Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

796 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.8)0.43%—CalendarAI27/7/202627/7/2026
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.
AplazadaMedia (5.3)0.30%—Theeventscalendar THE Events CalendarAI27/7/202627/7/2026
The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a…
AplazadaMedia (6.5)0.41%—Roundupwp Registrations FOR THE Events CalendarAI23/7/202623/7/2026
The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys…
AnalizadaMedia (6.3)0.27%—Oracle Common Applications Calendar21/7/202619/8/2026
Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Calendar Synchronizations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common…
AplazadaAlta (8.6)0.45%💥 PoCModern Event Calendar PROAIModern Event Calendar LiteAI20/7/202620/7/2026
The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection…
AplazadaAlta (8.7)0.40%—Digital-peak DP CalendarAIJoomlaAI15/7/202623/7/2026
Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulnerable to an unauthenticated SQL injection.
AplazadaAlta (7.1)0.25%—Room 34 Creative Services LLC ICS CalendarAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Reflected XSS.This issue affects ICS Calendar: from n/a through <= 12.1.1.
AplazadaMedia (5.3)0.29%—Wpdevart Booking CalendarAI13/7/202613/7/2026
Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36.
AplazadaMedia (4.4)0.41%—Lockme Oauth2 Calendars IntegrationAI11/7/202613/7/2026
The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App ID' setting in all versions up to, and including, 2.11.0. This is due to insufficient input sanitization and output escaping. The register_setting() call on line 197 lacks a sanitize callback,…
AplazadaMedia (6.4)0.35%—Starboard Suite Reservation CalendarsAI11/7/202629/9/2026
The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (6.1)0.50%—ICS CalendarAI10/7/202610/7/2026
The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter in all versions up to, and including, 12.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaMedia (5.9)0.44%—Wpdevart Booking CalendarAI10/7/202610/7/2026
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpdevart_id’ parameter in all versions up to, and including, 3.2.17 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
AplazadaAlta (7.5)1.6%💥 ExploitMY CalendarAI8/7/20268/7/2026
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaAlta (8.1)0.65%—Appointment Booking Calendar Plugin AND Scheduling PluginAI8/7/20268/7/2026
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to…
AplazadaMedia (5.3)0.54%—MY CalendarAI2/7/20262/7/2026
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14 via the 'vcal' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate occurrence IDs…
AplazadaMedia (4.3)0.39%—Appointment Booking CalendarAI1/7/20261/7/2026
The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email…
AplazadaMedia (4.3)0.13%—Book A Room Event CalendarAI24/6/202625/6/2026
The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorrect nonce validation on the settings_form()/update_settings() functionality. The plugin's options page handler dispatches on the 'action' POST…
AnalizadaAlta (8.8)0.43%—Joomalshowroom Event Registration PRO Calendar19/6/202621/8/2026
Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_registrationpro&view=category&id parameter…
AnalizadaAlta (8.8)0.49%—Zcontent ZAP Calendar Lite19/6/202621/8/2026
Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requests to the RSVP plugin endpoint with crafted SQL payloads to extract sensitive…
AnalizadaAlta (8.8)0.49%—Joomla Calendar Planner19/6/202619/8/2026
Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id parameter to extract sensitive database…
AplazadaMedia (6.4)0.33%—Appointment Booking CalendarAI19/6/202622/6/2026
The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and…
AplazadaMedia (4.3)0.28%—Appointment Booking CalendarAI18/6/202618/6/2026
The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabc_appointments_calendar_load2() function, which is reachable via the…
AplazadaAlta (8.5)0.34%—Theeventscalendar THE Events CalendarAI17/6/20266/10/2026
Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.
AplazadaCrítica (9.3)0.45%💥 PoCStellarwp THE Events CalendarAI16/6/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
AplazadaAlta (8.8)0.52%—Geodir Events CalendarAIPHPAI15/6/202617/6/2026
Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
Orbitaley — Vulnerabilidades