Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.46% | — | Liquidweb Event Tickets | 4/3/2024 | 17/6/2026 | The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts). | |
| Analizada | Media (6.5) | 0.60% | — | Liquidweb Event Tickets | 4/3/2024 | 17/6/2026 | The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed… | |
| Modificada | Media (4.3) | 0.39% | — | Liquidweb Event Tickets | 22/2/2024 | 17/6/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, with contributor-level access and above, to email the attendees… | |
| Modificada | Alta (8.8) | 0.50% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 12/2/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin: from n/a through 4.1.1. | |
| Modificada | Media (5.4) | 0.33% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 18/7/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 versions. | |
| Modificada | Alta (8.8) | 0.29% | — | Mage-people Event Manager AND Tickets Selling Plugin FOR Woocommerce | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.7.7 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 23/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce <= 3.8.6. versions. | |
| Modificada | Alta (8.8) | 0.28% | — | MY Tickets Project MY Tickets | 13/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Tickets plugin <= 1.9.10 versions. | |
| Modificada | Media (5.4) | 0.48% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 6/2/2023 | 17/6/2026 | The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Alta (8.8) | 1.5% | — | Mage-people Event Manager AND Tickets Selling FOR Woocommerce | 14/3/2022 | 17/6/2026 | The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | TRI Event Tickets | 24/1/2022 | 17/6/2026 | The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue | |
| Modificada | Media (6.1) | 1.2% | — | MY Tickets Project MY Tickets | 17/11/2021 | 17/6/2026 | The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins | |
| Modificada | Media (5.4) | 0.78% | — | Solaplugins Sola Support Tickets | 20/9/2019 | 17/6/2026 | The sola-support-tickets plugin before 3.13 for WordPress has incorrect access control for /wp-admin with resultant XSS. | |
| Modificada | Alta (8.8) | 3.2% | — | Liquidweb Event Tickets | 8/9/2019 | 17/6/2026 | CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticketed > Attendees" Export Attendees feature. | |
| Modificada | Alta (7.5) | 1.4% | — | Tickets Project Tickets | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for tickets (TKT), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | JSP Tickets Project JSP Tickets | 5/2/2018 | 17/6/2026 | SQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id parameter in a statuslist (or prioritylist) edit action. | |
| Modificada | Media (4.3) | 2.1% | — | Theeventscalendar Eventbrite Tickets | 18/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php. | |
| Modificada | Media (5.4) | 0.27% | — | MB Tickets Project MB Tickets | 21/10/2014 | 17/6/2026 | The MB Tickets (aka com.xcr.android.mbtickets) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Awesomeseating BUY Tickets | 9/9/2014 | 17/6/2026 | The Buy Tickets (aka com.xcr.android.buytickets) application 2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Joomla COM Gsticketsystem | 20/5/2009 | 16/6/2026 | SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewCategory action to index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joomla COM Waticketsystem | 29/1/2009 | 16/6/2026 | SQL injection vulnerability in the WebAmoeba (WA) Ticket System (com_waticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php. | |
| Modificada | Media (5.1) | 2.7% | 💥 Exploit | HOT Open Tickets | 1/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/lib_action_step.php in Hot Open Tickets (HOT) 11012004_ver2f, when register_globals is enabled, allows remote attackers to include arbitrary files via the GLOBALS[CLASS_PATH] parameter. NOTE: this issue might be resultant from a global overwrite vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Triangle Solutions PHP Support Tickets | 15/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in PHP Support Tickets 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields, and (3) id parameter. |