Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1447 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.9)0.33%—Themewinter EventinAI5/9/20268/9/2026
The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy…
AplazadaMedia (6.6)0.43%—Themewinter EventinAI5/9/20268/9/2026
The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.
AplazadaBaja (2.7)0.32%—Theeventscalendar THE Events CalendarAI5/9/20268/9/2026
The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'.
AplazadaMedia (5.4)0.22%—Events ManagerAI5/9/20268/9/2026
The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions up to, and including, 7.3.3. This is due to insufficient input sanitization when storing attribute values (using only `wp_unslash()` without…
AplazadaAlta (7.1)0.25%—Fullworksplugins Quick Event ManagerAI3/9/20264/9/2026
Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
AplazadaAlta (7.5)0.35%—Fullworksplugins Quick Event ManagerAI3/9/20265/9/2026
Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
AplazadaMedia (6.5)0.33%—WP Event SolutionAI2/9/20262/9/2026
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.
AplazadaMedia (6.5)0.30%—Booking FOR Appointments AND Events CalendarAI2/9/20263/9/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier.
AplazadaBaja (2.7)0.28%—Booking FOR Appointments AND Events CalendarAI29/8/202631/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were…
AplazadaCrítica (9.1)0.44%—Plone APP EventAI28/8/20269/9/2026
plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events, and commits work per event. A logged-in…
AplazadaMedia (4.3)0.27%—WpeventlyAI28/8/202628/8/2026
Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
AplazadaMedia (5.4)0.29%—WpeventlyAI28/8/202628/8/2026
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
AplazadaBaja (3.1)0.18%—HCL Intelliops Event ManagementAI27/8/202628/8/2026
HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sessions to remain active after logout or session deletion.
AplazadaMedia (6.4)0.19%—HCL Intelliops Event ManagementAI27/8/202628/8/2026
HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of user sessions, resulting in sessions not being fully terminated after logout or deletion.
AplazadaCrítica (9.4)0.64%💥 PoCJoomlaeventmanager Joomla Event ManagerAI27/8/202628/8/2026
Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to remote code execution.
AplazadaMedia (5.3)0.35%—Joomla Event ManagerAI27/8/202628/8/2026
Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events.
AplazadaMedia (5.3)0.44%—Joomlaeventmanager Joomla Events ManagerAI27/8/202628/8/2026
Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.
AplazadaMedia (5.1)0.39%—Joomlaeventmanager Joomla Event ManagerAI27/8/202628/8/2026
Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that…
AplazadaMedia (6.9)0.41%—Ezcode Event ManagerAI27/8/202628/8/2026
Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.
AplazadaMedia (5.3)0.30%—Themewinter EventinAI26/8/202626/8/2026
The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed and be issued a valid paid ticket with no payment taken.
AplazadaMedia (6.5)0.30%—Booking FOR Appointments AND Events CalendarAI26/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
AplazadaMedia (4.7)0.20%—Booking FOR Appointments AND Events CalendarAI26/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account.
AplazadaMedia (5.3)0.31%—Themewinter EventinAI26/8/202626/8/2026
The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords and contents of password-protected ones.
AplazadaAlta (7.7)0.40%—Typo3AITypo3 Event RegistrationAI25/8/202626/8/2026
The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects.…
AplazadaMedia (6.1)0.41%💥 PoCEvents ManagerAI25/8/202626/8/2026
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'header_format' parameter in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
Orbitaley — Vulnerabilidades