Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.26% | — | Marchettidesign Next Event CalendarAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marchetti Design Next Event Calendar allows Stored XSS. This issue affects Next Event Calendar: from n/a through 1.2. | |
| Analizada | Alta (7.5) | 0.45% | — | Total-soft Event Calendar | 15/5/2025 | 17/6/2026 | The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars. | |
| Aplazada | Alta (7.1) | 0.39% | — | Rzfarrell CGM Event CalendarAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rzfarrell CGM Event Calendar cgm-event-calendar allows Reflected XSS.This issue affects CGM Event Calendar: from n/a through <= 0.8.5. | |
| Analizada | Media (5.3) | 0.45% | — | Theeventscalendar Event Tickets | 21/2/2025 | 17/6/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Media (5.4) | 0.29% | — | Theeventscalendar THE Events Calendar | 23/1/2025 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar Link Widget through the html_tag attribute in all versions up to, and including, 6.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.63% | — | Theeventscalendar THE Events CalendarAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through 6.1.2.2. | |
| Aplazada | Baja (3.8) | 0.47% | — | Codepeople CP Multi View Event CalendarAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar : from n/a through 1.4.13. | |
| Analizada | Alta (7.2) | 0.74% | — | Theeventscalendar Events Calendar PRO | 30/8/2024 | 17/6/2026 | The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP… | |
| Aplazada | Media (4.3) | 0.31% | — | Codepeople CP Multi View Event CalendarAI | 3/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue affects CP Multi View Event Calendar: from n/a through 1.4.10. | |
| Aplazada | Media (6.5) | 0.48% | — | Theeventscalendar BookitAI | 17/5/2024 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0. | |
| Modificada | Alta (8.8) | 1.4% | — | Coolplugins Cool TimelineCoolplugins Cryptocurrency WidgetsCoolplugins Cryptocurrency Widgets FOR ElementorCoolplugins Event Single Page Builder FOR THE Event Calendar+6 | 7/6/2023 | 17/6/2026 | Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber. | |
| Modificada | Media (4.8) | 0.37% | — | Easy Event Calendar Project Easy Event Calendar | 8/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CoreFortress Easy Event calendar plugin <= 1.0 versions. | |
| Modificada | Media (5.4) | 0.55% | — | Total-soft Event Calendar | 21/9/2022 | 17/6/2026 | Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress. | |
| Modificada | Media (5.3) | 0.66% | — | Total-soft Event Calendar | 9/9/2022 | 17/6/2026 | Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress. | |
| Modificada | Media (4.3) | 0.35% | — | Theeventscalendar Eventcalendar | 17/1/2022 | 17/6/2026 | The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events | |
| Modificada | Media (6.1) | 0.81% | — | Theeventscalendar Eventcalendar | 17/1/2022 | 17/6/2026 | The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues | |
| Modificada | Media (6.1) | 0.89% | — | PHP Event Calendar Project PHP Event Calendar | 8/11/2021 | 17/6/2026 | PHP Event Calendar through 2021-11-04 allows persistent cross-site scripting (XSS), as demonstrated by the /server/ajax/events_manager.php title parameter. This can be exploited by an adversary in multiple ways, e.g., to perform actions on the page in the context of other users, or to deface the site. | |
| Modificada | Crítica (9.8) | 2.5% | — | Kaysongroup PHP Event Calendar | 8/11/2021 | 17/6/2026 | PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username parameter. This can be used to execute SQL statements directly on the database, allowing an adversary in some cases to completely compromise the database system. It can also be used to bypass the… | |
| Modificada | Media (5.4) | 1.2% | — | Web-dorado Event Calendar WD | 9/1/2019 | 17/6/2026 | Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Joomlacalendars Event Calendar | 30/1/2018 | 17/6/2026 | SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Event Calendar Category Script Project Event Calendar Category Script | 13/12/2017 | 17/6/2026 | Event Search Script 1.0 has SQL Injection via the /event-list city parameter. | |
| Modificada | Media (6.1) | 1.5% | — | Web-dorado Event Calendar WD | 7/7/2017 | 17/6/2026 | Cross-site scripting vulnerability in Event Calendar WD prior to version 1.0.94 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.3% | — | Web-dorado Spider Event Calendar | 12/4/2017 | 17/6/2026 | SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php. | |
| Modificada | Media (4.3) | 2.1% | — | Theeventscalendar Eventbrite Tickets | 18/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php. | |
| Modificada | Alta (7.5) | 40% | 💥 Exploit | CP Multi View Event Calendar Project CP Multi View Event Calendar | 4/11/2014 | 17/6/2026 | SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter. |