Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
323 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.56% | — | Theeventscalendar THE Events CalendarAI | 24/8/2026 | 26/8/2026 | Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | E-dynamics Events Made EasyAI | 24/8/2026 | 24/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions. | |
| Aplazada | Alta (7.5) | 0.87% | — | E-dynamics Events Made EasyAI | 20/8/2026 | 20/8/2026 | The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Webnus Modern Events CalendarAI | 18/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. | |
| Aplazada | Baja (3.7) | 0.26% | — | Booking FOR Appointments AND Events CalendarAI | 13/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data. | |
| Aplazada | Crítica (9.8) | 0.50% | 💥 PoC | Events ManagerAI | 12/8/2026 | 26/8/2026 | The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to Administrator, or delete any account whose user ID… | |
| Aplazada | Alta (8.1) | 0.39% | — | Events ManagerAI | 12/8/2026 | 26/8/2026 | The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to other people. | |
| Aplazada | Baja (3.8) | 0.26% | — | Booking FOR Appointments AND Events CalendarAI | 10/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating… | |
| Aplazada | Media (5.3) | 0.16% | — | Wpeventsmanager WP Events ManagerAI | 7/8/2026 | 26/8/2026 | The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Wpeventsmanager WP Events ManagerAI | 7/8/2026 | 26/8/2026 | The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment. | |
| Aplazada | Media (5.3) | 0.30% | — | E-dynamics Events Made EasyAI | 6/8/2026 | 26/8/2026 | The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid. | |
| Aplazada | Alta (7.1) | 0.25% | — | Events ManagerAI | 6/8/2026 | 22/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager events-manager allows Reflected XSS.This issue affects Events Manager: from n/a through 7.4.2. | |
| Aplazada | Alta (7.5) | 0.43% | — | Events ManagerAI | 6/8/2026 | 26/8/2026 | The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to… | |
| Aplazada | Media (5.3) | 0.32% | — | Simple Google Calendar Outlook Events WidgetAI | 4/8/2026 | 26/8/2026 | The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal request. | |
| Aplazada | Baja (2.7) | 0.28% | — | Booking FOR Appointments AND Events CalendarAI | 1/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request. | |
| Aplazada | Media (5.3) | 0.30% | — | E-dynamics Events Made EasyAI | 31/7/2026 | 26/8/2026 | The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the… | |
| Aplazada | Media (6.5) | 0.33% | — | E-dynamics Events Made EasyAI | 27/7/2026 | 27/7/2026 | Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. | |
| Aplazada | Media (5.3) | 0.30% | — | Theeventscalendar THE Events CalendarAI | 27/7/2026 | 27/7/2026 | The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a… | |
| Aplazada | Media (6.5) | 0.41% | — | Roundupwp Registrations FOR THE Events CalendarAI | 23/7/2026 | 23/7/2026 | The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys… | |
| Aplazada | Alta (7.5) | 0.39% | — | Joomdonation Events BookingAI | 22/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information. | |
| Aplazada | Alta (7.5) | 0.45% | — | Events ManagerAI | 22/7/2026 | 22/7/2026 | The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget… | |
| Aplazada | Alta (8.8) | 0.20% | — | Joomdonation Events BookingAI | 17/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Joomdonation Events BookingAI | 17/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets. | |
| Aplazada | Media (5.3) | 0.34% | — | Joomdonation Events BookingAI | 17/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses. | |
| Analizada | Media (5.4) | 0.39% | — | Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events | 14/7/2026 | 28/8/2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is… |