Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9) | 0.42% | — | Shinetheme TravelerAI | 27/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1. | |
| Aplazada | Alta (8.2) | 0.36% | — | Shinetheme TravelerAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in shinetheme Traveler traveler.This issue affects Traveler: from n/a through < 3.2.1. | |
| Aplazada | Alta (8.8) | 0.67% | — | Magepeopleteam WptravellyAI | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam WpTravelly tour-booking-manager allows PHP Local File Inclusion.This issue affects WpTravelly: from n/a through <= 1.8.7. | |
| Modificada | Alta (7.5) | 0.98% | — | Wptravelengine WP Travel Engine | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows PHP Local File Inclusion.This issue affects WP Travel Engine: from n/a through <= 6.3.5. | |
| Analizada | Media (6.1) | 0.25% | — | Shinecommerce Traveler | 15/3/2025 | 17/6/2026 | The Traveler theme for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if… | |
| Analizada | Crítica (9.8) | 0.67% | — | Shinecommerce Traveler | 15/3/2025 | 17/6/2026 | The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via the 'hotel_alone_load_more_post' function 'style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any… | |
| Aplazada | Crítica (9.8) | 0.41% | — | Boceksoft Informatics E-travelAI | 5/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Boceksoft Informatics E-Travel allows SQL Injection. This issue affects E-Travel: before 15.12.2024. | |
| Aplazada | Alta (8.8) | 0.76% | — | TravelerAI | 28/2/2025 | 17/6/2026 | The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via shortcodes. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP… | |
| Aplazada | Alta (8.5) | 0.37% | — | Shinetheme Traveler CodeAI | 4/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This issue affects Traveler Code: from n/a through < 3.1.3. | |
| Aplazada | Crítica (9) | 0.38% | — | Shinetheme Traveler CodeAI | 4/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Traveler Code traveler-code.This issue affects Traveler Code: from n/a through < 3.1.2. | |
| Aplazada | Media (5.4) | 0.30% | — | Shinetheme Traveler Layout Essential FOR ElementorAI | 3/2/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in shinetheme Traveler Layout Essential For Elementor traveler-layout-essential-for-elementor.This issue affects Traveler Layout Essential For Elementor: from n/a through < 1.4. | |
| Aplazada | Alta (7.6) | 0.51% | — | Wensolutions WP TravelAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel wp-travel allows SQL Injection.This issue affects WP Travel: from n/a through <= 10.1.3. | |
| Aplazada | Media (5.3) | 0.35% | — | Magepeopleteam WptravellyAI | 15/1/2025 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through <= 1.8.5. | |
| Aplazada | Alta (8.5) | 0.38% | — | Google Maps Travel RouteAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in traveller11 Google Maps Travel Route google-maps-travel-route allows SQL Injection.This issue affects Google Maps Travel Route: from n/a through <= 1.3.1. | |
| Aplazada | Media (6.5) | 0.47% | — | Wensolutions WP TravelAI | 9/1/2025 | 17/6/2026 | The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injection via the 'booking_itinerary' parameter of the 'wptravel_get_booking_data' function in all versions up to, and including, 10.0.0 due to insufficient escaping on the user supplied parameter and lack… | |
| Analizada | Media (5.3) | 0.68% | — | Fabian Travel Management System | 5/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Travel Management System 1.0. This issue affects some unknown processing of the file /enquiry.php. The manipulation of the argument pid/t1/t2/t3/t4/t5/t6/t7 leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Modificada | Alta (8.8) | 0.21% | — | Rarathemes Travel Agency | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in raratheme Travel Agency travel-agency allows Cross Site Request Forgery.This issue affects Travel Agency: from n/a through <= 1.4.9. | |
| Aplazada | Media (4.3) | 0.18% | — | Travel MonsterAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wptravelengine Travel Monster travel-monster allows Cross Site Request Forgery.This issue affects Travel Monster: from n/a through <= 1.1.2. | |
| Aplazada | Alta (7.5) | 0.42% | — | Wensolutions WP TravelAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Travel: from n/a through <= 7.8.0. | |
| Analizada | Media (6.1) | 0.36% | — | Goodlayers Travel Tour | 1/1/2025 | 17/6/2026 | The does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.3) | 0.40% | — | Code-projects Travel Management System | 26/12/2024 | 17/6/2026 | A vulnerability was found in code-projects/projectworlds Travel Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /subcat.php. The manipulation of the argument catid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.45% | — | Code-projects Travel Management System | 26/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Travel Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /package.php. The manipulation of the argument subcatid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.61% | — | Code-projects Travel Management System | 26/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Travel Management System 1.0. It has been classified as critical. This affects an unknown part of the file /detail.php. The manipulation of the argument pid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Alta (8.8) | 0.77% | — | Wptravelengine WP Travel EngineAI | 25/12/2024 | 17/6/2026 | The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.7 via several widgets. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (6.5) | 0.31% | — | Travel BookingAI | 18/12/2024 | 17/6/2026 | The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '__stPartnerCreateServiceRental', 'st_delete_order_item', '_st_partner_approve_booking', 'save_order_item', and '__userDenyEachInfo' functions in all versions up to, and… |