Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2533▼ 405 respecto a la semana anterior
Críticas / altas1319▲ 38 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.6% | — | Cththemes CitybookCththemes EasybookCththemes Townhub | 13/1/2020 | 17/6/2026 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form. | |
| Modificada | Media (6.1) | 2.6% | — | Cththemes CitybookCththemes EasybookCththemes Townhub | 13/1/2020 | 17/6/2026 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address, Latitude, Longitude, Phone Number, or Website. | |
| Modificada | Media (6.1) | 3.2% | — | Cththemes CitybookCththemes EasybookCththemes Townhub | 13/1/2020 | 17/6/2026 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query. | |
| Modificada | Alta (7.5) | 3.2% | — | Cththemes CitybookCththemes EasybookCththemes Townhub | 13/1/2020 | 17/6/2026 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing. | |
| Modificada | Media (4.3) | 1.6% | — | Wp-easybooking Plugin Project Wp-easybooking | 1/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in admin/editFacility.php in the wp-easybooking plugin 1.0.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the fID parameter. | |
| Modificada | Alta (7.5) | 0.91% | — | Myiosoft Easybookmarker | 17/12/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified vectors, possibly to (a) plugins/bookmarker/bookmarker_backend.php or (b) ajaxp.php, different vectors than… | |
| Modificada | Alta (7.5) | 1.2% | — | Myiosoft Easybookmarker | 17/12/2008 | 16/6/2026 | SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.3% | — | Myiosoft Easybookmarker | 17/12/2008 | 16/6/2026 | SQL injection vulnerability in plugins/bookmarker/bookmarker_backend.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the Parent parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Myiosoft Easybookmarker | 30/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ajaxp_backend.php in MyioSoft EasyBookMarker 4.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the rs parameter. | |
| Modificada | Alta (7.5) | 1.00% | — | Joomla Easybook Component | 6/6/2008 | 16/6/2026 | SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a deleteentry action to index.php. |