Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.17% | — | Stellarwp Event TicketsAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through 5.30.0. | |
| Aplazada | Media (6.5) | 0.28% | — | Eventtickets Event Tickets AND RegistrationAI | 2/10/2026 | 2/10/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (8.5) | 0.25% | — | Event TicketsAI | 30/9/2026 | 2/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Blind SQL Injection.This issue affects Event Tickets: from n/a through 5.29.5. | |
| Aplazada | Alta (7.1) | 0.18% | — | Event TicketsAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions. | |
| Aplazada | Alta (7.5) | 0.47% | — | Eventbrite Event TicketsAI | 8/9/2026 | 9/9/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant… | |
| Aplazada | Alta (7.1) | 0.25% | — | Event TicketsAI | 24/8/2026 | 26/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions. | |
| Aplazada | Baja (2.2) | 0.23% | — | Event Tickets AND RegistrationAI | 1/8/2026 | 26/8/2026 | The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own. | |
| Aplazada | Media (5.3) | 0.30% | — | Eventbrite Event TicketsAI | 1/8/2026 | 26/8/2026 | The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders. | |
| Aplazada | Baja (3.5) | 0.24% | — | Eventtickets Event TicketsAI | 28/7/2026 | 28/7/2026 | The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations. | |
| Aplazada | Media (5.3) | 0.29% | — | Event TicketsAI | 27/7/2026 | 27/7/2026 | Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Nexcess Event TicketsAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5. | |
| Aplazada | Media (6.5) | 0.33% | — | Wpswings Event Tickets Manager FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5. | |
| Aplazada | Media (6.5) | 0.36% | — | Event TicketsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Event Tickets ManagerAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions. | |
| Aplazada | Crítica (9) | 0.37% | — | Vollstart Event Tickets With Ticket ScannerAI | 22/1/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Code Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.8.5. | |
| Aplazada | Media (5.4) | 0.22% | — | Stellarwp Event TicketsAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in StellarWP Event Tickets event-tickets.This issue affects Event Tickets: from n/a through <= 5.26.3. | |
| Aplazada | Alta (7.5) | 0.40% | — | Event Tickets AND RegistrationAI | 18/10/2025 | 17/6/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.26.5. This is due to the /wp-json/tribe/tickets/v1/commerce/free/order endpoint not verifying that a ticket type should be free allowing the user to bypass the payment. This makes it possible… | |
| Aplazada | Media (6.4) | 0.24% | — | Event Tickets Rsvps CalendarAI | 3/10/2025 | 17/6/2026 | The Event Tickets, RSVPs, Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ticket_spot' shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Baja (3.5) | 0.32% | — | Vollstart Event Tickets With Ticket Scanner | 15/5/2025 | 17/6/2026 | The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks | |
| Aplazada | Alta (7.1) | 0.31% | — | Stellarwp Event TicketsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Event Tickets event-tickets allows Reflected XSS.This issue affects Event Tickets: from n/a through <= 5.20.0. | |
| Analizada | Media (4.3) | 0.17% | — | Vollstart Event Tickets With Ticket Scanner | 28/3/2025 | 17/6/2026 | The Event Tickets with Ticket Scanner WordPress plugin before 2.5.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Media (5.3) | 0.45% | — | Theeventscalendar Event Tickets | 21/2/2025 | 17/6/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'ajax_ticket_delete' function in all versions up to, and including, 5.19.1.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Media (5.3) | 0.32% | — | Liquidweb Event Tickets | 30/1/2025 | 17/6/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view order details of orders… | |
| Aplazada | Media (4.3) | 0.19% | — | Stellarwp Event TicketsAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in StellarWP Event Tickets event-tickets allows Cross Site Request Forgery.This issue affects Event Tickets: from n/a through <= 5.11.0.4. | |
| Aplazada | Media (5.4) | 0.31% | — | Vollstart Event Tickets With Ticket ScannerAI | 6/12/2024 | 17/6/2026 | The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping and missing authorization on the functionality to manage tickets. This makes it… |