Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.16% | — | Themewinter EventinAI | 16/9/2026 | 16/9/2026 | The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as successful, not its amount, currency, or which order it belongs to, allowing unauthenticated visitors to mark unpaid orders… | |
| Aplazada | Baja (3.7) | 0.25% | — | Themewinter EventinAI | 16/9/2026 | 17/9/2026 | The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) payment method is enabled, relying on a nonce that is exposed to unauthenticated visitors and never checking that the caller owns the order, allowing unauthenticated attackers to reset any existing order… | |
| Aplazada | Baja (2.7) | 0.28% | — | Themewinter EventinAI | 16/9/2026 | 17/9/2026 | The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and above to create new WordPress user accounts that carry capabilities beyond their own, including publishing content and uploading files, and, by… | |
| Aplazada | Media (5.3) | 0.30% | — | Themewinter EventinAI | 16/9/2026 | 17/9/2026 | The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's tickets afterwards, allowing unauthenticated users to replace a paid ticket with a free one and complete the order at no charge. | |
| Aplazada | Alta (7.5) | 0.70% | — | Themewinter EventinAI | 15/9/2026 | 15/9/2026 | The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions()` function being registered as a callback on WordPress core's `map_meta_cap`… | |
| Aplazada | Media (6.4) | 0.25% | — | Themewinter EventinAI | 15/9/2026 | 16/9/2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, 4.1.23 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (6.5) | 0.27% | — | Themewinter WpcafeAI | 11/9/2026 | 11/9/2026 | The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose guest order information and to change the status of, or trash, any order. | |
| Aplazada | Media (5.4) | 0.18% | — | Themewinter EventinAI | 9/9/2026 | 9/9/2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.1.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.80% | — | Themewinter EventinAI | 9/9/2026 | 9/9/2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Alta (7.5) | 0.66% | — | Themewinter EventinAI | 9/9/2026 | 11/9/2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This makes it possible for authenticated attackers, with custom-level access and above, to… | |
| Aplazada | Media (5.3) | 0.24% | — | Themewinter EventinAI | 9/9/2026 | 9/9/2026 | The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The endpoint's create_item_permissions_check() function only verifies a wp_rest nonce (which is leaked to… | |
| Aplazada | Media (4.9) | 0.33% | — | Themewinter EventinAI | 5/9/2026 | 8/9/2026 | The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy… | |
| Aplazada | Media (6.6) | 0.43% | — | Themewinter EventinAI | 5/9/2026 | 8/9/2026 | The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files. | |
| Aplazada | Media (4.9) | 0.52% | — | Winter CMSAILaravelAI | 26/8/2026 | 9/9/2026 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, authenticated backend users can disclose arbitrary files readable by the PHP process by injecting @import (inline) directives into LESS source that the backend compiles, because the LESS parser was… | |
| Aplazada | Media (5.4) | 0.24% | — | LaravelAIWintercms Winter CMSAI | 26/8/2026 | 9/9/2026 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget trusted an attacker-controlled file_id POST parameter when resolving the attachment it operates on, allowing an authenticated backend user to read and modify… | |
| Aplazada | Media (6.8) | 0.46% | — | Wintercms Winter CMSAI | 26/8/2026 | 9/9/2026 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor AJAX handlers did not enforce per-template-type permission checks, allowing a backend user with any single CMS permission to act on template types outside their… | |
| Aplazada | Media (5.9) | 0.27% | — | LaravelAIWintercms Winter CMSAI | 26/8/2026 | 9/9/2026 | Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configured with a conditions key, allowing an authenticated backend user to inject… | |
| Aplazada | Alta (7.1) | 0.44% | — | Winter CMSAILaravelAI | 26/8/2026 | 9/9/2026 | Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler name submitted through the form postback _handler POST field, allowing an authenticated backend user to invoke arbitrary controller methods, including protected, private,… | |
| Aplazada | Alta (8.1) | 0.38% | — | LaravelAIWintercms WinterAI | 26/8/2026 | 9/9/2026 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LESS parser and rendered without sanitization on every backend… | |
| Aplazada | Alta (8.1) | 0.38% | — | LaravelAIWintercms WinterAI | 26/8/2026 | 9/9/2026 | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the LESS parser and rendered without sanitization on every backend… | |
| Aplazada | Media (5.3) | 0.30% | — | Themewinter EventinAI | 26/8/2026 | 26/8/2026 | The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated users to mark their own unpaid order as completed and be issued a valid paid ticket with no payment taken. | |
| Aplazada | Media (5.3) | 0.25% | — | Themewinter WpcafeAI | 26/8/2026 | 26/8/2026 | The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available nonce, allowing unauthenticated users to submit reservations with an arbitrary approval status and bypass the administrator moderation workflow. | |
| Aplazada | Media (5.3) | 0.31% | — | Themewinter EventinAI | 26/8/2026 | 26/8/2026 | The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords and contents of password-protected ones. | |
| Aplazada | Crítica (9.3) | 0.81% | — | Winter CMSAI | 25/8/2026 | 31/8/2026 | Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding through Eloquent models and query… | |
| Aplazada | Media (6.9) | 0.49% | — | Winter CMSAI | 25/8/2026 | 28/8/2026 | Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable files by placing =include or =require directives in theme JavaScript assets. Attackers can reference files like… |