« Volver al listado

Timetics

Timetics: vulnerabilidades y CVE

Timetics tiene 5 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses4
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-84215Media (6.5)0.33%—3 sept 2026
Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.
CVE-2026-14326Baja (3.8)0.22%—2 sept 2026
The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments…
CVE-2026-57674Alta (7.1)0.25%—2 jul 2026
Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions.
CVE-2025-15473Media (4.3)0.16%—12 mar 2026
The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking"…
CVE-2024-1094Alta (7.3)0.54%—14 jun 2024
The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the…