Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.28% | — | Eventtickets Event Tickets AND RegistrationAI | 2/10/2026 | 2/10/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.29.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (4.8) | 0.29% | — | Crocantickets EntradiumAI | 1/10/2026 | 1/10/2026 | CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Specifically, in the Name and Field parameters of the endpoint /tools/discount_wizard/discount_config during the process of creating discounts assigned to an event. This vulnerability allows JavaScript code to be injected into the… | |
| Aplazada | Media (4.8) | 0.28% | — | Crocantickets EntradiumAI | 1/10/2026 | 1/10/2026 | CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data. | |
| Aplazada | Alta (8.5) | 0.25% | — | Event TicketsAI | 30/9/2026 | 2/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Blind SQL Injection.This issue affects Event Tickets: from n/a through 5.29.5. | |
| Aplazada | Alta (7.1) | 0.18% | — | Event TicketsAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions. | |
| Aplazada | Alta (7.5) | 0.47% | — | Eventbrite Event TicketsAI | 8/9/2026 | 9/9/2026 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endpoint in all versions up to, and including, 5.27.4. This makes it possible for unauthenticated attackers to overwrite the site's Stripe merchant… | |
| Aplazada | Alta (7.1) | 0.25% | — | Event TicketsAI | 24/8/2026 | 26/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions. | |
| Aplazada | Baja (2.2) | 0.23% | — | Event Tickets AND RegistrationAI | 1/8/2026 | 26/8/2026 | The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access and above to overwrite the seating layout, ticket inventory, and attendee seat assignments of events they do not own. | |
| Aplazada | Media (5.3) | 0.30% | — | Eventbrite Event TicketsAI | 1/8/2026 | 26/8/2026 | The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of its order-management REST endpoints, allowing unauthenticated users to change the status of existing orders. | |
| Aplazada | Baja (3.5) | 0.24% | — | Eventtickets Event TicketsAI | 28/7/2026 | 28/7/2026 | The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users with the Editor role and above to perform Stored Cross-Site Scripting attacks that execute against higher-privileged users on multisite installations. | |
| Aplazada | Media (5.3) | 0.29% | — | Event TicketsAI | 27/7/2026 | 27/7/2026 | Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Nexcess Event TicketsAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in Nexcess Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a through <= 5.28.5. | |
| Aplazada | Media (6.5) | 0.33% | — | Wpswings Event Tickets Manager FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5. | |
| Pendiente de análisis | Crítica (9.6) | 0.84% | — | Centreon-open-ticketsAICentreon Infra MonitoringAI | 13/7/2026 | 13/7/2026 | This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without sanitization and rendered via Smarty with no security policy enabled, allowing any authenticated user, to inject and execute… | |
| Aplazada | Media (6.5) | 0.36% | — | Event TicketsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Event Tickets ManagerAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions. | |
| Aplazada | Alta (8.2) | 0.27% | — | Open Ises TicketsAI | 21/5/2026 | 23/7/2026 | Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests issued during the mobile (RouteMate) login flow. An attacker positioned on the network path… | |
| Aplazada | Alta (8.2) | 0.31% | — | Open Ises TicketsAI | 21/5/2026 | 23/7/2026 | Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests issued during the login/authentication flow. An attacker positioned on the network path between the server… | |
| Aplazada | Alta (8.2) | 0.27% | — | Open Ises TicketsAI | 21/5/2026 | 23/7/2026 | Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for general-purpose outbound HTTPS requests issued by the shared helper functions. An attacker… | |
| Aplazada | Alta (8.2) | 0.27% | — | Open Ises TicketsAI | 21/5/2026 | 23/7/2026 | Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests for Google Maps Directions API lookups during incident report generation. An attacker positioned on the… | |
| Aplazada | Media (6.9) | 0.38% | — | Open Ises TicketsAI | 21/5/2026 | 20/7/2026 | Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the public source repository. Any actor with read access to the source tree can extract the key and use it to make third-party API calls billed to or rate-limited against the original owner's WhitePages… | |
| Aplazada | Crítica (9.2) | 0.51% | — | Open Ises TicketsAI | 21/5/2026 | 23/7/2026 | Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php. The credentials are embedded in source code committed to the public repository, allowing any reader of the source to obtain valid configuration values that may match… | |
| Aplazada | Crítica (9.2) | 0.52% | — | Open Ises TicketsAI | 21/5/2026 | 23/7/2026 | Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed installation) can read… | |
| Aplazada | Alta (7.1) | 0.36% | — | Open Ises TicketsAI | 21/5/2026 | 23/7/2026 | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in message.php where the frm_ticket_id and frm_resp_id POST parameters are concatenated into WHERE clauses of SELECT/UPDATE statements without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or… | |
| Aplazada | Alta (7.1) | 0.36% | — | Open Ises TicketsAI | 21/5/2026 | 23/7/2026 | Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loader.php where the multiple POST parameters (ticketsdb, ticketshost, ticketsuser, ticketspassword) are concatenated into mysqli connection arguments and dynamic SQL operating against an attacker-controlled database without sanitization.… |