Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
796 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.32% | — | Wpsimplebookingcalendar WP Simple Booking CalendarAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Roland Murg WP Simple Booking Calendar wp-simple-booking-calendar.This issue affects WP Simple Booking Calendar: from n/a through <= 2.0.13. | |
| Aplazada | Media (6.5) | 0.17% | — | George Sexton Wordpress Events Calendar Plugin ConnectdailyAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in George Sexton WordPress Events Calendar Plugin – connectDaily connect-daily-web-calendar allows Stored XSS.This issue affects WordPress Events Calendar Plugin – connectDaily: from n/a through <= 1.5.5. | |
| Aplazada | Alta (7.1) | 0.12% | — | Quick-event-calendarAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Stored XSS.This issue affects Quick Event Calendar: from n/a through <= 1.4.9. | |
| Aplazada | Media (6.5) | 0.21% | — | Jonathanjernigan PIE CalendarAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jonathan Jernigan Pie Calendar pie-calendar allows DOM-Based XSS.This issue affects Pie Calendar: from n/a through <= 1.2.8. | |
| Analizada | Media (4.6) | 0.22% | — | Samsung Calendar | 3/9/2025 | 17/6/2026 | Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across multiple user profiles. | |
| Aplazada | Media (6.4) | 0.20% | — | Booking CalendarAI | 28/8/2025 | 17/6/2026 | The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 10.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject… | |
| Modificada | Alta (7.2) | 0.44% | 💥 PoC | Vcita Online Booking & Scheduling Calendar | 20/8/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Using Malicious Files.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.3. | |
| Aplazada | Media (6.4) | 0.25% | — | Intl Datetime CalendarAI | 16/8/2025 | 17/6/2026 | The Intl DateTime Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Alta (7.5) | 0.76% | — | BizcalendarAI | 15/8/2025 | 17/6/2026 | The BizCalendar Web plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.0.53 via the 'bizcalv' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the… | |
| Modificada | Media (5.4) | 0.22% | — | Vcita Online Booking & Scheduling Calendar | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Stored XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.3. | |
| Aplazada | Media (6.4) | 0.25% | — | Mocca CalendarAIXwikiAI | 3/8/2025 | 17/6/2026 | The Mocca Calendar application before 2.15 for XWiki allows XSS via a title upon calendar import. | |
| Aplazada | Media (6.4) | 0.25% | — | Mocca CalendarAI | 3/8/2025 | 17/6/2026 | The Mocca Calendar application before 2.15 for XWiki allows XSS via a title to the view event page. | |
| Aplazada | Media (6.4) | 0.25% | — | Mocca CalendarAI | 3/8/2025 | 17/6/2026 | The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field. | |
| Aplazada | Crítica (9.8) | 0.39% | — | Joomla Articles CalendarAIJoomlaAI | 18/7/2025 | 17/6/2026 | A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands. | |
| Analizada | Crítica (9.8) | 0.38% | — | Webnus Modern Events Calendar Lite | 12/7/2025 | 17/6/2026 | The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_ajax_mec_load_single_page' AJAX action in all versions up to, and including, 6.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (6.5) | 0.23% | — | Codepeople Booking Calendar Contact FormAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form booking-calendar-contact-form allows Stored XSS.This issue affects Booking Calendar Contact Form: from n/a through <= 1.2.58. | |
| Analizada | Media (4.3) | 0.14% | — | VR Calendar Project VR Calendar | 27/6/2025 | 17/6/2026 | The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.7. This is due to missing or incorrect nonce validation on the syncCalendar() function. This makes it possible for unauthenticated attackers to trigger a calendar sync via a forged request granted… | |
| Aplazada | Media (6.4) | 0.29% | — | Simply Schedule Appointments Appointment Booking CalendarAI | 14/6/2025 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ssa_admin_upcoming_appointments, ssa_admin_upcoming_appointments, and ssa_past_appointments shortcodes in all versions up to, and including, 1.6.8.30 due to… | |
| Analizada | Media (6.5) | 0.23% | — | Joshfabean Bookable Calendar | 13/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Bookable Calendar allows Forceful Browsing.This issue affects Bookable Calendar: from 0.0.0 before 2.2.13. | |
| Aplazada | Alta (8.6) | 0.49% | — | Joomla NO Boss CalendarAI | 13/6/2025 | 17/6/2026 | A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability allows remote authenticated users to execute arbitrary SQL commands via the id_module parameter. | |
| Analizada | Media (5.4) | 0.26% | — | Stellarwp THE Events Calendar | 11/6/2025 | 17/6/2026 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-date-*’ parameters in all versions up to, and including, 6.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (6.5) | 0.25% | — | Coolhappy Countdown FOR THE Events CalendarAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CoolHappy The Events Calendar Countdown Addon countdown-for-the-events-calendar allows Stored XSS.This issue affects The Events Calendar Countdown Addon: from n/a through <= 1.4.9. | |
| Aplazada | Media (6.5) | 0.25% | — | Theholidaycalendar The-holiday-calendarAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mva7 The Holiday Calendar the-holiday-calendar allows Stored XSS.This issue affects The Holiday Calendar: from n/a through <= 1.18.2.1. | |
| Aplazada | Alta (7.1) | 0.14% | — | Vadim Bogaiskov BG Orthodox CalendarAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Vadim Bogaiskov Bg Orthodox Calendar bg-orthodox-calendar allows Stored XSS.This issue affects Bg Orthodox Calendar: from n/a through <= 0.13.10. | |
| Aplazada | Media (4.3) | 0.16% | — | Quick-event-calendarAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Cross Site Request Forgery.This issue affects Quick Event Calendar: from n/a through <= 1.4.9. |