Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.24% | — | Shinetheme TravelerAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through < 3.2.8. | |
| Aplazada | Media (6.5) | 0.29% | — | Shinetheme TravelerAI | 8/1/2026 | 7/10/2026 | Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through <= 3.2.6. | |
| Modificada | Media (5.4) | 0.22% | — | Qodeinteractive Backpack Traveler | 30/12/2025 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Backpack Traveler backpacktraveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backpack Traveler: from n/a through <= 2.10.3. | |
| Aplazada | Alta (8.1) | 0.40% | — | Shinetheme TravelerAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in shinetheme Traveler traveler allows PHP Local File Inclusion.This issue affects Traveler: from n/a through < 3.2.6. | |
| Aplazada | Alta (7.1) | 0.18% | — | Shinetheme TravelerAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Traveler traveler allows Reflected XSS.This issue affects Traveler: from n/a through < 3.2.6. | |
| Modificada | Alta (8.1) | 0.53% | — | Ancorathemes Unitravel | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes UniTravel unitravel allows PHP Local File Inclusion.This issue affects UniTravel: from n/a through <= 1.4.2. | |
| Aplazada | Alta (8.5) | 0.25% | — | Shinetheme TravelerAI | 18/12/2025 | 5/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through < 3.2.6. | |
| Aplazada | Baja (2.7) | 0.27% | — | Shinetheme Traveler Option TreeAI | 16/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in shinetheme Traveler Option Tree custom-option-tree allows Retrieve Embedded Sensitive Data.This issue affects Traveler Option Tree: from n/a through <= 2.8. | |
| Aplazada | Media (5.3) | 0.25% | — | Shinetheme TravelerAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through <= 3.2.6. | |
| Analizada | Baja (2.1) | 0.36% | — | Ashraf-kabir Travel-agency | 23/11/2025 | 17/6/2026 | A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this issue is some unknown functionality of the file /results.php of the component Search. The manipulation of the argument user_query results in sql injection. The attack can be launched remotely.… | |
| Analizada | Baja (2) | 0.38% | — | Ashraf-kabir Travel-agency | 23/11/2025 | 17/6/2026 | A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this vulnerability is an unknown functionality of the file /admin_area/index.php. The manipulation of the argument edit_pack leads to sql injection. The attack can be initiated remotely.… | |
| Modificada | Baja (2.1) | 0.38% | — | Ashraf-kabir Travel-agency | 23/11/2025 | 17/6/2026 | A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to… | |
| Aplazada | Media (6.5) | 0.15% | — | Camille V Travelers MAPAI | 21/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Camille V Travelers' Map travelers-map allows Stored XSS.This issue affects Travelers' Map: from n/a through <= 2.3.2. | |
| Aplazada | Media (6.5) | 0.18% | — | WP Travel Gutenberg BlocksAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel WP Travel Gutenberg Blocks wp-travel-blocks.This issue affects WP Travel Gutenberg Blocks: from n/a through <= 3.9.2. | |
| Analizada | Media (5.5) | 0.16% | — | Hcltech Traveler FOR Microsoft Outlook | 16/10/2025 | 1/10/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications. | |
| Aplazada | Crítica (9.8) | 0.80% | — | Wptravelengine WP Travel EngineAI | 9/10/2025 | 17/6/2026 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.6.7 via the mode parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the… | |
| Aplazada | Crítica (9.8) | 0.92% | — | Wptravelengine WP Travel EngineAI | 9/10/2025 | 17/6/2026 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to insufficient file path validation in the set_user_profile_image function in all versions up to, and including, 6.6.7. This makes it possible for unauthenticated… | |
| Analizada | Baja (2) | 0.38% | — | Projectworlds Online Tours AND Travels | 28/9/2025 | 17/6/2026 | A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be initiated remotely. The exploit has… | |
| Aplazada | Alta (7.1) | 0.24% | — | Shinetheme TravelerAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Traveler traveler allows Reflected XSS.This issue affects Traveler: from n/a through < 3.2.3. | |
| Aplazada | Alta (7.5) | 0.38% | — | Shinetheme TravelerAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Traveler: from n/a through < 3.2.3. | |
| Aplazada | Media (6.5) | 0.17% | — | Wptravelengine WP Travel EngineAIWptravelengine WTE Elementor WidgetsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel Engine WP Travel Engine wte-elementor-widgets allows Stored XSS.This issue affects WP Travel Engine: from n/a through <= 1.4.2. | |
| Aplazada | Media (4.3) | 0.17% | — | Travelmap-blogAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in TravelMap Travel Map travelmap-blog allows Cross Site Request Forgery.This issue affects Travel Map: from n/a through <= 1.0.3. | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Travel Management System | 3/9/2025 | 17/6/2026 | A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown function of the file /viewcategory.php. Performing manipulation of the argument t1 results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public… | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Travel Management System | 3/9/2025 | 17/6/2026 | A vulnerability was identified in projectworlds Travel Management System 1.0. The affected element is an unknown function of the file /viewpackage.php. Such manipulation of the argument t1 leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.44% | — | Projectworlds Travel Management System | 3/9/2025 | 17/6/2026 | A vulnerability was determined in projectworlds Travel Management System 1.0. Impacted is an unknown function of the file /viewsubcategory.php. This manipulation of the argument t1 causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. |