Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2628▼ 312 respecto a la semana anterior
Críticas / altas1351▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.43% | — | Xnau Participants DatabaseAI | 13/8/2026 | 14/8/2026 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions. | |
| Aplazada | Crítica (9.1) | 0.46% | — | Xnau Participants DatabaseAI | 1/8/2026 | 26/8/2026 | The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. | |
| Aplazada | Media (5.3) | 0.42% | — | Xnau Participants DatabaseAI | 24/7/2026 | 24/7/2026 | The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing… | |
| Aplazada | Crítica (10) | 0.60% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. | |
| Aplazada | Media (6.5) | 0.21% | — | Xnau Participants DatabaseAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xnau webdesign Participants Database participants-database allows Stored XSS.This issue affects Participants Database: from n/a through <= 2.7.6.3. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Xnau Participants DatabaseAI | 13/8/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2. | |
| Modificada | Alta (8.8) | 0.25% | — | Xnau Participants Database | 19/12/2023 | 17/6/2026 | Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database allows Accessing Functionality Not Properly Constrained by ACLs, Cross Site Request Forgery.This issue affects Participants Database: from n/a through 2.5.5. | |
| Modificada | Alta (8.8) | 0.34% | — | Xnau Participants Database | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.9 versions. | |
| Modificada | Media (4.3) | 0.23% | — | Xnau Participants Database | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.5 leads to list column update. | |
| Modificada | Alta (7.5) | 1.6% | — | Xnau Participants Database | 11/2/2020 | 17/6/2026 | participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_count, or sortBy parameters. It is possible to exfiltrate data and potentially execute code (if certain conditions are met). | |
| Modificada | Media (6.1) | 2.3% | — | Xnau Participants Database | 4/9/2017 | 17/6/2026 | The Participants Database plugin before 1.7.5.10 for WordPress has XSS. | |
| Modificada | Alta (7.5) | 5.6% | — | Xnau Participants Database | 4/6/2014 | 17/6/2026 | SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/. |