Ameliabooking
Ameliabooking Amelia: vulnerabilidades y CVE
Ameliabooking Amelia tiene 17 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses16
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-14311 | Media (5.4) | 0.17% | — | 17 sept 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in… |
| CVE-2026-62112 | Alta (7.6) | 0.38% | — | 11 sept 2026 | Editor SQL Injection in Amelia <= 2.4.9 versions. |
| CVE-2026-9055 | Crítica (9.8) | 0.51% | — | 2 sept 2026 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled… |
| CVE-2026-6286 | Alta (7.2) | 0.62% | — | 28 ago 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication… |
| CVE-2026-14782 | Media (4.9) | 0.41% | — | 16 jul 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user… |
| CVE-2026-48889 | Alta (8.8) | 0.42% | — | 15 jun 2026 | Subscriber Privilege Escalation in Amelia <= 2.3 versions. |
| CVE-2026-40789 | Alta (7.5) | 0.42% | — | 15 jun 2026 | Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions. |
| CVE-2026-6449 | Media (5.3) | 0.42% | — | 2 may 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in… |
| CVE-2026-39487 | Alta (7.6) | 0.38% | — | 8 abr 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.1.1. |
| CVE-2026-5465 | Alta (8.8) | 0.56% | — | 7 abr 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the… |
| CVE-2026-4668 | Media (6.5) | 0.41% | — | 1 abr 2026 | The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and including, 2.1.2. This… |
| CVE-2026-2931 | Alta (8.8) | 0.55% | — | 26 mar 2026 | The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user… |
| CVE-2026-24963 | Alta (7.2) | 0.32% | — | 5 mar 2026 | Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n/a through <= 1.2.38. |
| CVE-2026-24967 | Media (5.3) | 0.26% | — | 3 feb 2026 | Missing Authorization vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <= 1.2.38. |
| CVE-2025-14720 | Media (5.3) | 0.32% | — | 9 ene 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38.… |
| CVE-2025-12482 | Alta (7.5) | 0.32% | — | 16 nov 2025 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the… |
| CVE-2025-26965 | Media (5.3) | 0.44% | — | 25 feb 2025 | Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <=… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.