Timetics
Timetics: vulnerabilidades y CVE
Timetics tiene 5 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses4
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-84215 | Media (6.5) | 0.33% | — | 3 sept 2026 | Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions. |
| CVE-2026-14326 | Baja (3.8) | 0.22% | — | 2 sept 2026 | The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments… |
| CVE-2026-57674 | Alta (7.1) | 0.25% | — | 2 jul 2026 | Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions. |
| CVE-2025-15473 | Media (4.3) | 0.16% | — | 12 mar 2026 | The Timetics WordPress plugin before 1.0.52 does not have authorization in a REST endpoint, allowing unauthenticated users to arbitrarily change a booking's payment status and post status for the "timetics-booking"… |
| CVE-2024-1094 | Alta (7.3) | 0.54% | — | 14 jun 2024 | The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the… |