Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1060 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.15% | — | Themespride Advanced Appointment Booking SchedulingAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in themespride Advanced Appointment Booking & Scheduling advanced-appointment-booking-scheduling allows Cross Site Request Forgery.This issue affects Advanced Appointment Booking & Scheduling: from n/a through <= 2.1. | |
| Aplazada | Media (6.5) | 0.22% | — | Themewant Easy Hotel BookingAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themewant Easy Hotel Booking easy-hotel allows DOM-Based XSS.This issue affects Easy Hotel Booking: from n/a through <= 1.9.0. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Service Finder BookingsAI | 19/9/2025 | 17/6/2026 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to claiming a business when using the claim_business AJAX action. This makes it possible for… | |
| Aplazada | Crítica (9.1) | 0.30% | — | Thimpress WP Hotel BookingAI | 18/9/2025 | 17/6/2026 | The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an attacker to manipulate the rating value (e.g., sending negative or out-of-range values) by intercepting and modifying requests. | |
| Aplazada | Media (5.3) | 0.29% | — | Salonbookingsystem Salon Booking SystemAI | 11/9/2025 | 17/6/2026 | The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax function in all versions up to, and including, 10.22. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.1) | 0.11% | — | Cristiano Zanca Woocommerce Booking Bundle HoursAI | 9/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cristiano Zanca WooCommerce Booking Bundle Hours allows Stored XSS. This issue affects WooCommerce Booking Bundle Hours: from n/a through 0.7.4. | |
| Aplazada | Media (6.5) | 0.32% | — | Wpsimplebookingcalendar WP Simple Booking CalendarAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Roland Murg WP Simple Booking Calendar wp-simple-booking-calendar.This issue affects WP Simple Booking Calendar: from n/a through <= 2.0.13. | |
| Aplazada | Media (6.5) | 0.17% | — | Course Finder Course Booking PlatformAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Course Finder | andré martin - it solutions & research UG Course Booking Platform course-booking-platform allows Stored XSS.This issue affects Course Booking Platform: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.17% | — | Deetronix Booking Ultra PROAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Deetronix Booking Ultra Pro booking-ultra-pro allows Stored XSS.This issue affects Booking Ultra Pro: from n/a through <= 1.1.21. | |
| Aplazada | Media (6.4) | 0.20% | — | Booking CalendarAI | 28/8/2025 | 17/6/2026 | The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 10.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject… | |
| Aplazada | Media (6.5) | 0.17% | — | Ameliabooking Booking System TrafftAI | 27/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ameliabooking Booking System Trafft booking-system-trafft allows Stored XSS.This issue affects Booking System Trafft: from n/a through <= 1.0.14. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Magepeopleteam Taxi Booking Manager FOR WoocommerceAI | 20/8/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Authentication Abuse.This issue affects Taxi Booking Manager for WooCommerce: from n/a through <= 1.3.0. | |
| Modificada | Alta (7.2) | 0.44% | 💥 PoC | Vcita Online Booking & Scheduling Calendar | 20/8/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Using Malicious Files.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.3. | |
| Aplazada | Media (6.5) | 0.36% | — | Webba Booking LiteAI | 20/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Webba Booking: from n/a through <= 5.1.20. | |
| Aplazada | Alta (8.1) | 0.84% | — | Uxper BookingAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Uxper Booking uxper-booking allows PHP Local File Inclusion.This issue affects Uxper Booking: from n/a through <= 1.3.3. | |
| Aplazada | Alta (8.5) | 0.34% | — | Uxper BookingAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in uxper Uxper Booking uxper-booking allows Blind SQL Injection.This issue affects Uxper Booking: from n/a through <= 1.3.3. | |
| Aplazada | Crítica (9.8) | 0.47% | — | E-cab Taxi Booking Manager FOR WoocommerceAI | 16/8/2025 | 17/6/2026 | The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.0. This is due to the plugin not properly validating a user's capabilities prior to updating a plugin setting or their identity prior to updating… | |
| Aplazada | Media (5.9) | 0.18% | — | Webba Booking LiteAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Stored XSS.This issue affects Webba Booking: from n/a through <= 6.0.5. | |
| Analizada | Media (5.5) | 0.50% | — | Campcodes Online Flight Booking Management System | 14/8/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Online Flight Booking Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/save_airlines.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.5) | 0.40% | — | Campcodes Online Flight Booking Management System | 14/8/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Online Flight Booking Management System 1.0. Affected is an unknown function of the file /flights.php. The manipulation of the argument departure_airport_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (5.4) | 0.22% | — | Vcita Online Booking & Scheduling Calendar | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Stored XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.3. | |
| Aplazada | Alta (7.3) | 0.27% | — | Vonstroheim ThebookingAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in VonStroheim TheBooking thebooking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects TheBooking: from n/a through <= 1.4.4. | |
| Analizada | Media (5.5) | 0.40% | — | Campcodes Online Flight Booking Management System | 14/8/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Flight Booking Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The… | |
| Aplazada | Media (4.3) | 0.15% | — | CBX Restaurant BookingAI | 11/8/2025 | 17/6/2026 | The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Aplazada | Crítica (9.8) | 4.4% | 💥 Exploit | Service Finder BookingsAI | 1/8/2025 | 17/6/2026 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's cookie value prior to logging them in through the service_finder_switch_back() function. This makes it… |