Magepeopleteam
Magepeopleteam Wpevently: vulnerabilidades y CVE
Magepeopleteam Wpevently tiene 9 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses5
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-25361 | Alta (7.1) | 0.18% | — | 25 mar 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpEvently mage-eventpress allows Reflected XSS.This issue affects WpEvently: from n/a through <= 5.1.4. |
| CVE-2026-32354 | Media (5.3) | 0.33% | — | 13 mar 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Retrieve Embedded Sensitive Data.This issue affects WpEvently: from n/a through < 5.1.9. |
| CVE-2026-23549 | Crítica (9.8) | 0.39% | — | 19 feb 2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.1.1. |
| CVE-2026-24954 | Alta (8.8) | 0.42% | — | 3 feb 2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.0.8. |
| CVE-2026-24942 | Media (4.3) | 0.13% | — | 3 feb 2026 | Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam WpEvently mage-eventpress allows Cross Site Request Forgery.This issue affects WpEvently: from n/a through <= 5.1.1. |
| CVE-2025-54705 | Media (4.3) | 0.25% | — | 14 ago 2025 | Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpEvently: from n/a through <= 4.4.6. |
| CVE-2025-32145 | Alta (8.8) | 0.48% | — | 10 abr 2025 | Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 4.3.6. |
| CVE-2025-30895 | Alta (7.5) | 0.81% | — | 27 mar 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in magepeopleteam WpEvently mage-eventpress allows PHP Local File Inclusion.This issue affects WpEvently: from n/a through <=… |
| CVE-2024-49703 | Media (6.5) | 0.26% | — | 24 oct 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpEvently mage-eventpress.This issue affects WpEvently: from n/a through <= 4.2.5. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Magepeopleteam
Booking AND Rental Manager FOR Woocommerce · 9WP Evently · 4Taxi Booking Manager FOR Woocommerce · 3Booking AND Rental Manager · 2CAR Rental Manager · 2Mage-eventpress · 2Wpbookingly · 2Wptravelly · 2Mage Eventpress · 1WP Travelly · 1Wptravelly Tour-booking-manager · 1Multipurpose Ticket Booking Manager · 1