Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2616▼ 309 respecto a la semana anterior
Críticas / altas1342▲ 71 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.40% | — | Typo3AITypo3 Event RegistrationAI | 25/8/2026 | 26/8/2026 | The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or execute TypoScript content objects.… | |
| Analizada | Alta (8.8) | 0.43% | — | Joomalshowroom Event Registration PRO Calendar | 19/6/2026 | 21/8/2026 | Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_registrationpro&view=category&id parameter… | |
| Aplazada | Media (6.4) | 0.34% | — | Vcita Event Registration CalendarAI | 15/1/2025 | 17/6/2026 | The Event Registration Calendar By vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Media (6.9) | 0.61% | — | Oretnom23 Event Registration System | 20/5/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Event Registration System 1.0. This affects an unknown part of the file /registrar/. The manipulation of the argument searchbar leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.71% | — | Oretnom23 Event Registration System | 20/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Event Registration System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registrar/. The manipulation of the argument search leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.43% | — | Oretnom23 Event Registration System | 20/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Event Registration System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /registrar/?page=registration. The manipulation of the argument e leads to cross site scripting. The attack can be launched remotely.… | |
| Analizada | Media (5.3) | 0.58% | — | Oretnom23 Event Registration System | 20/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Event Registration System 1.0. It has been classified as critical. Affected is an unknown function of the file /registrar/?page=registration. The manipulation of the argument e leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.58% | — | Oretnom23 Event Registration System | 20/5/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Event Registration System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Master.php?f=load_registration. The manipulation of the argument last_id/event_id leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Media (6.9) | 0.75% | — | Oretnom23 Event Registration System | 20/5/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.68% | — | Oretnom23 Event Registration System | 20/5/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. This affects an unknown part of the file portal.php. The manipulation of the argument username/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.5) | 0.42% | — | Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe | 3/6/2023 | 17/6/2026 | The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function. This makes it possible… | |
| Modificada | Media (5.4) | 0.76% | — | Event Registration Calendar BY VcitaVcita Online Payments - GET Paid With Paypal, Square & Stripe | 3/6/2023 | 17/6/2026 | The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 1.3.1 due to insufficient input sanitization… | |
| Modificada | Media (6.1) | 0.36% | — | Rinvizle Event Registration System | 30/11/2022 | 17/6/2026 | A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /event/admin/?page=user/list. The manipulation of the argument First Name/Last Name leads to cross site scripting. The attack can be… | |
| Modificada | Crítica (9.8) | 0.47% | — | Rinvizle Event Registration System | 30/11/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected is an unknown function. The manipulation of the argument cmd leads to unrestricted upload. It is possible to launch the attack remotely. VDB-214590 is the identifier assigned to this vulnerability. | |
| Modificada | Alta (7.8) | 0.58% | — | Event Registration Application Project Event Registration Application | 21/11/2022 | 17/6/2026 | Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file. | |
| Modificada | Alta (7.5) | 2.7% | — | Edgetechweb Event Registration | 14/9/2011 | 16/6/2026 | SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the event_id parameter in a register action. | |
| Modificada | Alta (7.5) | 1.3% | — | Codewidgets Online Event Registration Template | 29/10/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in CodeWidgets.com Online Event Registration Template allow remote attackers to execute arbitrary SQL commands via the (1) Email Address and (2) Password fields in (a) login.asp and (b) admin_login.asp. | |
| Modificada | Alta (7.5) | 1.3% | — | Codewidgets Online Event Registration Template | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in sign_in.aspx in WebEvents (Online Event Registration Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Codewidgets Online Event Registration Template | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in sign_in.aspx in WebStore (Online Store Application Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Media (5) | 1.0% | — | Webevents Online Event Registration | 21/11/2006 | 16/6/2026 | save_profile.asp in WebEvents (Online Event Registration Template) 2.0 and earlier allows remote attackers to change the profiles, passwords, and other information for arbitrary users via a modified UserID parameter. | |
| Modificada | Media (6.8) | 1.8% | — | Cescripts Event Registration 2checkoutCescripts Event Registration CorporateCescripts Event Registration PaypalCescripts Event Registration Rsvp | 16/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Event Registration allows remote attackers to inject arbitrary web script or HTML via the (1) event_id parameter to view-event-details.php or (2) select_events parameter to event-registration.php. NOTE: the provenance of this information is unknown; the details are obtained… |