Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.33%—Liquidweb WpcompleteAI19/9/202621/9/2026
The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all versions up to, and including, 2.9.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
AplazadaCrítica (10)2.3%—Stellarwp GivewpAILiquidweb GivewpAI28/8/202628/8/2026
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.
AplazadaAlta (7.1)0.25%—Liquidweb WpcompleteAI24/8/202624/8/2026
Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.
AplazadaMedia (5.4)0.29%—Liquidweb WpcompleteAI26/6/202626/6/2026
Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
AplazadaAlta (7.5)0.48%—Stellarwp BookitAILiquidweb BookitAI2/6/202622/7/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation. This issue affects BookIt: from n/a before 2.5.4.1.
AplazadaMedia (6.5)0.22%—Liquidweb WpcompleteAI27/5/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nexcess WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through <= 2.9.5.4.
AnalizadaAlta (7.5)0.46%—Liquidweb Restrict Content16/1/202617/6/2026
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup_intent_for_saved_card' function due to missing capability check. Additionally, the plugin does not check a user-controlled key, which makes…
AnalizadaMedia (5.3)0.32%—Liquidweb Event Tickets30/1/202517/6/2026
The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view order details of orders…
AnalizadaAlta (7.5)0.46%—Liquidweb Restrict Content26/1/202517/6/2026
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to…
AnalizadaMedia (4.3)0.46%—Liquidweb Event Tickets4/3/202417/6/2026
The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).
AnalizadaMedia (6.5)0.60%—Liquidweb Event Tickets4/3/202417/6/2026
The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed…
ModificadaMedia (4.3)0.39%—Liquidweb Event Tickets22/2/202417/6/2026
The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action in all versions up to, and including, 5.8.1. This makes it possible for authenticated attackers, with contributor-level access and above, to email the attendees…
ModificadaAlta (7.5)1.0%—Liquidweb Restrict Content23/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions.
ModificadaAlta (7.5)0.69%—Idattend Idweb25/10/202317/6/2026
Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
ModificadaAlta (7.5)0.69%—Idattend Idweb25/10/202317/6/2026
Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
ModificadaAlta (7.5)0.69%—Idattend Idweb25/10/202317/6/2026
Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attackers.
ModificadaCrítica (9.1)0.76%—Idattend Idweb25/10/202317/6/2026
Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.
ModificadaMedia (6.5)0.53%—Idattend Idweb25/10/202317/6/2026
Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allows deletion of data by unauthenticated attackers.
ModificadaCrítica (9.1)0.55%—Idattend Idweb25/10/202317/6/2026
Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.
ModificadaAlta (7.5)0.51%—Idattend Idweb25/10/202317/6/2026
Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student and teacher data by unauthenticated attackers.
ModificadaAlta (7.5)0.51%—Idattend Idweb25/10/202317/6/2026
Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student and teacher data by unauthenticated attackers.
ModificadaAlta (7.5)0.69%—Idattend Idweb25/10/202317/6/2026
Missing authentication in the GetActiveToiletPasses method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student information by unauthenticated attackers.
ModificadaMedia (5.3)0.56%—Idattend Idweb25/10/202317/6/2026
Missing authentication in the GetLogFiles method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of sensitive log files by unauthenticated attackers.
ModificadaCrítica (9.1)0.76%—Idattend Idweb25/10/202317/6/2026
Unauthenticated SQL injection in the DeleteRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.
ModificadaCrítica (9.1)0.76%—Idattend Idweb25/10/202317/6/2026
Unauthenticated SQL injection in the GetRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.