Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1447 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.23% | — | Event Booking ManagerAI | 2/8/2026 | 26/8/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and… | |
| Aplazada | Media (5.4) | 0.23% | — | Event Booking ManagerAI | 2/8/2026 | 26/8/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to inject arbitrary JavaScript that executes… | |
| Aplazada | Media (6.6) | 0.59% | — | Event Booking ManagerAI | 2/8/2026 | 26/8/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce… | |
| Aplazada | Baja (2.2) | 0.23% | — | Event Tickets AND RegistrationAI | 1/8/2026 | 26/8/2026 | The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own. | |
| Aplazada | Media (5.3) | 0.30% | — | Eventbrite Event TicketsAI | 1/8/2026 | 26/8/2026 | The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders. | |
| Aplazada | Baja (2.7) | 0.28% | — | Booking FOR Appointments AND Events CalendarAI | 1/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request. | |
| Aplazada | Media (5.3) | 0.30% | — | E-dynamics Events Made EasyAI | 31/7/2026 | 26/8/2026 | The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated data-change request, relying only on a public nonce with no per-record token or ownership check, allowing unauthenticated attackers to overwrite the… | |
| Aplazada | Alta (7.5) | 0.36% | — | Themewinter EventinAI | 30/7/2026 | 30/7/2026 | The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment. | |
| Aplazada | Media (4.3) | 0.40% | — | Eventbooking Event Booking Manager FOR WoocommerceAI | 29/7/2026 | 30/7/2026 | The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Baja (3.5) | 0.24% | — | Eventtickets Event TicketsAI | 28/7/2026 | 28/7/2026 | The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations. | |
| Pendiente de análisis | Alta (7.5) | 0.28% | — | Event Driven AnsibleAI | 27/7/2026 | 4/8/2026 | A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]) and relies solely on the Subject HTTP header value for mTLS authentication without verifying that the header originated from a trusted… | |
| Aplazada | Media (5.3) | 0.29% | — | Event TicketsAI | 27/7/2026 | 27/7/2026 | Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | E-dynamics Events Made EasyAI | 27/7/2026 | 27/7/2026 | Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. | |
| Aplazada | Media (5.3) | 0.30% | — | Theeventscalendar THE Events CalendarAI | 27/7/2026 | 27/7/2026 | The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arbitrary content in a… | |
| Aplazada | Alta (7.3) | 0.34% | — | Eventeon Action UserAI | 24/7/2026 | 24/7/2026 | The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to grant EventON management capabilities… | |
| Aplazada | Media (5.3) | 0.31% | — | EventAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Event post <= 6.0.1 versions. | |
| Aplazada | Alta (8.8) | 0.70% | — | Mdjm Event ManagementAI | 23/7/2026 | 23/7/2026 | The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of… | |
| Aplazada | Media (6.5) | 0.41% | — | Roundupwp Registrations FOR THE Events CalendarAI | 23/7/2026 | 23/7/2026 | The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from $_POST['standard'] and uses the JSON array keys… | |
| Aplazada | Alta (7.5) | 0.39% | — | Joomdonation Events BookingAI | 22/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information. | |
| Aplazada | Alta (7.5) | 0.45% | — | Events ManagerAI | 22/7/2026 | 22/7/2026 | The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget… | |
| Analizada | Media (4.2) | 0.20% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data. | |
| Analizada | Media (4.3) | 0.25% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions. | |
| Analizada | Baja (3.7) | 0.24% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications. | |
| Analizada | Media (5.3) | 0.29% | — | Hcltech Intelliops Event Management | 21/7/2026 | 30/7/2026 | HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits. | |
| Aplazada | Alta (8.6) | 0.45% | 💥 PoC | Modern Event Calendar PROAIModern Event Calendar LiteAI | 20/7/2026 | 20/7/2026 | The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection… |