Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1060 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.31% | — | Eagle-themes Eagle BookingAI | 30/12/2025 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Eagle-Themes Eagle Booking eagle-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Eagle Booking: from n/a through <= 1.3.4.3. | |
| Aplazada | Media (6.5) | 0.29% | — | Codepeople WP Time Slots Booking FormAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.39. | |
| Aplazada | Media (6.4) | 0.18% | — | Ba-booking BA Book EverythingAI | 19/12/2025 | 17/6/2026 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-form shortcode in all versions up to, and including, 1.8.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Baja (2) | 0.32% | — | Anisha Online Appointment Booking System | 19/12/2025 | 17/6/2026 | A vulnerability was found in code-projects Online Appointment Booking System 1.0. Impacted is an unknown function of the file /admin/deletemanager.php. The manipulation of the argument managername results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Aplazada | Crítica (9.1) | 0.37% | — | Jetmonsters Motopress-hotel-booking-liteAI | 18/12/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote Code Inclusion.This issue affects Hotel Booking Lite: from n/a through <= 5.2.3. | |
| Aplazada | Alta (8.8) | 0.43% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 18/12/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.4. | |
| Aplazada | Media (5.9) | 0.32% | — | E4jvikwp VikbookingAI | 18/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Retrieve Embedded Sensitive Data.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.2. | |
| Analizada | Media (5.5) | 0.36% | — | Anisha Online Appointment Booking System | 17/12/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an unknown function of the file /admin/deletemanagerclinic.php. Performing manipulation of the argument clinic results in sql injection. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Alta (8.5) | 0.31% | 💥 PoC | Themefic Hydra BookingAI | 16/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection.This issue affects Hydra Booking: from n/a through <= 1.1.32. | |
| Aplazada | Alta (7.5) | 0.42% | — | Booking CalendarAI | 15/12/2025 | 7/10/2026 | The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' parameter in all versions up to, and including, 10.14.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.18% | — | Shahjahan Jewel Fluent BookingAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Shahjahan Jewel Fluent Booking fluent-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Booking: from n/a through <= 1.9.11. | |
| Aplazada | Media (5.3) | 0.25% | — | Wpdevart Booking CalendarAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.30. | |
| Modificada | Media (5.4) | 0.25% | — | Vcita Online Booking & Scheduling Calendar | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.5. | |
| Modificada | Alta (8.8) | 0.15% | — | Vcita Online Booking & Scheduling Calendar | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.5. | |
| Aplazada | Media (4.3) | 0.16% | — | Salonbookingsystem Salon Booking SystemAI | 9/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.30.3. | |
| Aplazada | Media (4.3) | 0.31% | — | Webba Booking LiteAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Webba Booking: from n/a through <= 6.2.1. | |
| Aplazada | Media (4.3) | 0.26% | — | Thimpress WP Hotel BookingAI | 9/12/2025 | 7/10/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Retrieve Embedded Sensitive Data.This issue affects WP Hotel Booking: from n/a through <= 2.2.7. | |
| Aplazada | Media (4.3) | 0.13% | — | Thimpress WP Hotel BookingAI | 9/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows Cross Site Request Forgery.This issue affects WP Hotel Booking: from n/a through <= 2.2.8. | |
| Aplazada | Media (5.9) | 0.20% | — | Thimpress WP Hotel BookingAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows DOM-Based XSS.This issue affects WP Hotel Booking: from n/a through <= 2.2.8. | |
| Aplazada | Media (6.4) | 0.18% | — | Booking CalendarAI | 5/12/2025 | 17/6/2026 | The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' shortcode in all versions up to, and including, 10.14.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.19% | — | Fluentbooking Fluent BookingAI | 3/12/2025 | 17/6/2026 | The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing capability check on the "importCalendar" function in all versions up to, and including, 1.9.11. This makes it possible for authenticated attackers, with subscriber level access and above, to import… | |
| Aplazada | Media (5.3) | 0.30% | — | Codepeople Booking Calendar Contact FormAI | 22/11/2025 | 17/6/2026 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.60. This is due to missing authorization checks and payment verification in the `dex_bccf_check_IPN_verification` function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.3) | 0.28% | — | Appointment Booking CalendarAI | 22/11/2025 | 17/6/2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.96. This is due to the plugin exposing an unauthenticated booking processing endpoint (cpabc_appointments_check_IPN_verification) that trusts attacker-supplied payment notifications… | |
| Aplazada | Media (6.4) | 0.18% | — | Hotelrunner Booking WidgetAI | 21/11/2025 | 7/10/2026 | The HotelRunner Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hotelrunner' shortcode in all versions up to, and including, 5.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.29% | — | Booking Plugin FOR Wordpress Appointments Time SlotAI | 19/11/2025 | 17/6/2026 | The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 due to missing validation on the tslot_appt_email AJAX action. This makes it possible for unauthenticated attackers to send appointment notification emails… |