Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2628▼ 312 respecto a la semana anterior
Críticas / altas1351▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.33%—MY CalendarAI9/9/202611/9/2026
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.4)0.36%—MY CalendarAI9/9/20269/9/2026
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fallback' Shortcode Attribute in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.5)1.6%—MY CalendarAI8/7/20268/7/2026
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaMedia (5.3)0.54%—MY CalendarAI2/7/20262/7/2026
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14 via the 'vcal' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to enumerate occurrence IDs…
AplazadaMedia (4.3)0.47%—MY CalendarAI14/5/202617/6/2026
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level…
AplazadaAlta (8.8)1.1%—MY CalendarAI16/4/202617/6/2026
My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJAX endpoint, registered for unauthenticated users, passes user-supplied arguments through parse_str() without validation, allowing injection of arbitrary parameters including a site value. On…
AplazadaMedia (6.4)0.28%—MY CalendarAI4/3/202617/6/2026
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template` attribute of the `[my_calendar_upcoming]` shortcode in all versions up to, and including, 3.7.3. This is due to the use of `stripcslashes()` on user-supplied shortcode attribute values in the…
AplazadaMedia (4.3)0.18%—Joedolson MY CalendarAI9/12/202517/6/2026
Missing Authorization vulnerability in Joe Dolson My Calendar my-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Calendar: from n/a through <= 3.6.16.
AnalizadaMedia (5.4)0.43%—Joedolson MY Calendar2/4/202417/6/2026
The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks (depending on the permissions set by the admin)
AplazadaMedia (6.5)0.33%—Joseph C Dolson MY CalendarAI15/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joseph C Dolson My Calendar allows Stored XSS.This issue affects My Calendar: from n/a through 3.4.23.
ModificadaCrítica (9.8)63%—Joedolson MY Calendar30/11/202317/6/2026
The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.
ModificadaAlta (8.8)0.27%—MY Calendar Project MY Calendar22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3 versions.
ModificadaAlta (8.8)0.27%—MY Calendar Project MY Calendar15/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions.
ModificadaMedia (5.4)0.62%—MY Calendar Project MY Calendar29/11/202117/6/2026
The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (6.1)2.2%—MY Calendar Project MY Calendar28/8/201917/6/2026
The my-calendar plugin before 3.1.10 for WordPress has XSS.
ModificadaBaja (2.6)2.2%—Joedolson MY CalendarWordpress31/1/201316/6/2026
Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
ModificadaMedia (5)2.0%—Mike Spice MY Calendar31/12/200216/6/2026
Directory traversal vulnerability in Mike Spice My Calendar before 1.5 allows remote attackers to write arbitrary files via .. (dot dot) sequences in a URL.