Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

98 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.46%—Liquidweb Event Tickets4/3/202417/6/2026
The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).
AnalizadaMedia (6.5)0.60%—Liquidweb Event Tickets4/3/202417/6/2026
The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed…
ModificadaMedia (4.3)0.39%—Liquidweb Event Tickets22/2/202417/6/2026
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, with contributor-level access and above, to email the attendees…
ModificadaAlta (8.8)0.50%—Mage-people Event Manager AND Tickets Selling FOR Woocommerce12/2/202417/6/2026
Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin: from n/a through 4.1.1.
ModificadaMedia (5.4)0.33%—Mage-people Event Manager AND Tickets Selling FOR Woocommerce18/7/202317/6/2026
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 versions.
ModificadaAlta (8.8)0.29%—Mage-people Event Manager AND Tickets Selling Plugin FOR Woocommerce25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.7.7 versions.
ModificadaMedia (4.8)0.37%—Mage-people Event Manager AND Tickets Selling FOR Woocommerce23/3/202317/6/2026
Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions.
ModificadaAlta (8.8)0.28%—MY Tickets Project MY Tickets13/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Tickets plugin <= 1.9.10 versions.
ModificadaMedia (5.4)0.48%—Mage-people Event Manager AND Tickets Selling FOR Woocommerce6/2/202317/6/2026
The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (8.8)1.5%—Mage-people Event Manager AND Tickets Selling FOR Woocommerce14/3/202217/6/2026
The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks
ModificadaMedia (6.1)1.9%💥 ExploitTRI Event Tickets24/1/202217/6/2026
The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue
ModificadaMedia (6.1)1.2%—MY Tickets Project MY Tickets17/11/202117/6/2026
The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins
ModificadaMedia (5.4)0.78%—Solaplugins Sola Support Tickets20/9/201917/6/2026
The sola-support-tickets plugin before 3.13 for WordPress has incorrect access control for /wp-admin with resultant XSS.
ModificadaAlta (8.8)3.2%—Liquidweb Event Tickets8/9/201917/6/2026
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature.
ModificadaAlta (7.5)1.4%—Tickets Project Tickets9/7/201817/6/2026
The mintToken function of a smart contract implementation for tickets (TKT), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaCrítica (9.8)2.7%💥 ExploitJSP Tickets Project JSP Tickets5/2/201817/6/2026
SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a statuslist (or prioritylist) edit action.
ModificadaMedia (4.3)2.1%—Theeventscalendar Eventbrite Tickets18/8/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php.
ModificadaMedia (5.4)0.27%—MB Tickets Project MB Tickets21/10/201417/6/2026
The MB Tickets (aka com.xcr.android.mbtickets) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Awesomeseating BUY Tickets9/9/201417/6/2026
The Buy Tickets (aka com.xcr.android.buytickets) application 2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)1.1%💥 ExploitJoomla COM Gsticketsystem20/5/200916/6/2026
SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewCategory action to index.php.
ModificadaAlta (7.5)1.0%💥 ExploitJoomla COM Waticketsystem29/1/200916/6/2026
SQL injection vulnerability in the WebAmoeba (WA) Ticket System (com_waticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php.
ModificadaMedia (5.1)2.7%💥 ExploitHOT Open Tickets1/6/200616/6/2026
PHP remote file inclusion vulnerability in admin/lib_action_step.php in Hot Open Tickets (HOT) 11012004_ver2f, when register_globals is enabled, allows remote attackers to include arbitrary files via the GLOBALS[CLASS_PATH] parameter. NOTE: this issue might be resultant from a global overwrite vulnerability.
ModificadaAlta (7.5)1.3%—Triangle Solutions PHP Support Tickets15/12/200516/6/2026
Multiple SQL injection vulnerabilities in index.php in PHP Support Tickets 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields, and (3) id parameter.
Orbitaley — Vulnerabilidades