Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.40% | — | WP Travel Gutenberg BlocksAI | 17/6/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wptravelengine WP Travel EngineAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. | |
| Aplazada | Alta (7.5) | 0.37% | — | Wptravelengine WP Travel EngineAI | 15/6/2026 | 17/6/2026 | Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | WptravellyAI | 15/6/2026 | 17/6/2026 | Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions. | |
| Aplazada | Crítica (9.3) | 0.67% | — | TravelscapeAI | 8/6/2026 | 23/7/2026 | WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting insufficient validation in the theme's upload functionality. Attackers can upload arbitrary files to the theme directory and execute them to achieve remote… | |
| Aplazada | Crítica (9.1) | 0.46% | — | WP Travel PROAI | 29/5/2026 | 21/7/2026 | The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and the Database::delete() method passing… | |
| Aplazada | Media (6.3) | 0.26% | — | Magepeople WptravellyAI | 26/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpTravelly: from n/a through 2.1.5. | |
| Aplazada | Alta (7.7) | 0.36% | — | Wensolutions WP TravelAI | 12/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows Blind SQL Injection.This issue affects WP Travel: from n/a through <= 11.4.0. | |
| Aplazada | Alta (8.8) | 0.27% | — | Adivaha TravelAI | 9/4/2026 | 26/9/2026 | WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pid' GET parameter. Attackers can send requests to the /mobile-app/v3/ endpoint with crafted 'pid' values using XOR-based… | |
| Aplazada | Media (5.1) | 0.26% | — | Adivaha TravelAI | 9/4/2026 | 26/9/2026 | WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at the /mobile-app/v3/… | |
| Aplazada | Media (4.3) | 0.23% | — | Magepeopleteam Wptravelly Tour-booking-managerAI | 8/4/2026 | 20/7/2026 | Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through <= 2.1.7. | |
| Aplazada | Media (6.4) | 0.16% | — | Wptravelengine WP Travel EngineAI | 4/4/2026 | 24/7/2026 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wte_trip_tax' shortcode in all versions up to, and including, 6.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Thamerex Work AND Travel CompanyAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work & Travel Company: from n/a through <= 1.2. | |
| Pendiente de análisis | Media (6.3) | 0.15% | — | HCL TravelerAI | 24/3/2026 | 17/6/2026 | HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks. | |
| Analizada | Media (4.3) | 0.28% | — | Hcltech Traveler | 24/3/2026 | 17/6/2026 | HCL Traveler is affected by sensitive information disclosure. The application generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Shinetheme TravelerAI | 18/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler allows Object Injection.This issue affects Traveler: from n/a through < 3.2.8.1. | |
| Aplazada | Media (5.3) | 0.29% | — | Wptravelengine Travel-bookingAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in wptravelengine Travel Booking travel-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Booking: from n/a through <= 1.3.9. | |
| Aplazada | Media (5.3) | 0.29% | — | Raratheme Travel DiariesAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme Travel Diaries travel-diaries allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Diaries: from n/a through <= 1.2.4. | |
| Aplazada | Media (5.3) | 0.29% | — | Rarathemes Travel AgencyAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme Travel Agency travel-agency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Agency: from n/a through <= 1.5.5. | |
| Aplazada | Alta (8.1) | 0.52% | — | Mikado-themes GotravelAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes GoTravel gotravel allows PHP Local File Inclusion.This issue affects GoTravel: from n/a through <= 2.1. | |
| Aplazada | Media (6.5) | 0.21% | — | TravelpayoutsAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Travelpayouts Travelpayouts travelpayouts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travelpayouts: from n/a through <= 1.2.2. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Boldthemes TraveliciousAI | 20/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in BoldThemes Travelicious travelicious allows Object Injection.This issue affects Travelicious: from n/a through < 1.6.7. | |
| Aplazada | Media (4.3) | 0.21% | — | Themefic Travelfic ToolkitAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Themefic Travelfic Toolkit travelfic-toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travelfic Toolkit: from n/a through <= 1.3.3. | |
| Aplazada | Media (5.3) | 0.40% | — | Travel MonsterAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in wptravelengine Travel Monster travel-monster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Monster: from n/a through <= 1.3.3. | |
| Aplazada | Media (5.3) | 0.25% | — | Wensolutions WP TravelAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through <= 11.1.0. |