Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1448 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.25% | — | Coolhappy Countdown FOR THE Events CalendarAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CoolHappy The Events Calendar Countdown Addon countdown-for-the-events-calendar allows Stored XSS.This issue affects The Events Calendar Countdown Addon: from n/a through <= 1.4.9. | |
| Aplazada | Media (6.5) | 0.25% | — | Avecnous Event PostAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post allows Stored XSS.This issue affects Event post: from n/a through <= 5.10.1. | |
| Aplazada | Media (4.3) | 0.16% | — | Quick-event-calendarAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Cross Site Request Forgery.This issue affects Quick Event Calendar: from n/a through <= 1.4.9. | |
| Aplazada | Media (5.9) | 0.26% | — | Marchettidesign Next Event CalendarAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marchetti Design Next Event Calendar allows Stored XSS. This issue affects Next Event Calendar: from n/a through 1.2. | |
| Aplazada | Crítica (9) | 0.68% | — | Stylemixthemes Motors - EventsAI | 6/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors - Events stm-motors-events allows PHP Local File Inclusion.This issue affects Motors - Events: from n/a through <= 1.4.7. | |
| Aplazada | Media (5.3) | 0.34% | — | Webnus Modern Events Calendar LiteAI | 6/6/2025 | 17/6/2026 | The Modern Events Calendar Lite plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 7.21.9. This is due improper or insufficient validation of the id property when exporting calendars. This makes it possible for unauthenticated attackers to retrieve the full path of the web… | |
| Aplazada | Media (6.3) | 0.14% | — | Fossasia Open-event-serverAI | 29/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in fossasia open-event-server 1.19.1. This issue affects the function send_email_change_user_email of the file /fossasia/open-event-server/blob/development/app/api/helpers/mail.py of the component Mail Verification Handler. The manipulation leads to… | |
| Modificada | Crítica (9.8) | 28% | 💥 Exploit | Themewinter Eventin | 23/5/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This issue affects Eventin: from n/a through <= 4.0.26. | |
| Analizada | Alta (7.5) | 0.40% | — | Events LOG Track Project Events LOG Track | 21/5/2025 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocation.This issue affects Events Log Track: from 0.0.0 before 3.1.11, from 4.0.0 before 4.0.2. | |
| Aplazada | Alta (7.1) | 0.22% | — | Elbisnero Wordpress Events Calendar Registration AND TicketsAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplus allows Reflected XSS.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through <= 2.6.0. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Elbisnero WpeventplusAI | 19/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplus allows Object Injection.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through <= 2.6.0. | |
| Modificada | Media (5.4) | 0.26% | — | Xylusthemes Import Social Events | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes Import Social Events import-facebook-events allows Stored XSS.This issue affects Import Social Events: from n/a through <= 1.8.5. | |
| Aplazada | Media (5.4) | 0.36% | — | Stellarwp THE Events CalendarAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in StellarWP The Events Calendar the-events-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through <= 6.11.2.1. | |
| Analizada | Media (5.4) | 0.20% | — | Myeventon Eventon | 17/5/2025 | 17/6/2026 | The EventON Pro plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the 'assets/lib/settings/settings.js' file in all versions up to, and including, 4.9.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject… | |
| Aplazada | Media (5.3) | 0.33% | — | Ashan Perera Eventon LiteAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Ashan Perera EventON eventon-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects EventON: from n/a through <= 2.4.4. | |
| Aplazada | Media (5.3) | 0.40% | — | Myeventon EventonAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ashanjay EventON eventon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects EventON: from n/a through <= 4.9.8. | |
| Modificada | Alta (8.8) | 0.50% | — | Imithemes Eventer | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in imithemes Eventer eventer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eventer: from n/a through < 3.11.4. | |
| Modificada | Crítica (9.8) | 0.52% | — | Imithemes Eventer | 16/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in imithemes Eventer eventer allows Blind SQL Injection.This issue affects Eventer: from n/a through < 3.11.4. | |
| Analizada | Media (4.8) | 0.31% | — | Snumb130 Events Calendar | 15/5/2025 | 17/6/2026 | The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Alta (7.5) | 0.45% | — | Total-soft Event Calendar | 15/5/2025 | 17/6/2026 | The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars. | |
| Analizada | Media (4.8) | 0.35% | — | Stellarwp THE Events Calendar | 15/5/2025 | 17/6/2026 | The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Baja (3.5) | 0.32% | — | Vollstart Event Tickets With Ticket Scanner | 15/5/2025 | 17/6/2026 | The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks | |
| Modificada | Media (6.4) | 0.30% | — | Metagauss Eventprime | 15/5/2025 | 17/6/2026 | The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally, the feature is lacking a nonce. | |
| Analizada | Media (4.3) | 0.18% | — | Bluetrait Blue Trait Event Viewer | 15/5/2025 | 17/6/2026 | The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Crítica (9.8) | 5.1% | 💥 Exploit | Themewinter Eventin | 14/5/2025 | 17/6/2026 | Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Eventin: from n/a through <= 4.0.26. |