Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1060 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.27% | — | Code-projects Simple Flight Ticket Booking SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Alta (7.2) | 0.61% | — | Saasproject Booking PackageAI | 6/6/2026 | 23/7/2026 | The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the package_app_action AJAX endpoint, where the handler only validates a nonce and the dispatcher invokes… | |
| Aplazada | Alta (7.3) | 0.30% | — | Themefic Hydra BookingAI | 1/6/2026 | 22/7/2026 | Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hydra Booking: from n/a through 1.1.41. | |
| Aplazada | Alta (7.1) | 0.25% | — | E4jvikwp Vikbooking Hotel Booking Engine AND PMSAI | 1/6/2026 | 22/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows DOM-Based XSS. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.8. | |
| Aplazada | Media (5.3) | 0.64% | — | Booking Calendar Simply Schedule AppointmentsAI | 28/5/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments REST API endpoint.… | |
| Aplazada | Alta (7.5) | 0.67% | — | Simplyscheduleappointments Appointment Booking CalendarAI | 28/5/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Aplazada | Alta (7.1) | 0.25% | — | E4jvikwp VikbookingAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows DOM-Based XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9. | |
| Aplazada | Media (6.5) | 0.22% | — | Oplugins Booking ManagerAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Manager booking-manager allows Stored XSS.This issue affects Booking Manager: from n/a through <= 2.1.18. | |
| Aplazada | Alta (8.6) | 0.53% | — | E4jvikwp VikbookingAI | 27/5/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Path Traversal.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9. | |
| Aplazada | Media (4.3) | 0.25% | — | Magepeople INC WpbookinglyAI | 26/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9. | |
| Aplazada | Media (5.3) | 0.19% | — | Magepeople Taxi Booking Manager FOR WoocommerceAI | 26/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.1. | |
| Aplazada | Media (5.3) | 0.47% | — | Motopress Hotel BookingAI | 22/5/2026 | 23/7/2026 | The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite or delete the internal… | |
| Aplazada | Crítica (9.8) | 0.87% | 💥 PoC | Bookingpress PROAI | 21/5/2026 | 23/7/2026 | The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Aplazada | Media (6.5) | 0.42% | — | Magepeople WpbookinglyAI | 20/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9. | |
| Aplazada | Media (5.3) | 0.39% | — | Smart Appointment BookingAI | 12/5/2026 | 17/6/2026 | The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation logic flaw in the saab_cancel_booking() function in all versions up to, and including, 1.0.8. The nonce check uses && (AND) instead of || (OR), which means… | |
| Aplazada | Media (5.1) | 0.19% | — | Motopress Hotel Booking LiteAI | 10/5/2026 | 25/7/2026 | Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting payloads in accommodation type fields. Attackers can inject script tags through the title and excerpt parameters when creating accommodation types, which… | |
| Aplazada | Media (5.3) | 0.17% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 7/5/2026 | 7/10/2026 | Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bus Ticket Booking with Seat Reservation: from n/a before 5.6.8. | |
| Aplazada | Media (6.5) | 0.48% | — | Appointment Booking CalendarAI | 7/5/2026 | 17/6/2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to a flawed authorization logic in the nonce_permissions_check() method combined with the public exposure of a site-wide reusable nonce. The plugin exposes a public_nonce… | |
| Aplazada | Alta (7.5) | 0.34% | — | Gravity Bookings PremiumAI | 6/5/2026 | 17/6/2026 | The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append… | |
| Aplazada | Alta (7.5) | 0.55% | — | Salonbookingsystem Salon Booking SystemAI | 2/5/2026 | 17/6/2026 | The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using those stored values as trusted paths for email attachments. This makes it… | |
| Aplazada | Media (5.3) | 0.42% | — | Ameliabooking AmeliaAI | 2/5/2026 | 17/6/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting'… | |
| Aplazada | Media (5.3) | 0.53% | — | Saasproject Booking PackageAI | 28/4/2026 | 17/6/2026 | The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 This is due to the intentForStripe() function passing user-controlled $_POST['amount'] directly to the Stripe PaymentIntent API without validation, and the commitStripe() function ignoring the… | |
| Aplazada | Crítica (9.3) | 0.28% | — | Directorist BookingAI | 27/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Booking allows SQL Injection.This issue affects Directorist Booking: from n/a before 3.0.2. | |
| Aplazada | Media (5.3) | 0.43% | — | Codepeople Booking Calendar Contact FormAI | 24/4/2026 | 17/6/2026 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the dex_bccf_admin_int_calendar_list.inc.php file due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.7) | 0.42% | — | Spicejet Booking APIAI | 23/4/2026 | 17/6/2026 | A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without any access controls. Because PNR identifiers follow a predictable pattern, an attacker could systematically enumerate valid records and obtain associated passenger names. This flaw stems from missing… |