL Injection.This issue affects FooEvents for WooCommerce: from n/a through <= 1.20.4. | |
| Aplazada | Alta (8.8) | 0.56% | — | Arraytics EventinAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Arraytics Eventin wp-event-solution allows Object Injection.This issue affects Eventin: from n/a through <= 4.1.3. | |
| Aplazada | Crítica (9) | 0.37% | — | Vollstart Event Tickets With Ticket ScannerAI | 22/1/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.5. | |
| Aplazada | Media (6.5) | 0.39% | — | Eventespresso Event Espresso 4 DecafAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf event-espresso-decaf allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Espresso 4 Decaf: from n/a through <= 5.0.37.decaf. | |
| Aplazada | Media (6.5) | 0.38% | — | Tickera-event-ticketing-systemAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tickera: from n/a through <= 3.5.6.2. | |
| Aplazada | Crítica (9.9) | 0.54% | — | Blazethemes News EventAI | 22/1/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <= 1.0.1. | |
| Aplazada | Alta (8.5) | 0.15% | — | Fspro Event LOG ExplorerAI | 21/1/2026 | 17/6/2026 | Event Log Explorer 4.9.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific file system locations that will be executed with… | |
| Aplazada | Media (5.4) | 0.21% | — | Theeventscalendar THE Events CalendarAI | 20/1/2026 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'start_migration', 'cancel_migration', and 'revert_migration' functions in all versions up to, and including, 6.15.13. This makes it possible for authenticated attackers, with subscriber level… | |
| Aplazada | Media (5.3) | 0.27% | — | Community EventsAI | 17/1/2026 | 17/6/2026 | The Community Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_admin_event_approval() function in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to approve arbitrary events via the 'eventlist'… | |
| Aplazada | Media (5.3) | 0.43% | — | EventprimeAI | 13/1/2026 | 17/6/2026 | The EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.7.0 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive booking data including user names, email addresses,… | |
| Aplazada | Crítica (9.3) | 0.33% | — | Imaster Mems Events CRMAI | 12/1/2026 | 17/6/2026 | Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’. | |
| Aplazada | Alta (8.7) | 0.29% | — | Imaster Mems Events CRMAI | 12/1/2026 | 17/6/2026 | Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.php’. | |
| Analizada | Media (5.3) | 0.27% | — | Wikimedia Campaignevents | 9/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki - CampaignEvents extension: 1.45, 1.44, 1.43, 1.39. |