Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

797 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.7%—Booking Calendar Project Booking Calendar10/5/202217/6/2026
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.
ModificadaMedia (4.8)0.56%—Webnus Modern Events Calendar Lite14/4/202217/6/2026
Authenticated (admin+ user) Stored Cross-Site Scripting (XSS) in Modern Events Calendar Lite (WordPress plugin) <= 6.5.1
ModificadaCrítica (9.8)33%—Nextcloud Calendar11/4/202217/6/2026
Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails via Newlines: as newlines and special characters are not sanitized in the email value in the JSON request, a malicious attacker can inject newlines to break out of the `RCPT TO:<BOOKING USER'S EMAIL>…
ModificadaMedia (6.1)1.9%💥 ExploitElbtide Advanced Booking Calendar11/4/202217/6/2026
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
ModificadaAlta (7.2)1.5%—Elbtide Advanced Booking Calendar11/4/202217/6/2026
The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks
ModificadaCrítica (9.8)1.8%—Elbtide Advanced Booking Calendar21/3/202217/6/2026
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection
ModificadaMedia (5.4)70%—Webnus Modern Events Calendar Lite21/3/202217/6/2026
The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
ModificadaMedia (4.3)0.40%—Spiffyplugins Spiffy Calendar21/2/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0).
ModificadaMedia (6.1)2.3%💥 Exploit10web Spidercalendar14/2/202217/6/2026
The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.
ModificadaMedia (6.1)0.89%—Roundupwp Registrations FOR THE Events Calendar24/1/202217/6/2026
The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (5.4)0.61%—Webnus Modern Events Calendar Lite17/1/202217/6/2026
The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.
ModificadaMedia (4.3)0.35%—Theeventscalendar Eventcalendar17/1/202217/6/2026
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events
ModificadaMedia (6.1)0.81%—Theeventscalendar Eventcalendar17/1/202217/6/2026
The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues
ModificadaMedia (6.1)0.80%—Booking Calendar Project Booking Calendar3/1/202217/6/2026
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaCrítica (9.8)73%💥 ExploitWebnus Modern Events Calendar Lite13/12/202117/6/2026
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before using it in a SQL statement in the mec_load_single_page AJAX action, available to unauthenticated users, leading to an unauthenticated SQL injection issue
ModificadaMedia (6.1)0.82%—Webnus Modern Events Calendar Lite13/12/202117/6/2026
The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider parameter of its mec_list_load_more AJAX call (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
ModificadaCrítica (9.8)7.3%💥 ExploitRoundupwp Registrations FOR THE Events Calendar6/12/202117/6/2026
The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.
ModificadaMedia (5.4)0.62%—MY Calendar Project MY Calendar29/11/202117/6/2026
The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (6.1)1.2%💥 ExploitRoundupwp Registrations FOR THE Events Calendar29/11/202117/6/2026
The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)0.89%—PHP Event Calendar Project PHP Event Calendar8/11/202117/6/2026
PHP Event Calendar through 2021-11-04 allows persistent cross-site scripting (XSS), as demonstrated by the /server/ajax/events_manager.php title parameter. This can be exploited by an adversary in multiple ways, e.g., to perform actions on the page in the context of other users, or to deface the site.
ModificadaCrítica (9.8)2.5%—Kaysongroup PHP Event Calendar8/11/202117/6/2026
PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the…
ModificadaMedia (5.4)0.65%—Webnus Modern Events Calendar Lite1/11/202117/6/2026
The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users with access to adjust settings withing wp-admin.
ModificadaMedia (4.8)0.62%—Webnus Modern Events Calendar Lite4/10/202117/6/2026
The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (8.8)1.3%—Offshorewebmaster Availability Calendar20/9/202117/6/2026
The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before using it in a SQL statement, leading to a SQL Injection issue, which can be exploited by any user able to add shortcode to posts/pages, such as contributor+
ModificadaMedia (4.8)0.62%—Offshorewebmaster Availability Calendar20/9/202117/6/2026
The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting them in page/post where the associated shortcode is embed, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
Orbitaley — Vulnerabilidades