Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2533▼ 411 respecto a la semana anterior
Críticas / altas1305▲ 22 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
1442 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.3) | — | — | Arraytics WP Event SolutionAI | 5/10/2026 | 5/10/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP Event Solution: from n/a through 4.1.25. | |
| Recibida | Media (5.3) | — | — | Arraytics WP Event SolutionAI | 5/10/2026 | 5/10/2026 | Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through 4.1.25. | |
| Recibida | Media (5.3) | 0.20% | — | Pixelite Events ManagerAI | 5/10/2026 | 5/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Pixelite Events Manager events-manager allows Retrieve Embedded Sensitive Data.This issue affects Events Manager: from n/a through 7.4.5. | |
| Recibida | Media (4.3) | 0.17% | — | Stellarwp Event TicketsAI | 5/10/2026 | 5/10/2026 | Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0. | |
| Aplazada | Media (6.5) | 0.28% | — | Eventtickets Event Tickets AND RegistrationAI | 2/10/2026 | 2/10/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.22% | — | Theeventscalendar THE Events CalendarAI | 2/10/2026 | 2/10/2026 | The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. | |
| Aplazada | Alta (8.5) | 0.25% | — | Event TicketsAI | 30/9/2026 | 2/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Blind SQL Injection.This issue affects Event Tickets: from n/a through 5.29.5. | |
| Aplazada | Media (5.4) | 0.20% | — | Theeventscalendar THE Events CalendarAI | 30/9/2026 | 30/9/2026 | Contributor Broken Access Control in The Events Calendar <= 6.17.5 versions. | |
| Aplazada | Media (4.3) | 0.21% | — | Prevent Files Folders AccessAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions. | |
| Pendiente de análisis | Alta (7.5) | 0.31% | — | Wikimedia EventbusAI | 29/9/2026 | 30/9/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - EventBus Extension allows Excavation. This issue affects Mediawiki - EventBus Extension: 1.47.0-alpha. | |
| En análisis | Media (5.3) | 0.24% | — | Event GalleryAI | 27/9/2026 | 30/9/2026 | Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to the “Back” link without being validated. | |
| En análisis | Alta (7) | 0.31% | — | Svenbluege Event GalleryAI | 27/9/2026 | 29/9/2026 | Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extension < 6.5.0 - Using the `images` parameter of the `cache.process` task, you can recursively delete any directories that the web server is authorized to write to. | |
| En análisis | Media (5.1) | 0.15% | — | Svenbluege Event GalleryAI | 27/9/2026 | 30/9/2026 | Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned file entries and shopping carts that are older than 30 days will be deleted. | |
| En análisis | Media (6.9) | 0.15% | — | Svenbluege Event GalleryAI | 27/9/2026 | 29/9/2026 | Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 | |
| En análisis | Media (5.1) | 0.15% | — | Svenbluege Event GalleryAI | 27/9/2026 | 30/9/2026 | Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF token check, a third-party site can upload files to an event and overwrite existing files with the same name. | |
| Pendiente de análisis | Media (5.3) | 0.97% | — | Zoho Eventlog AnalyzerAIZoho Log360AI | 24/9/2026 | 24/9/2026 | ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets. | |
| Aplazada | Media (4.3) | 0.18% | — | Events ManagerAI | 24/9/2026 | 24/9/2026 | The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner value, letting a low-privileged user read other accounts' unpublished, pending or trashed event and venue content, including full street addresses. | |
| Aplazada | Baja (2.7) | 0.17% | — | Events ManagerAI | 24/9/2026 | 24/9/2026 | The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event. | |
| Aplazada | Alta (7.1) | 0.18% | — | Event TicketsAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions. | |
| Aplazada | Baja (2.7) | 0.18% | — | Event Booking ManagerAI | 23/9/2026 | 23/9/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard… | |
| Aplazada | Baja (3.8) | 0.23% | — | Theeventscalendar THE Events CalendarAI | 23/9/2026 | 23/9/2026 | The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its REST write routes, allowing users with a low-privilege role such as contributor to modify, unpublish, trash and take ownership of records belonging to other users, including administrators. | |
| Aplazada | Baja (2.7) | 0.23% | — | Modern Tribe THE Events CalendarAI | 23/9/2026 | 23/9/2026 | The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before creating or updating it through its REST API, allowing users with a role that cannot normally publish, such as contributor, to publish content directly and bypass editorial review. | |
| Aplazada | Media (5.3) | 0.25% | — | Theeventscalendar THE Events CalendarAI | 23/9/2026 | 23/9/2026 | The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST API response, allowing unauthenticated users to read the contents of records that have never been published. | |
| Aplazada | Media (4.9) | 0.38% | — | Event Booking ManagerAI | 17/9/2026 | 18/9/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys. | |
| Aplazada | Baja (3.7) | 0.26% | — | Event Booking Manager FOR WoocommerceAI | 17/9/2026 | 18/9/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom… |