Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.37% | — | Icalendar Project Icalendar | 26/3/2026 | 17/6/2026 | iCalendar is a Ruby library for dealing with iCalendar files in the iCalendar format defined by RFC-5545. Starting in version 2.0.0 and prior to version 2.12.2, .ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines… | |
| Analizada | Media (4.3) | 0.14% | — | VR Calendar Project VR Calendar | 27/6/2025 | 17/6/2026 | The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.7. This is due to missing or incorrect nonce validation on the syncCalendar() function. This makes it possible for unauthenticated attackers to trigger a calendar sync via a forged request granted… | |
| Analizada | Alta (7.5) | 0.32% | — | MF GIG Calendar Project MF GIG Calendar | 6/5/2024 | 17/6/2026 | The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack | |
| Analizada | Media (5.4) | 0.43% | — | MF GIG Calendar Project MF GIG Calendar | 6/5/2024 | 17/6/2026 | The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.23% | — | MF GIG Calendar Project MF GIG Calendar | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar : from n/a through 1.2.1. | |
| Modificada | Crítica (9.8) | 0.80% | — | Bookingcalendar Project Bookingcalendar | 7/2/2024 | 17/6/2026 | SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via ics_export.php. | |
| Modificada | Media (6.1) | 0.46% | — | Webcalendar Project Webcalendar | 25/1/2024 | 17/6/2026 | WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php. | |
| Modificada | Alta (8.8) | 0.48% | — | MF GIG Calendar Project MF GIG Calendar | 28/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar: from n/a through 1.2.1. | |
| Modificada | Alta (8.8) | 0.31% | — | Chronosly-events-calendar Project Chronosly-events-calendar | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Chronosly Chronosly Events Calendar plugin <= 2.6.2 versions. | |
| Modificada | Media (5.4) | 0.37% | — | MF GIG Calendar Project MF GIG Calendar | 27/7/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Matthew Fries MF Gig Calendar plugin <= 1.2 versions. | |
| Modificada | Media (5.4) | 0.62% | — | Tiva Events Calendar Project Tiva Events Calendar | 20/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Codecanyon Tiva Events Calender 1.4. This vulnerability affects unknown code. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-235054 is the… | |
| Modificada | Media (6.1) | 0.41% | — | Booking Calendar Project Booking Calendar | 18/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CodePeople Booking Calendar Contact Form plugin <= 1.2.40 versions. | |
| Modificada | Media (5.4) | 0.44% | — | Editorial Calendar Project Editorial Calendar | 27/6/2023 | 17/6/2026 | The Editorial Calendar WordPress plugin before 3.8.3 does not sanitise and escape its settings, allowing users with roles as low as contributor to inject arbitrary web scripts in the plugin admin panel, enabling a Stored Cross-Site Scripting vulnerability targeting higher privileged users. | |
| Modificada | Alta (8.8) | 0.27% | — | MY Calendar Project MY Calendar | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Easy Event Calendar Project Easy Event Calendar | 8/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CoreFortress Easy Event calendar plugin <= 1.0 versions. | |
| Modificada | Crítica (9.8) | 0.72% | — | Editorial Calendar Project Editorial Calendar | 8/4/2023 | 16/6/2026 | A vulnerability was found in Editorial Calendar Plugin up to 2.6 on WordPress. It has been declared as critical. Affected by this vulnerability is the function edcal_filter_where of the file edcal.php. The manipulation of the argument edcal_startDate/edcal_endDate leads to sql injection. The attack can be launched… | |
| Modificada | Media (5.4) | 0.39% | — | WP Calendar Project WP Calendar | 17/3/2023 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in Fabian von Allmen WP Calendar plugin <= 1.5.3 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | MY Calendar Project MY Calendar | 15/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions. | |
| Modificada | Media (5.4) | 0.53% | — | Webcalendar Project Webcalendar | 13/1/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository craigk5n/webcalendar prior to master. | |
| Modificada | Media (6.5) | 0.50% | — | VR Calendar Project VR Calendar | 3/11/2022 | 17/6/2026 | The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify calendars as well as the plugin settings, via… | |
| Modificada | Crítica (9.8) | 17% | — | VR Calendar Project VR Calendar | 15/8/2022 | 17/6/2026 | The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site. | |
| Modificada | Alta (8.8) | 1.7% | — | Booking Calendar Project Booking Calendar | 10/5/2022 | 17/6/2026 | The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site. | |
| Modificada | Media (6.1) | 0.80% | — | Booking Calendar Project Booking Calendar | 3/1/2022 | 17/6/2026 | The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (5.4) | 0.62% | — | MY Calendar Project MY Calendar | 29/11/2021 | 17/6/2026 | The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.89% | — | PHP Event Calendar Project PHP Event Calendar | 8/11/2021 | 17/6/2026 | PHP Event Calendar through 2021-11-04 allows persistent cross-site scripting (XSS), as demonstrated by the /server/ajax/events_manager.php title parameter. This can be exploited by an adversary in multiple ways, e.g., to perform actions on the page in the context of other users, or to deface the site. |