Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
797 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.7% | — | Booking Calendar Project Booking Calendar | 10/5/2022 | 17/6/2026 | The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site. | |
| Modificada | Media (4.8) | 0.56% | — | Webnus Modern Events Calendar Lite | 14/4/2022 | 17/6/2026 | Authenticated (admin+ user) Stored Cross-Site Scripting (XSS) in Modern Events Calendar Lite (WordPress plugin) <= 6.5.1 | |
| Modificada | Crítica (9.8) | 33% | — | Nextcloud Calendar | 11/4/2022 | 17/6/2026 | Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the email value in the JSON request, a malicious attacker can inject newlines to break out of the `RCPT TO:<BOOKING USER'S EMAIL>… | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Elbtide Advanced Booking Calendar | 11/4/2022 | 17/6/2026 | The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Alta (7.2) | 1.5% | — | Elbtide Advanced Booking Calendar | 11/4/2022 | 17/6/2026 | The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks | |
| Modificada | Crítica (9.8) | 1.8% | — | Elbtide Advanced Booking Calendar | 21/3/2022 | 17/6/2026 | The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection | |
| Modificada | Media (5.4) | 70% | — | Webnus Modern Events Calendar Lite | 21/3/2022 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.3) | 0.40% | — | Spiffyplugins Spiffy Calendar | 21/2/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0). | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | 10web Spidercalendar | 14/2/2022 | 17/6/2026 | The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue. | |
| Modificada | Media (6.1) | 0.89% | — | Roundupwp Registrations FOR THE Events Calendar | 24/1/2022 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (5.4) | 0.61% | — | Webnus Modern Events Calendar Lite | 17/1/2022 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS. | |
| Modificada | Media (4.3) | 0.35% | — | Theeventscalendar Eventcalendar | 17/1/2022 | 17/6/2026 | The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events | |
| Modificada | Media (6.1) | 0.81% | — | Theeventscalendar Eventcalendar | 17/1/2022 | 17/6/2026 | The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues | |
| Modificada | Media (6.1) | 0.80% | — | Booking Calendar Project Booking Calendar | 3/1/2022 | 17/6/2026 | The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Crítica (9.8) | 73% | 💥 Exploit | Webnus Modern Events Calendar Lite | 13/12/2021 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue | |
| Modificada | Media (6.1) | 0.82% | — | Webnus Modern Events Calendar Lite | 13/12/2021 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Crítica (9.8) | 7.3% | 💥 Exploit | Roundupwp Registrations FOR THE Events Calendar | 6/12/2021 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection. | |
| Modificada | Media (5.4) | 0.62% | — | MY Calendar Project MY Calendar | 29/11/2021 | 17/6/2026 | The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Roundupwp Registrations FOR THE Events Calendar | 29/11/2021 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.89% | — | PHP Event Calendar Project PHP Event Calendar | 8/11/2021 | 17/6/2026 | PHP Event Calendar through 2021-11-04 allows persistent cross-site scripting (XSS), as demonstrated by the /server/ajax/events_manager.php title parameter. This can be exploited by an adversary in multiple ways, e.g., to perform actions on the page in the context of other users, or to deface the site. | |
| Modificada | Crítica (9.8) | 2.5% | — | Kaysongroup PHP Event Calendar | 8/11/2021 | 17/6/2026 | PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the… | |
| Modificada | Media (5.4) | 0.65% | — | Webnus Modern Events Calendar Lite | 1/11/2021 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users with access to adjust settings withing wp-admin. | |
| Modificada | Media (4.8) | 0.62% | — | Webnus Modern Events Calendar Lite | 4/10/2021 | 17/6/2026 | The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8.8) | 1.3% | — | Offshorewebmaster Availability Calendar | 20/9/2021 | 17/6/2026 | The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+ | |
| Modificada | Media (4.8) | 0.62% | — | Offshorewebmaster Availability Calendar | 20/9/2021 | 17/6/2026 | The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting them in page/post where the associated shortcode is embed, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed |