Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.39% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can submit unlimited wrong passphrase guesses against any known email address, capped only by the Argon2 verification cost… | |
| Aplazada | Media (6.5) | 0.36% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, applies no schema validation to the message body, writes attacker-controlled content directly into the application's stdout… | |
| Aplazada | Baja (3.7) | 0.39% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at `/api/tenants/{id}/appointments/bootstrap-challenge` issues a SHA-256 proof-of-work with `difficulty=4` hex zeros, equivalent to 16 bits of work.… | |
| Aplazada | Alta (8.1) | 0.24% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` configuration (`website`, `imprint`, `privacyStatement`). These values are returned to the patient-facing landing page… | |
| Aplazada | Alta (8) | 0.47% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the full tenant record to any authenticated `TENANT_ADMIN` of that tenant, including the `databaseUrl` field. This field contains the live… | |
| Aplazada | Alta (7.4) | 0.50% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side load handler deletes the `access_token` cookie before calling `/api/auth/logout` via an internal `event.fetch()`. The… | |
| Aplazada | Media (5.3) | 0.34% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a tenant regardless of the channel's `isPublic` flag. Channels marked `isPublic = false`… | |
| Aplazada | Media (5.3) | 0.43% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}` performs no authorization check before returning the appointment record. Any party who knows or obtains a valid… | |
| Aplazada | Media (6.5) | 0.33% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap-challenge` (returns a 16-bit PoW challenge with `difficulty=4` leading hex zeroes), `bootstrap-verify` (validates the… | |
| Aplazada | Media (6.5) | 0.42% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunnel` endpoint creates a new appointment row in any client tunnel without any caller authentication. A request that supplies any valid `tunnelId` and any valid `emailHash`… | |
| Aplazada | Baja (2.7) | 0.29% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing staff user, the underlying `StaffService.deleteStaffMember()` runs an additional invite cleanup that deletes from the central `user_invite` table… | |
| Aplazada | Media (5.8) | 0.40% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. The throttle rows live in the central `challenge_throttle` table, which is shared across all tenants. Every tenant's… | |
| Aplazada | Media (5.3) | 0.34% | — | Appointment Booking PluginAI | 30/7/2026 | 30/7/2026 | The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval… | |
| Aplazada | Alta (8.6) | 0.45% | — | Online Scheduling AND Appointment Booking SystemAI | 30/7/2026 | 30/7/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive… | |
| Aplazada | Alta (8.2) | 0.43% | 💥 PoC | Bookingpress Appointment Booking PROAI | 27/7/2026 | 27/7/2026 | The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings. | |
| Aplazada | Media (5.4) | 0.14% | — | Appointment Booking PluginAI | 16/7/2026 | 16/7/2026 | The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway,… | |
| Aplazada | Alta (8.1) | 0.65% | — | Appointment Booking Calendar Plugin AND Scheduling PluginAI | 8/7/2026 | 8/7/2026 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to… | |
| Aplazada | Media (5.3) | 0.56% | — | Motopress Appointment BookingAI | 3/7/2026 | 6/7/2026 | The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This is due to the `POST /motopress/appointment/v1/bookings` REST endpoint being registered with `'permission_callback' => '__return_true'`, allowing… | |
| Aplazada | Media (6.5) | 0.45% | — | Motopress Appointment BookingAI | 1/7/2026 | 1/7/2026 | The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 2.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (7.5) | 0.46% | — | Bookingpress Appointment Booking PROAI | 1/7/2026 | 1/7/2026 | The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is… | |
| Aplazada | Media (4.3) | 0.39% | — | Appointment Booking CalendarAI | 1/7/2026 | 1/7/2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email… | |
| Aplazada | Media (6.4) | 0.33% | — | Appointment Booking CalendarAI | 19/6/2026 | 22/6/2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and… | |
| Aplazada | Media (4.3) | 0.28% | — | Appointment Booking CalendarAI | 18/6/2026 | 18/6/2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabc_appointments_calendar_load2() function, which is reachable via the… | |
| Aplazada | Media (5.1) | 0.24% | — | Appointment Booking CalendarAI | 15/6/2026 | 17/6/2026 | WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify calendar settings and inject persistent cross-site scripting payloads through the admin.php page parameters. Attackers can inject malicious JavaScript into the 'ict' and… | |
| Aplazada | Alta (7.5) | 0.67% | — | Simplyscheduleappointments Appointment Booking CalendarAI | 28/5/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied parameter and lack of sufficient… |