Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.52% | — | Carrcommunications RsvpmakerAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMarker rsvpmaker allows SQL Injection.This issue affects RSVPMarker : from n/a through <= 11.6.7. | |
| Aplazada | Media (5.3) | 0.29% | — | Carrcommunications RsvpmakerAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in davidfcarr RSVPMarker rsvpmaker.This issue affects RSVPMarker : from n/a through <= 11.4.5. | |
| Aplazada | Alta (7.1) | 0.28% | — | Davidfcarr Rsvpmaker Volunteer RolesAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in davidfcarr RSVPMaker Volunteer Roles rsvpmaker-volunteer-roles allows Reflected XSS.This issue affects RSVPMaker Volunteer Roles: from n/a through <= 1.5.1. | |
| Modificada | Crítica (9.8) | 0.51% | — | Carrcommunications Rsvpmaker | 4/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toastmasters allows Upload a Web Shell to a Web Server.This issue affects RSVPMaker for Toastmasters: from n/a through <= 6.2.4. | |
| Modificada | Crítica (9.8) | 0.85% | — | Carrcommunications Rsvpmaker | 29/12/2023 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in David F. Carr RSVPMaker.This issue affects RSVPMaker: from n/a through 10.6.6. | |
| Modificada | Crítica (9.8) | 1.0% | — | Carrcommunications Rsvpmaker | 3/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 10.6.6. | |
| Modificada | Alta (7.2) | 0.68% | — | Carrcommunications Rsvpmaker | 31/10/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3. | |
| Modificada | Alta (7.2) | 0.55% | — | Carrcommunications Rsvpmaker | 31/10/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 9.9.3. | |
| Modificada | Media (4.8) | 0.37% | — | Carrcommunications Rsvpmaker | 27/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions. | |
| Modificada | Media (6.1) | 0.39% | — | Carrcommunications Rsvpmaker | 27/9/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions. | |
| Modificada | Alta (7.2) | 0.90% | — | Carrcommunications Rsvpmaker | 10/7/2023 | 17/6/2026 | Auth. (admin+) SQL Injection (SQLi) vulnerability in David F. Carr RSVPMaker plugin < 10.5.5 versions. | |
| Modificada | Alta (7.5) | 13% | — | Carrcommunications Rsvpmaker | 13/6/2022 | 17/6/2026 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the… | |
| Modificada | Alta (7.5) | 1.9% | — | Carrcommunications Rsvpmaker | 10/5/2022 | 17/6/2026 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database… | |
| Modificada | Alta (7.5) | 6.9% | — | Carrcommunications Rsvpmaker | 10/5/2022 | 17/6/2026 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in… | |
| Modificada | Media (6.1) | 0.90% | — | Carrcommunications Rsvpmaker Excel | 10/9/2021 | 17/6/2026 | The RSVPMaker Excel WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/phpexcel/PHPExcel/Shared/JAMA/docs/download.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1. | |
| Modificada | Baja (2.7) | 1.0% | — | Carrcommunications Rsvpmaker | 2/8/2021 | 17/6/2026 | The Import feature of the RSVPMaker WordPress plugin before 8.7.3 (/wp-admin/tools.php?page=rsvpmaker_export_screen) takes an URL input and calls curl on it, without first validating it to ensure it's a remote one. As a result, a high privilege user could use that feature to scan the internal network via a SSRF attack. | |
| Modificada | Crítica (9.8) | 2.3% | — | Carrcommunications Rsvpmaker | 27/8/2019 | 17/6/2026 | The rsvpmaker plugin before 6.2 for WordPress has SQL injection. | |
| Modificada | Crítica (9.8) | 2.2% | — | Carrcommunications Rsvpmaker | 27/8/2019 | 17/6/2026 | The rsvpmaker plugin before 5.6.4 for WordPress has SQL injection. |