Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.23% | — | Joedolson MY TicketsAI | 9/12/2025 | 5/10/2026 | Missing Authorization vulnerability in Joe Dolson My Tickets my-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Tickets: from n/a through <= 2.1.0. | |
| Aplazada | Media (5.4) | 0.22% | — | Stellarwp Event TicketsAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in StellarWP Event Tickets event-tickets.This issue affects Event Tickets: from n/a through <= 5.26.3. | |
| Aplazada | Alta (7.5) | 0.40% | — | Event Tickets AND RegistrationAI | 18/10/2025 | 17/6/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to the /wp-json/tribe/tickets/v1/commerce/free/order endpoint not verifying that a ticket type should be free allowing the user to bypass the payment. This makes it possible… | |
| Aplazada | Media (6.4) | 0.24% | — | Event Tickets Rsvps CalendarAI | 3/10/2025 | 17/6/2026 | The Event Tickets, RSVPs, Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ticket_spot' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.17% | — | Joedolson MY TicketsAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Dolson My Tickets my-tickets allows Stored XSS.This issue affects My Tickets: from n/a through <= 2.0.22. | |
| Aplazada | Alta (8.5) | 0.33% | — | RsticketsAIJoomlaAI | 11/6/2025 | 17/6/2026 | A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was discovered. It allows attackers to perform cross-site scripting (XSS) attacks via sending crafted payload. | |
| Analizada | Media (5.4) | 0.26% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 7/6/2025 | 17/6/2026 | The WpEvently plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Alta (7.1) | 0.22% | — | Elbisnero Wordpress Events Calendar Registration AND TicketsAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplus allows Reflected XSS.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through <= 2.6.0. | |
| Modificada | Baja (3.5) | 0.32% | — | Vollstart Event Tickets With Ticket Scanner | 15/5/2025 | 17/6/2026 | The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks | |
| Aplazada | Alta (8.8) | 0.38% | — | MY TicketsAI | 24/4/2025 | 17/6/2026 | The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.16. This is due to the mt_save_profile() function not appropriately restricting access to unauthorized users to update roles. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.31% | — | Stellarwp Event TicketsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Event Tickets event-tickets allows Reflected XSS.This issue affects Event Tickets: from n/a through <= 5.20.0. | |
| Analizada | Media (4.3) | 0.17% | — | Vollstart Event Tickets With Ticket Scanner | 28/3/2025 | 17/6/2026 | The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Media (5.3) | 0.45% | — | Theeventscalendar Event Tickets | 21/2/2025 | 17/6/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Media (5.3) | 0.32% | — | Liquidweb Event Tickets | 30/1/2025 | 17/6/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view order details of orders… | |
| Aplazada | Alta (7.5) | 0.40% | — | Joedolson MY TicketsAI | 21/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Joe Dolson My Tickets my-tickets allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects My Tickets: from n/a through <= 2.0.9. | |
| Aplazada | Media (4.3) | 0.19% | — | Stellarwp Event TicketsAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in StellarWP Event Tickets event-tickets allows Cross Site Request Forgery.This issue affects Event Tickets: from n/a through <= 5.11.0.4. | |
| Aplazada | Media (6.4) | 0.35% | — | TicketsourceAI | 20/12/2024 | 17/6/2026 | The Sell Tickets Online – TicketSource Ticket Shop for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ticketshop' shortcode in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (5.4) | 0.31% | — | Vollstart Event Tickets With Ticket ScannerAI | 6/12/2024 | 17/6/2026 | The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping and missing authorization on the functionality to manage tickets. This makes it… | |
| Aplazada | Alta (7.2) | 0.50% | — | Centreon-open-ticketsAI | 25/11/2024 | 17/6/2026 | An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection can occur in the form to create a ticket. Exploitation is only accessible to authenticated users with high-privileged… | |
| Modificada | Alta (8.8) | 0.74% | — | Vollstart Event Tickets With Ticket Scanner | 18/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.3.11. | |
| Aplazada | Alta (7.5) | 0.45% | — | Videowhisper Contact FormsAIVideowhisper Live SupportAIVideowhisper CRMAIVideowhisper Video MessagesAI+1 | 17/10/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in videowhisper Contact Forms, Live Support, CRM, Video Messages live-support-tickets allows Retrieve Embedded Sensitive Data.This issue affects Contact Forms, Live Support, CRM, Video Messages: from n/a through <= 1.10.2. | |
| Analizada | Alta (8.8) | 0.63% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 13/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Event Manager for WooCommerce: from n/a through 4.2.1. | |
| Modificada | Media (6.1) | 0.29% | — | Vollstart Event Tickets With Ticket Scanner | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Reflected XSS.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.1. | |
| Aplazada | Alta (7.5) | 0.68% | — | Joseph C Dolson MY TicketsAI | 17/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Joseph C Dolson My Tickets.This issue affects My Tickets: from n/a through 1.9.11. | |
| Aplazada | Media (4.3) | 0.40% | — | Event Tickets AND RegistrationAI | 9/4/2024 | 17/6/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.8.2 via the RSVP functionality. This makes it possible for authenticated attackers, with contributor access and above, to extract sensitive data including emails and street… |