Tickera
Tickera: vulnerabilidades y CVE
Tickera tiene 14 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-82226 | Crítica (9.8) | 0.56% | — | 31 ago 2026 | Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions. |
| CVE-2026-15761 | Media (6.5) | 0.45% | — | 23 jul 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on… |
| CVE-2026-15448 | Media (6.5) | 0.41% | — | 23 jul 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient… |
| CVE-2026-13755 | Media (6.4) | 0.39% | — | 16 jul 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute in all versions up to, and including, 3.6.0.0 due to insufficient… |
| CVE-2026-13754 | Media (6.5) | 0.41% | — | 16 jul 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 3.6.0.0 due to insufficient escaping on the user… |
| CVE-2025-12356 | Media (4.3) | 0.25% | — | 18 feb 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_change_ticket_status' AJAX endpoint in all versions up… |
| CVE-2024-12578 | Media (5.3) | 0.50% | — | 14 dic 2024 | The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.5.4.8 via the 'tickera_tickets_info' endpoint. This makes it possible for… |
| CVE-2023-23726 | Media (5.4) | 0.27% | — | 9 dic 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Tickera.com Tickera allows Cross Site Request Forgery.This issue affects Tickera: from n/a through 3.5.1.0. |
| CVE-2024-10263 | Alta (7.3) | 0.51% | — | 5 nov 2024 | The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the software allowing users to execute an action… |
| CVE-2024-5860 | Media (4.3) | 0.28% | — | 18 jun 2024 | The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tc_dl_delete_tickets AJAX action in all versions up to, and including,… |
| CVE-2024-35729 | Alta (8.8) | 0.34% | — | 10 jun 2024 | Missing Authorization vulnerability in Tickera Tickera tickera-event-ticketing-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tickera: from n/a through <= 3.5.2.6. |
| CVE-2023-7252 | Media (5.3) | 0.52% | — | 22 abr 2024 | The Tickera WordPress plugin before 3.5.2.5 does not prevent users from leaking other users' tickets. |
| CVE-2022-4549 | Media (4.3) | 0.29% | — | 16 ene 2023 | The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack. |
| CVE-2021-24797 | Media (6.1) | 1.2% | — | 27 dic 2021 | The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events before outputting them in the Orders admin dashboard, which could allow unauthenticated users to perform… |