Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

33 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.17%—Stellarwp Event TicketsAI5/10/20266/10/2026
Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0.
AplazadaMedia (6.5)0.28%—Eventtickets Event Tickets AND RegistrationAI2/10/20262/10/2026
The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaAlta (8.5)0.25%—Event TicketsAI30/9/20262/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Blind SQL Injection.This issue affects Event Tickets: from n/a through 5.29.5.
AplazadaAlta (7.1)0.18%—Event TicketsAI23/9/202623/9/2026
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.
AplazadaAlta (7.5)0.47%—Eventbrite Event TicketsAI8/9/20269/9/2026
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant…
AplazadaAlta (7.1)0.25%—Event TicketsAI24/8/202626/8/2026
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
AplazadaBaja (2.2)0.23%—Event Tickets AND RegistrationAI1/8/202626/8/2026
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own.
AplazadaMedia (5.3)0.30%—Eventbrite Event TicketsAI1/8/202626/8/2026
The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders.
AplazadaBaja (3.5)0.24%—Eventtickets Event TicketsAI28/7/202628/7/2026
The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations.
AplazadaMedia (5.3)0.29%—Event TicketsAI27/7/202627/7/2026
Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.
AplazadaAlta (7.5)0.35%—Nexcess Event TicketsAI13/7/202613/7/2026
Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5.
AplazadaMedia (6.5)0.33%—Wpswings Event Tickets Manager FOR WoocommerceAI13/7/202613/7/2026
Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5.
AplazadaMedia (6.5)0.36%—Event TicketsAI15/6/202617/6/2026
Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions.
AplazadaAlta (7.5)0.35%—Event Tickets ManagerAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.
AplazadaCrítica (9)0.37%—Vollstart Event Tickets With Ticket ScannerAI22/1/202617/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.5.
AplazadaMedia (5.4)0.22%—Stellarwp Event TicketsAI22/10/202517/6/2026
Missing Authorization vulnerability in StellarWP Event Tickets event-tickets.This issue affects Event Tickets: from n/a through <= 5.26.3.
AplazadaAlta (7.5)0.40%—Event Tickets AND RegistrationAI18/10/202517/6/2026
The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to the /wp-json/tribe/tickets/v1/commerce/free/order endpoint not verifying that a ticket type should be free allowing the user to bypass the payment. This makes it possible…
AplazadaMedia (6.4)0.24%—Event Tickets Rsvps CalendarAI3/10/202517/6/2026
The Event Tickets, RSVPs, Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ticket_spot' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
ModificadaBaja (3.5)0.32%—Vollstart Event Tickets With Ticket Scanner15/5/202517/6/2026
The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks
AplazadaAlta (7.1)0.31%—Stellarwp Event TicketsAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Event Tickets event-tickets allows Reflected XSS.This issue affects Event Tickets: from n/a through <= 5.20.0.
AnalizadaMedia (4.3)0.17%—Vollstart Event Tickets With Ticket Scanner28/3/202517/6/2026
The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
AnalizadaMedia (5.3)0.45%—Theeventscalendar Event Tickets21/2/202517/6/2026
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AnalizadaMedia (5.3)0.32%—Liquidweb Event Tickets30/1/202517/6/2026
The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view order details of orders…
AplazadaMedia (4.3)0.19%—Stellarwp Event TicketsAI2/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in StellarWP Event Tickets event-tickets allows Cross Site Request Forgery.This issue affects Event Tickets: from n/a through <= 5.11.0.4.
AplazadaMedia (5.4)0.31%—Vollstart Event Tickets With Ticket ScannerAI6/12/202417/6/2026
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping and missing authorization on the functionality to manage tickets. This makes it…