Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1447 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.43%—EventprimeAI9/7/20269/7/2026
The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_background_color' parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaAlta (7.5)0.46%—Imithemes EventerAI8/7/20268/7/2026
The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers…
AplazadaCrítica (9.8)0.48%—Imithemes EventerAI8/7/20268/7/2026
The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the `eventer_verification_code` user meta field when a user requests a password reset. The plaintext key stored in…
AplazadaMedia (6.4)0.26%—Event OrganiserAI1/7/20261/7/2026
The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.12.9. This is due to the 'eo_events' shortcode accepting attacker-controlled 'no_events' content and rendering it in event list templates without output escaping. This makes it possible for…
AplazadaCrítica (9.8)0.54%—Myeventon EventonAI30/6/202630/6/2026
The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient escaping on the user supplied parameter and lack of preparation on the existing SQL query. This makes it…
AplazadaAlta (8.3)0.43%—Hi.eventsAI29/6/202614/7/2026
Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal information. Attackers with knowledge of the short_id can call GET /api/public/check-in-lists/{short_id}/attendees to read attendee…
AplazadaAlta (8.2)0.26%—HI EventsAI29/6/202614/7/2026
Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStatisticsJob increments it, allowing attackers to redeem limited promo codes unlimited times. Attackers can sequentially reserve multiple orders with the same restricted promo…
AplazadaAlta (8.8)0.52%—EventprimeAI25/6/202626/6/2026
Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
AplazadaMedia (4.3)0.13%—Book A Room Event CalendarAI24/6/202625/6/2026
The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorrect nonce validation on the settings_form()/update_settings() functionality. The plugin's options page handler dispatches on the 'action' POST…
Pendiente de análisisCrítica (9.6)0.53%—Event Driven AnsibleAI23/6/202616/7/2026
A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive plaintext credentials…
AnalizadaAlta (8.8)0.43%—Joomalshowroom Event Registration PRO Calendar19/6/202621/8/2026
Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_registrationpro&view=category&id parameter…
AplazadaMedia (5.3)0.31%—Event KOI LiteAI18/6/202618/6/2026
The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.13.1 via the get_events. This makes it possible for unauthenticated attackers to extract sensitive data including virtual meeting…
AplazadaAlta (8.1)0.35%—EventicityAI17/6/20266/10/2026
Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.
AplazadaAlta (8.5)0.34%—Theeventscalendar THE Events CalendarAI17/6/20266/10/2026
Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.
AplazadaCrítica (9.3)0.45%💥 PoCStellarwp THE Events CalendarAI16/6/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.
AplazadaAlta (7.5)0.22%—WP Event SolutionAI16/6/20267/10/2026
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
AplazadaAlta (7.5)0.37%—WpeventlyAI15/6/202617/6/2026
Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.
AplazadaAlta (8.1)0.44%—EventprimeAI15/6/202617/6/2026
Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.
AplazadaAlta (7.1)0.38%—EventprimeAI15/6/202617/6/2026
Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2.1 versions.
AplazadaMedia (6.5)0.36%—Event TicketsAI15/6/202617/6/2026
Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions.
AplazadaAlta (7.5)0.39%💥 PoCWpevent WP Event SolutionAI15/6/202617/6/2026
Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.
AplazadaAlta (8.8)0.52%—Geodir Events CalendarAIPHPAI15/6/202617/6/2026
Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
AplazadaAlta (7.1)0.29%—EventprimeAI15/6/202617/6/2026
Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions.
AplazadaAlta (7.5)0.35%—Event Tickets ManagerAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.
AplazadaMedia (4.3)0.10%—Magepeople WpeventlyAI11/6/202623/7/2026
Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This issue affects WpEvently: from n/a through 4.1.2.