Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

89 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.81%—Winter CMSAI25/8/202631/8/2026
Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding through Eloquent models and query…
AplazadaMedia (6.9)0.49%—Winter CMSAI25/8/202628/8/2026
Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable files by placing =include or =require directives in theme JavaScript assets. Attackers can reference files like…
AplazadaBaja (2.7)0.33%—Themewinter EventinAI21/8/202626/8/2026
The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side requests to arbitrary hosts.
AplazadaBaja (2.7)0.28%—Themewinter EventinAI19/8/202626/8/2026
The Eventin WordPress plugin before 4.1.21 does not verify the current user's permission to edit other users before assigning roles and updating user metadata during speaker creation, allowing users with contributor-level access and above to modify other users' roles and metadata.
AplazadaAlta (8.1)0.35%—Themewinter EventinAI19/8/202626/8/2026
The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned to a different author, allowing users with contributor-level access and above to alter, delete, or take over events created by other users including administrators.
AplazadaMedia (4.3)0.25%—Themewinter EventinAI12/8/202626/8/2026
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers' order data including personal information by iterating order identifiers.
AplazadaAlta (8.2)0.33%—Themewinter EventinAI12/8/202626/8/2026
The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records.
AplazadaMedia (6.5)0.37%—Themewinter EventinAI12/8/202626/8/2026
The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users with contributor-level access and above to read other customers' personal data such as names and email addresses.
AplazadaAlta (7.2)0.57%—Themewinter EventinAI10/8/202626/8/2026
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.
AplazadaAlta (7.5)0.36%—Themewinter EventinAI30/7/202630/7/2026
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.
AplazadaMedia (5.3)0.35%—Themewinter EventinAI10/7/202613/7/2026
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a regression in versions from 4.0.26 up to and including 4.1.15. This is due to the plugin not properly verifying that a user is authorized to perform an action in the…
AplazadaMedia (6.4)0.36%—Themewinter EventinAI10/7/202610/7/2026
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter in all versions up to, and including, 4.1.15 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (5.4)0.41%—Themewinter WpcafeAI10/7/202610/7/2026
The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…
AplazadaMedia (4.3)0.27%—Themewinter WpcafeAI26/6/202626/6/2026
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
AplazadaMedia (4.3)0.28%—Themewinter EventinAI14/4/202617/6/2026
The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This makes it possible for authenticated…
AplazadaMedia (6.5)0.36%—Winterlock WP System LOGAI25/3/202617/6/2026
Missing Authorization vulnerability in activity-log.com WP System Log winterlock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP System Log: from n/a through <= 1.2.7.
AnalizadaCrítica (9.9)0.77%—Wintercms Winter11/3/202617/6/2026
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.0.477, 1.1.12, and 1.2.12, Winter CMS allowed authenticated backend users to escalate their accounts level of access to the system by modifying the roles / permissions assigned to their account through…
AplazadaMedia (6.5)0.30%—Winter Activity LOGAI12/2/202617/6/2026
The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the winter_activity_log_action() function in all versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
AnalizadaBaja (3.5)0.29%—Wintercms Winter6/2/202617/6/2026
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS before 1.2.10 allow users with access to the CMS Asset Manager were able to upload SVGs without automatic sanitization. To actively exploit this security issue, an attacker would need access to the…
AplazadaAlta (7.2)0.33%—Themewinter EventinAI9/1/202617/6/2026
The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'post_settings' function in all versions up to, and including, 4.0.51. This makes it possible for unauthenticated attackers to…
AplazadaAlta (7.2)0.29%—Themewinter EventinAI23/8/202517/6/2026
The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.37 via the proxy_image function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations…
AnalizadaCrítica (9.8)0.58%—Winterchens My-site22/8/202517/6/2026
Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.
AnalizadaAlta (7.5)0.37%—Winterchens My-site20/8/202517/6/2026
Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components without authentication via the cn.luischen.interceptor.BaseInterceptor class
AnalizadaAlta (7.5)0.37%—Winterchens My-site20/8/202517/6/2026
Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.
AnalizadaCrítica (9.8)0.44%—Winterchens My-site20/8/202517/6/2026
There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability to access /admin/ API without any token.