Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
372 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.31% | — | Dwbooster Appointment Hour BookingAI | 16/9/2026 | 16/9/2026 | The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully booked. | |
| Aplazada | Media (5.3) | 0.34% | — | ROX Appointment BookingAI | 16/9/2026 | 17/9/2026 | The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes stored on each service and category. | |
| Aplazada | Media (5.3) | 0.34% | — | ROX Appointment BookingAI | 16/9/2026 | 17/9/2026 | The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthenticated attackers to read staff email addresses, phone numbers, private internal notes and the linked WordPress account name for every agent. | |
| Aplazada | Media (6.4) | 0.24% | — | Booking FOR Appointments AND Events CalendarAI | 12/9/2026 | 14/9/2026 | The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of… | |
| Aplazada | Media (5.3) | 0.32% | — | ROX Appointment BookingAI | 12/9/2026 | 14/9/2026 | The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking… | |
| Aplazada | Media (5.3) | 0.34% | — | ROX Appointment BookingAI | 12/9/2026 | 14/9/2026 | The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method… | |
| Aplazada | Media (6.5) | 0.34% | — | ROX Appointment BookingAI | 12/9/2026 | 14/9/2026 | The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner… | |
| Aplazada | Alta (7.2) | 0.46% | — | Ameliabooking Booking FOR Appointments AND Events CalendarAI | 12/9/2026 | 14/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address… | |
| Aplazada | Media (5.3) | 0.30% | — | Booking FOR Appointments AND Events CalendarAI | 12/9/2026 | 14/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an… | |
| Aplazada | Alta (7.1) | 0.25% | — | Easyappointments Easy AppointmentsAI | 8/9/2026 | 8/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Doctor Appointment SystemAI | 4/9/2026 | 4/9/2026 | A flaw has been found in code-projects Doctor Appointment System 1.0. This issue affects some unknown processing of the file /contactus.php. This manipulation of the argument firstname causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Doctor Appointment SystemAI | 4/9/2026 | 11/9/2026 | A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Doctor Appointment SystemAI | 3/9/2026 | 5/9/2026 | A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Crítica (9.3) | 0.40% | — | VikappointmentsAI | 3/9/2026 | 3/9/2026 | Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. | |
| Aplazada | Alta (8.8) | 0.20% | — | Simply Schedule AppointmentsAI | 2/9/2026 | 4/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions. | |
| Aplazada | Media (5.3) | 0.22% | — | Motopress Appointment BookingAI | 2/9/2026 | 3/9/2026 | The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of… | |
| Aplazada | Media (6.5) | 0.30% | — | Booking FOR Appointments AND Events CalendarAI | 2/9/2026 | 3/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier. | |
| Aplazada | Baja (2.7) | 0.28% | — | Booking FOR Appointments AND Events CalendarAI | 29/8/2026 | 31/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were… | |
| Aplazada | Alta (7.5) | 0.36% | — | Appointment Booking Calendar Plugin AND Scheduling PluginAI | 29/8/2026 | 31/8/2026 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price. | |
| Aplazada | Media (6.5) | 0.30% | — | Booking FOR Appointments AND Events CalendarAI | 26/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks. | |
| Aplazada | Media (4.7) | 0.20% | — | Booking FOR Appointments AND Events CalendarAI | 26/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Bookingpress Appointment Booking PROAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | |
| Aplazada | Baja (2.7) | 0.32% | — | Easyappointments Easy AppointmentsAI | 19/8/2026 | 26/8/2026 | The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses. | |
| Aplazada | Alta (8.8) | 0.54% | — | Booking Calendar Appointment Booking SystemAI | 19/8/2026 | 26/8/2026 | The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary… | |
| Aplazada | Media (6.5) | 0.33% | — | Appointment Booking SystemAI | 18/8/2026 | 20/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. |