Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
314 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.48% | — | Restaurant ZoneAI | 17/6/2026 | 17/6/2026 | Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions. | |
| Aplazada | Alta (7.5) | 0.43% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 2/6/2026 | 22/7/2026 | Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Five Star Restaurant Reservations: from n/a through 2.7.14. | |
| Aplazada | Media (5.3) | 0.24% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 30/4/2026 | 17/6/2026 | The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function using a PHP loose comparison (==) between the attacker-controlled payment_id POST parameter and the booking's… | |
| Analizada | Media (6.6) | 0.19% | — | Saurabh-kumar Python-dotenv | 20/4/2026 | 17/6/2026 | python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()` in python-dotenv follow symbolic links when rewriting `.env` files, allowing a local attacker to overwrite arbitrary files via a crafted symlink when a cross-device… | |
| Aplazada | Media (5.4) | 0.30% | — | Restaurant CafeteriaAI | 28/3/2026 | 17/6/2026 | The Restaurant Cafeteria WordPress theme through 0.4.6 exposes insecure admin-ajax actions without nonce or capability checks, allowing any logged-in user, like subscriber, to perform privileged operations. An attacker can install and activate a from a user-supplied URL, leading to arbitrary PHP code execution, and… | |
| Analizada | Alta (8.8) | 0.47% | — | Wecodex Restaurant CMS | 26/3/2026 | 17/6/2026 | Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the username parameter. Attackers can send POST requests to the login endpoint with malicious SQL payloads using boolean-based blind or time-based blind… | |
| Aplazada | Media (6.5) | 0.21% | — | Rustaurius Five Star Restaurant ReservationsAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.9. | |
| Aplazada | Alta (7.1) | 0.23% | — | E4jvikwp VikrestaurantsAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Reflected XSS.This issue affects VikRestaurants: from n/a through <= 1.5.2. | |
| Aplazada | Media (5.3) | 0.29% | — | Rarathemes Restaurant AND CafeAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme Restaurant and Cafe restaurant-and-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restaurant and Cafe: from n/a through <= 1.2.5. | |
| Aplazada | Crítica (9.8) | 0.40% | — | Themegoods Grand RestaurantAI | 19/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.10. | |
| Aplazada | Media (4.3) | 0.15% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 2/2/2026 | 17/6/2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.9 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting bookings via CSRF attacks. | |
| Aplazada | Media (5.3) | 0.30% | — | Thingsforrestaurants Quick Restaurant ReservationsAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Alejandro Quick Restaurant Reservations quick-restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Restaurant Reservations: from n/a through <= 1.6.7. | |
| Aplazada | Media (6.5) | 0.27% | — | Themegoods Grand Restaurant Theme Elements FOR ElementorAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant Theme Elements for Elementor grandrestaurant-elementor allows Stored XSS.This issue affects Grand Restaurant Theme Elements for Elementor: from n/a through <= 2.1.1. | |
| Aplazada | Alta (7.1) | 0.30% | — | Ayecode RestauranteAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ayecode Restaurante restaurante allows Reflected XSS.This issue affects Restaurante: from n/a through <= 3.0.7. | |
| Modificada | Alta (7.1) | 0.22% | — | Themegoods Grand Restaurant | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Reflected XSS.This issue affects Grand Restaurant: from n/a through < 7.0.9. | |
| Aplazada | Media (6.4) | 0.33% | — | Snillrik RestaurantAI | 7/1/2026 | 17/6/2026 | The Snillrik Restaurant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'menu_style' shortcode attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Alta (8.6) | 0.27% | — | Rustaurius Five Star Restaurant ReservationsAI | 5/1/2026 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.4. | |
| Aplazada | Media (5.4) | 0.12% | — | Rustaurius Five Star Restaurant ReservationsAI | 24/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Cross Site Request Forgery.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.8. | |
| Aplazada | Media (6.1) | 0.21% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 21/12/2025 | 17/6/2026 | The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.5) | 0.34% | — | Motopress Mp-restaurant-menuAI | 18/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Retrieve Embedded Sensitive Data.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.7. | |
| Analizada | Alta (7.5) | 0.24% | 💥 PoC | Abacre Restaurant Point OF Sale | 3/12/2025 | 17/6/2026 | Abacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license keys in process memory during an activation attempt. | |
| Aplazada | Baja (2.1) | 0.32% | — | Jairiidriss RestaurantwebsiteAI | 1/12/2025 | 3/9/2026 | A vulnerability was determined in jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654. Impacted is an unknown function of the component Make a Reservation. This manipulation of the argument selected_date causes cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (6.5) | 0.24% | — | Hackerwhale Restaurant Website Restoran | 19/11/2025 | 17/6/2026 | Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form page. | |
| Aplazada | Alta (7.2) | 0.64% | 💥 PoC | Alex Reservations Smart Restaurant BookingAI | 8/11/2025 | 17/6/2026 | The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /wp-json/srr/v1/app/upload/file REST endpoint in all versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with Administrator-level… | |
| Aplazada | Media (6.5) | 0.32% | — | Gaurav Aggarwal Backup AND MoveAI | 6/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Gaurav Aggarwal Backup and Move backup-and-move allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Backup and Move: from n/a through <= 0.1. |