Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

61 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.26%—Marchettidesign Next Event CalendarAI6/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marchetti Design Next Event Calendar allows Stored XSS. This issue affects Next Event Calendar: from n/a through 1.2.
AnalizadaAlta (7.5)0.45%—Total-soft Event Calendar15/5/202517/6/2026
The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.
AplazadaAlta (7.1)0.39%—Rzfarrell CGM Event CalendarAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rzfarrell CGM Event Calendar cgm-event-calendar allows Reflected XSS.This issue affects CGM Event Calendar: from n/a through <= 0.8.5.
AnalizadaMedia (5.3)0.45%—Theeventscalendar Event Tickets21/2/202517/6/2026
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AnalizadaMedia (5.4)0.29%—Theeventscalendar THE Events Calendar23/1/202517/6/2026
The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.63%—Theeventscalendar THE Events CalendarAI13/12/202417/6/2026
Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through 6.1.2.2.
AplazadaBaja (3.8)0.47%—Codepeople CP Multi View Event CalendarAI9/12/202417/6/2026
Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar : from n/a through 1.4.13.
AnalizadaAlta (7.2)0.74%—Theeventscalendar Events Calendar PRO30/8/202417/6/2026
The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP…
AplazadaMedia (4.3)0.31%—Codepeople CP Multi View Event CalendarAI3/6/202417/6/2026
Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue affects CP Multi View Event Calendar: from n/a through 1.4.10.
AplazadaMedia (6.5)0.48%—Theeventscalendar BookitAI17/5/202417/6/2026
Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0.
ModificadaAlta (8.8)1.4%—Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+67/6/202317/6/2026
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
ModificadaMedia (4.8)0.37%—Easy Event Calendar Project Easy Event Calendar8/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CoreFortress Easy Event calendar plugin <= 1.0 versions.
ModificadaMedia (5.4)0.55%—Total-soft Event Calendar21/9/202217/6/2026
Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
ModificadaMedia (5.3)0.66%—Total-soft Event Calendar9/9/202217/6/2026
Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
ModificadaMedia (4.3)0.35%—Theeventscalendar Eventcalendar17/1/202217/6/2026
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events
ModificadaMedia (6.1)0.81%—Theeventscalendar Eventcalendar17/1/202217/6/2026
The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues
ModificadaMedia (6.1)0.89%—PHP Event Calendar Project PHP Event Calendar8/11/202117/6/2026
PHP Event Calendar through 2021-11-04 allows persistent cross-site scripting (XSS), as demonstrated by the /server/ajax/events_manager.php title parameter. This can be exploited by an adversary in multiple ways, e.g., to perform actions on the page in the context of other users, or to deface the site.
ModificadaCrítica (9.8)2.5%—Kaysongroup PHP Event Calendar8/11/202117/6/2026
PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the…
ModificadaMedia (5.4)1.2%—Web-dorado Event Calendar WD9/1/201917/6/2026
Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaCrítica (9.8)2.7%💥 ExploitJoomlacalendars Event Calendar30/1/201817/6/2026
SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.
ModificadaCrítica (9.8)3.0%💥 ExploitEvent Calendar Category Script Project Event Calendar Category Script13/12/201717/6/2026
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
ModificadaMedia (6.1)1.5%—Web-dorado Event Calendar WD7/7/201717/6/2026
Cross-site scripting vulnerability in Event Calendar WD prior to version 1.0.94 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaCrítica (9.8)2.3%—Web-dorado Spider Event Calendar12/4/201717/6/2026
SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.
ModificadaMedia (4.3)2.1%—Theeventscalendar Eventbrite Tickets18/8/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php.
ModificadaAlta (7.5)40%💥 ExploitCP Multi View Event Calendar Project CP Multi View Event Calendar4/11/201417/6/2026
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter.
Orbitaley — Vulnerabilidades