Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.41% | — | Joedolson MY TicketsAI | 25/3/2026 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Joe Dolson My Tickets my-tickets allows Identity Spoofing.This issue affects My Tickets: from n/a through <= 2.1.1. | |
| Aplazada | Alta (7.5) | 0.43% | — | Joedolson MY TicketsAI | 5/3/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Joe Dolson My Tickets my-tickets allows Retrieve Embedded Sensitive Data.This issue affects My Tickets: from n/a through <= 2.1.0. | |
| Aplazada | Media (4.3) | 0.23% | — | Joedolson MY TicketsAI | 9/12/2025 | 5/10/2026 | Missing Authorization vulnerability in Joe Dolson My Tickets my-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Tickets: from n/a through <= 2.1.0. | |
| Aplazada | Media (6.5) | 0.17% | — | Joedolson MY TicketsAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joe Dolson My Tickets my-tickets allows Stored XSS.This issue affects My Tickets: from n/a through <= 2.0.22. | |
| Aplazada | Alta (8.8) | 0.38% | — | MY TicketsAI | 24/4/2025 | 17/6/2026 | The My Tickets – Accessible Event Ticketing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.16. This is due to the mt_save_profile() function not appropriately restricting access to unauthorized users to update roles. This makes it possible for authenticated… | |
| Aplazada | Alta (7.5) | 0.40% | — | Joedolson MY TicketsAI | 21/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Joe Dolson My Tickets my-tickets allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects My Tickets: from n/a through <= 2.0.9. | |
| Aplazada | Alta (7.5) | 0.68% | — | Joseph C Dolson MY TicketsAI | 17/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Joseph C Dolson My Tickets.This issue affects My Tickets: from n/a through 1.9.11. | |
| Modificada | Alta (8.8) | 0.28% | — | MY Tickets Project MY Tickets | 13/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Tickets plugin <= 1.9.10 versions. | |
| Modificada | Media (6.1) | 1.2% | — | MY Tickets Project MY Tickets | 17/11/2021 | 17/6/2026 | The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets before outputting it in the Payment admin dashboard, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins |