Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1447 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.43% | — | EventprimeAI | 9/7/2026 | 9/7/2026 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_background_color' parameter in all versions up to, and including, 4.3.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (7.5) | 0.46% | — | Imithemes EventerAI | 8/7/2026 | 8/7/2026 | The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Imithemes EventerAI | 8/7/2026 | 8/7/2026 | The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of the password reset key in the `eventer_verification_code` user meta field when a user requests a password reset. The plaintext key stored in… | |
| Aplazada | Media (6.4) | 0.26% | — | Event OrganiserAI | 1/7/2026 | 1/7/2026 | The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.12.9. This is due to the 'eo_events' shortcode accepting attacker-controlled 'no_events' content and rendering it in event list templates without output escaping. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.54% | — | Myeventon EventonAI | 30/6/2026 | 30/6/2026 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and including, 5.0.11 due to insufficient escaping on the user supplied parameter and lack of preparation on the existing SQL query. This makes it… | |
| Aplazada | Alta (8.3) | 0.43% | — | Hi.eventsAI | 29/6/2026 | 14/7/2026 | Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal information. Attackers with knowledge of the short_id can call GET /api/public/check-in-lists/{short_id}/attendees to read attendee… | |
| Aplazada | Alta (8.2) | 0.26% | — | HI EventsAI | 29/6/2026 | 14/7/2026 | Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStatisticsJob increments it, allowing attackers to redeem limited promo codes unlimited times. Attackers can sequentially reserve multiple orders with the same restricted promo… | |
| Aplazada | Alta (8.8) | 0.52% | — | EventprimeAI | 25/6/2026 | 26/6/2026 | Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions. | |
| Aplazada | Media (4.3) | 0.13% | — | Book A Room Event CalendarAI | 24/6/2026 | 25/6/2026 | The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorrect nonce validation on the settings_form()/update_settings() functionality. The plugin's options page handler dispatches on the 'action' POST… | |
| Pendiente de análisis | Crítica (9.6) | 0.53% | — | Event Driven AnsibleAI | 23/6/2026 | 16/7/2026 | A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive plaintext credentials… | |
| Analizada | Alta (8.8) | 0.43% | — | Joomalshowroom Event Registration PRO Calendar | 19/6/2026 | 21/8/2026 | Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_registrationpro&view=category&id parameter… | |
| Aplazada | Media (5.3) | 0.31% | — | Event KOI LiteAI | 18/6/2026 | 18/6/2026 | The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.13.1 via the get_events. This makes it possible for unauthenticated attackers to extract sensitive data including virtual meeting… | |
| Aplazada | Alta (8.1) | 0.35% | — | EventicityAI | 17/6/2026 | 6/10/2026 | Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions. | |
| Aplazada | Alta (8.5) | 0.34% | — | Theeventscalendar THE Events CalendarAI | 17/6/2026 | 6/10/2026 | Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions. | |
| Aplazada | Crítica (9.3) | 0.45% | 💥 PoC | Stellarwp THE Events CalendarAI | 16/6/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2. | |
| Aplazada | Alta (7.5) | 0.22% | — | WP Event SolutionAI | 16/6/2026 | 7/10/2026 | Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions. | |
| Aplazada | Alta (7.5) | 0.37% | — | WpeventlyAI | 15/6/2026 | 17/6/2026 | Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions. | |
| Aplazada | Alta (8.1) | 0.44% | — | EventprimeAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions. | |
| Aplazada | Alta (7.1) | 0.38% | — | EventprimeAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2.1 versions. | |
| Aplazada | Media (6.5) | 0.36% | — | Event TicketsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions. | |
| Aplazada | Alta (7.5) | 0.39% | 💥 PoC | Wpevent WP Event SolutionAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions. | |
| Aplazada | Alta (8.8) | 0.52% | — | Geodir Events CalendarAIPHPAI | 15/6/2026 | 17/6/2026 | Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions. | |
| Aplazada | Alta (7.1) | 0.29% | — | EventprimeAI | 15/6/2026 | 17/6/2026 | Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Event Tickets ManagerAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions. | |
| Aplazada | Media (4.3) | 0.10% | — | Magepeople WpeventlyAI | 11/6/2026 | 23/7/2026 | Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This issue affects WpEvently: from n/a through 4.1.2. |