Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

323 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.56%—Theeventscalendar THE Events CalendarAI24/8/202626/8/2026
Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.
AplazadaAlta (7.1)0.25%—E-dynamics Events Made EasyAI24/8/202624/8/2026
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
AplazadaAlta (7.5)0.87%—E-dynamics Events Made EasyAI20/8/202620/8/2026
The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the…
AplazadaCrítica (9.3)0.40%—Webnus Modern Events CalendarAI18/8/202620/8/2026
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
AplazadaBaja (3.7)0.26%—Booking FOR Appointments AND Events CalendarAI13/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.
AplazadaCrítica (9.8)0.50%💥 PoCEvents ManagerAI12/8/202626/8/2026
The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to Administrator, or delete any account whose user ID…
AplazadaAlta (8.1)0.39%—Events ManagerAI12/8/202626/8/2026
The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to other people.
AplazadaBaja (3.8)0.26%—Booking FOR Appointments AND Events CalendarAI10/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating…
AplazadaMedia (5.3)0.16%—Wpeventsmanager WP Events ManagerAI7/8/202626/8/2026
The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the…
AplazadaCrítica (9.8)0.48%—Wpeventsmanager WP Events ManagerAI7/8/202626/8/2026
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.
AplazadaMedia (5.3)0.30%—E-dynamics Events Made EasyAI6/8/202626/8/2026
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.
AplazadaAlta (7.1)0.25%—Events ManagerAI6/8/202622/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager events-manager allows Reflected XSS.This issue affects Events Manager: from n/a through 7.4.2.
AplazadaAlta (7.5)0.43%—Events ManagerAI6/8/202626/8/2026
The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to…
AplazadaMedia (5.3)0.32%—Simple Google Calendar Outlook Events WidgetAI4/8/202626/8/2026
The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal request.
AplazadaBaja (2.7)0.28%—Booking FOR Appointments AND Events CalendarAI1/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.
AplazadaMedia (5.3)0.30%—E-dynamics Events Made EasyAI31/7/202626/8/2026
The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the…
AplazadaMedia (6.5)0.33%—E-dynamics Events Made EasyAI27/7/202627/7/2026
Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.
AplazadaMedia (5.3)0.30%—Theeventscalendar THE Events CalendarAI27/7/202627/7/2026
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a…
AplazadaMedia (6.5)0.41%—Roundupwp Registrations FOR THE Events CalendarAI23/7/202623/7/2026
The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys…
AplazadaAlta (7.5)0.39%—Joomdonation Events BookingAI22/7/202623/7/2026
Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.
AplazadaAlta (7.5)0.45%—Events ManagerAI22/7/202622/7/2026
The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget…
AplazadaAlta (8.8)0.20%—Joomdonation Events BookingAI17/7/202623/7/2026
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.
AplazadaCrítica (9.8)0.55%—Joomdonation Events BookingAI17/7/202623/7/2026
Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.
AplazadaMedia (5.3)0.34%—Joomdonation Events BookingAI17/7/202623/7/2026
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.
AnalizadaMedia (5.4)0.39%—Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events14/7/202628/8/2026
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is…
Orbitaley — Vulnerabilidades