Vulnerabilities
Summary — last 7 days
New vulnerabilities2,987▼ 96 vs. last week
Critical / high1,458▲ 101 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)350▼ 160 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (3.7) | 0.26% | — | Event Booking Manager FOR WoocommerceAI | 9/17/2026 | 9/18/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom… | |
| Deferred | Medium (5.3) | 0.32% | — | Event Booking Manager FOR WoocommerceAI | 8/6/2026 | 8/26/2026 | The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to… | |
| Deferred | Medium (4.3) | 0.40% | — | Eventbooking Event Booking Manager FOR WoocommerceAI | 7/29/2026 | 7/30/2026 | The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… |