Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2544 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | Shopfiles Ebook StoreAI | 27/7/2026 | 27/7/2026 | Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. | |
| Aplazada | Alta (8.2) | 0.43% | 💥 PoC | Bookingpress Appointment Booking PROAI | 27/7/2026 | 27/7/2026 | The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings. | |
| Aplazada | Alta (7.2) | 0.60% | — | VikbookingAI | 24/7/2026 | 24/7/2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.1) | 0.46% | — | VikbookingAI | 24/7/2026 | 24/7/2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.4) | 0.33% | — | Thimpress WP Hotel BookingAI | 24/7/2026 | 24/7/2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (5.1) | 0.44% | — | Phoca GuestbookAI | 23/7/2026 | 24/7/2026 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability. | |
| Aplazada | Alta (7.5) | 0.57% | — | Facebook ProxygenAI | 23/7/2026 | 23/7/2026 | Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory… | |
| Aplazada | Media (6.5) | 0.22% | — | Dwbooster Appointment Hour BookingAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | JetbookingAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. | |
| Aplazada | Media (4.9) | 0.19% | — | JetbookingAI | 23/7/2026 | 23/7/2026 | Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Shopfiles Ebook StoreAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Shopfiles Ebook StoreAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Themetechmount TruebookerAI | 23/7/2026 | 23/7/2026 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Themetechmount TruebookerAI | 23/7/2026 | 23/7/2026 | Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Booking-wp-plugin BooklyAI | 23/7/2026 | 23/7/2026 | Unauthenticated SQL Injection in Bookly <= 27.7 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Booking-wp-plugin BooklyAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | Wp-base BookingAI | 23/7/2026 | 23/7/2026 | Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. | |
| Aplazada | Alta (7.1) | 0.34% | — | Wpbookingsystem WP Booking SystemAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Joomdonation Events BookingAI | 22/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information. | |
| Pendiente de análisis | Alta (7.5) | 0.60% | — | Facebook React-server-dom-webpackAIFacebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAI | 21/7/2026 | 21/7/2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0… | |
| Aplazada | Alta (8.8) | 0.20% | — | Joomdonation Events BookingAI | 17/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Joomdonation Events BookingAI | 17/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets. | |
| Aplazada | Media (5.3) | 0.34% | — | Joomdonation Events BookingAI | 17/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses. | |
| Aplazada | Media (5.4) | 0.29% | — | WPS Bookings FOR WoocommerceAI | 17/7/2026 | 17/7/2026 | The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers' booking orders. | |
| Aplazada | Media (6.1) | 0.69% | 💥 Exploit | Thimpress WP Hotel BookingAI | 17/7/2026 | 17/7/2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… |