Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1060 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Magepeople Taxi Booking Manager FOR WoocommerceAI | 23/4/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.0. | |
| Aplazada | Media (5.5) | 0.53% | — | Pratham-jaiswal Hotel Booking Management SystemAI | 17/4/2026 | 2/8/2026 | A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an unknown function of the file /api/health/detailed of the component Health Check Endpoint. Performing a manipulation results in information disclosure. Remote exploitation… | |
| Aplazada | Baja (2) | 0.36% | — | ClassroombookingsAI | 17/4/2026 | 17/6/2026 | A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/application/views/layout.php of the component User Display Name Handler. The manipulation of the argument displayname results in cross site scripting. The attack can be executed remotely. The exploit is… | |
| Aplazada | Media (6.4) | 0.15% | — | Surbma Booking COM ShortcodeAI | 14/4/2026 | 17/6/2026 | The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `surbma-bookingcom` shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.45% | — | Booking-wp-plugin BooklyAI | 9/4/2026 | 17/6/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it… | |
| Aplazada | Media (5.3) | 0.26% | — | Dotonpaper Pinpoint Booking SystemAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through <= 2.9.9.6.5. | |
| Aplazada | Media (5.3) | 0.26% | — | Igms Direct BookingAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in igms iGMS Direct Booking igms-direct-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iGMS Direct Booking: from n/a through <= 1.3. | |
| Aplazada | Media (4.3) | 0.26% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 8/4/2026 | 24/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Retrieve Embedded Sensitive Data.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through < 5.6.5. | |
| Aplazada | Media (4.3) | 0.23% | — | Magepeopleteam Wptravelly Tour-booking-managerAI | 8/4/2026 | 20/7/2026 | Missing Authorization vulnerability in magepeopleteam WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through <= 2.1.7. | |
| Aplazada | Media (5.9) | 0.24% | — | Themefic Hydra BookingAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.38. | |
| Aplazada | Alta (7.6) | 0.38% | — | Ameliabooking AmeliaAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.1.1. | |
| Aplazada | Alta (8.8) | 0.56% | 💥 PoC | Ameliabooking AmeliaAI | 7/4/2026 | 17/6/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to the `externalId` field when a Provider (Employee) user updates… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Online Hotel BookingAI | 7/4/2026 | 24/7/2026 | A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Aplazada | Media (6.5) | 0.41% | — | Ameliabooking AmeliaAI | 1/4/2026 | 17/6/2026 | The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and including, 2.1.2. This is due to insufficient escaping on the user-supplied `sort` parameter and lack of sufficient… | |
| Aplazada | Alta (7.2) | 0.30% | — | Fluentbooking Fluent BookingAI | 26/3/2026 | 17/6/2026 | The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.0.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Alta (8.8) | 0.55% | 💥 PoC | Ameliabooking AmeliaAI | 26/3/2026 | 17/6/2026 | The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers… | |
| Aplazada | Alta (7.1) | 0.25% | — | Booking-wp-plugin BooklyAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bookly Bookly bookly-responsive-appointment-booking-tool allows Reflected XSS.This issue affects Bookly: from n/a through <= 26.7. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Object Injection.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through <= 5.6.0. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpdevart Booking CalendarAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Stored XSS.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36. | |
| Aplazada | Alta (8.1) | 0.26% | — | Wordpresschef Salon Booking System PROAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a through < 10.30.12. | |
| Aplazada | Media (6.5) | 0.30% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.0. | |
| Aplazada | Alta (7.2) | 0.39% | — | Vagaro Booking WidgetAI | 21/3/2026 | 17/6/2026 | The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parameter in all versions up to, and including, 0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Alta (7.5) | 0.51% | — | Appointment Booking CalendarAI | 19/3/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in all versions up to, and including, 1.6.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Alta (7.5) | 0.50% | — | Appointment Booking CalendarAI | 13/3/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized access of sensitive data in all versions up to and including 1.6.9.29. This is due to two compounding weaknesses: (1) a non-user-bound `public_nonce` is exposed to unauthenticated users through the public… | |
| Aplazada | Media (5.3) | 0.29% | — | Wptravelengine Travel-bookingAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in wptravelengine Travel Booking travel-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Booking: from n/a through <= 1.3.9. |