Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.33%—WpeventlyAI8/9/20268/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.
AplazadaMedia (4.3)0.27%—WpeventlyAI28/8/202628/8/2026
Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.
AplazadaMedia (5.4)0.29%—WpeventlyAI28/8/202628/8/2026
Contributor Broken Access Control in WpEvently <= 5.5.0 versions.
AplazadaAlta (7.5)0.37%—WpeventlyAI15/6/202617/6/2026
Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.
AplazadaMedia (4.3)0.10%—Magepeople WpeventlyAI11/6/202623/7/2026
Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery. This issue affects WpEvently: from n/a through 4.1.2.
AplazadaAlta (7.1)0.18%—Magepeopleteam WpeventlyAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpEvently mage-eventpress allows Reflected XSS.This issue affects WpEvently: from n/a through <= 5.1.4.
AplazadaMedia (5.3)0.33%—Magepeopleteam WpeventlyAIMagepeopleteam Mage-eventpressAI13/3/202617/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Retrieve Embedded Sensitive Data.This issue affects WpEvently: from n/a through < 5.1.9.
AplazadaAlta (8.1)0.52%—Mikado-themes EventlyAIPHPAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Evently evently allows PHP Local File Inclusion.This issue affects Evently: from n/a through <= 1.7.
AplazadaCrítica (9.8)0.39%—Magepeopleteam WpeventlyAI19/2/202617/6/2026
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.1.1.
AplazadaAlta (8.8)0.42%—Magepeopleteam WpeventlyAI3/2/202617/6/2026
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.0.8.
AplazadaMedia (4.3)0.13%—Magepeopleteam WpeventlyAIMagepeopleteam Mage-eventpressAI3/2/202617/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam WpEvently mage-eventpress allows Cross Site Request Forgery.This issue affects WpEvently: from n/a through <= 5.1.1.
AplazadaMedia (5.3)0.25%—Magepeopleteam WP EventlyAI21/11/202517/6/2026
Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.
AplazadaMedia (5.3)0.26%—Magepeopleteam WP EventlyAIMagepeopleteam Mage EventpressAI21/11/202517/6/2026
Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 5.0.4.
AplazadaAlta (8.8)0.37%—Magepeopleteam WP EventlyAI28/8/202525/9/2026
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 4.4.8.
AplazadaMedia (4.3)0.25%—Magepeopleteam WpeventlyAI14/8/202517/6/2026
Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 4.4.6.
AplazadaAlta (8.8)0.48%—Magepeopleteam WpeventlyAI10/4/202517/6/2026
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 4.3.6.
AplazadaAlta (7.5)0.81%—Magepeopleteam WpeventlyAI27/3/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in magepeopleteam WpEvently mage-eventpress allows PHP Local File Inclusion.This issue affects WpEvently: from n/a through <= 4.2.9.
AplazadaMedia (5.3)0.37%—Magepeopleteam WP EventlyAI27/3/202517/6/2026
Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 4.2.9.
AplazadaMedia (6.5)0.26%—Magepeopleteam WpeventlyAI24/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpEvently mage-eventpress.This issue affects WpEvently: from n/a through <= 4.2.5.