Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

136 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3.8)0.26%—Booking FOR Appointments AND Events CalendarAI10/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating…
AplazadaBaja (2.7)0.32%—Easyappointments Easy AppointmentsAI6/8/202626/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary…
AplazadaAlta (7.1)0.25%—Simply Schedule AppointmentsAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
AplazadaCrítica (9.3)0.40%—Simply Schedule AppointmentsAI6/8/202612/8/2026
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
AplazadaAlta (7.5)0.54%—VikappointmentsAI5/8/202612/8/2026
VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper validation or sanitization. Because this value…
AplazadaMedia (6.5)0.34%—Simply Schedule AppointmentsAI3/8/202626/8/2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records,…
AplazadaAlta (7.5)0.41%💥 PoCSimply Schedule AppointmentsAI2/8/202626/8/2026
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them.
AplazadaBaja (2.7)0.28%—Booking FOR Appointments AND Events CalendarAI1/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request.
AplazadaMedia (4.3)0.29%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer…
AplazadaMedia (4.3)0.27%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.
AplazadaBaja (3.8)0.32%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.
AplazadaBaja (3.8)0.26%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and…
AplazadaBaja (2.7)0.32%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.
AplazadaMedia (5.4)0.23%—Easyappointments Easy AppointmentsAI29/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an…
AplazadaCrítica (9.1)1.2%💥 ExploitEasyappointmentsAICodeigniterAI27/7/202630/7/2026
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema…
AplazadaMedia (6.1)0.25%—Simply Schedule AppointmentsAI27/7/202627/7/2026
Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments…
AplazadaAlta (8.1)0.40%—Easyappointments Easy AppointmentsAI24/7/202624/7/2026
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.5)0.33%💥 PoCEasyappointments Easy AppointmentsAI23/7/202623/7/2026
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
AplazadaAlta (7.1)0.32%—EasyappointmentsAI14/7/202614/7/2026
Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging to other users. Using these hashes, an attacker can modify or delete appointments of other providers,…
AplazadaBaja (3.1)0.21%—Easyappointments Easy AppointmentsAI14/7/202614/7/2026
Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and `oauth_callback` saves the issued Google OAuth token against that row without checking the caller owns the…
AplazadaBaja (2.7)0.31%—Easyappointments Easy AppointmentsAI14/7/202615/7/2026
Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzzle `REPORT` call without scheme or host validation. A logged-in backend user (admin, provider, or secretary) reaches…
AplazadaBaja (3.3)0.23%—Easyappointments Easy AppointmentsAI14/7/202629/7/2026
Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended security boundary. However, the direct mutation endpoints `appointments/store` and `appointments/update`…
AplazadaBaja (2.6)0.24%—Easyappointments Easy AppointmentsAI14/7/202614/7/2026
Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the `disable_booking_message` setting via a rich-text editor and later passed directly to the public…
AplazadaMedia (6.9)0.56%—Easyappointments Easy AppointmentsAI14/7/202629/7/2026
Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the entire customer record as inline JavaScript (`const vars = {... "customer_data": {...}, ...}`)…
AplazadaMedia (6.5)0.27%—Nsquared Simply Schedule AppointmentsAI13/7/202613/7/2026
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.11.11.
Orbitaley — Vulnerabilidades