Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1060 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.7) | 0.19% | — | Online Scheduling AND Appointment Booking SystemAI | 27/9/2026 | 28/9/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly… | |
| Aplazada | Baja (3.8) | 0.15% | — | Online Scheduling AND Appointment Booking SystemAI | 27/9/2026 | 28/9/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff… | |
| Aplazada | Media (5.3) | 0.18% | — | Booking-wp-plugin BooklyAI | 25/9/2026 | 25/9/2026 | The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifier to overwrite that customer's stored personal information such as name, email and address. | |
| Aplazada | Alta (7.2) | 0.24% | — | Ba-booking BA Book EverythingAI | 25/9/2026 | 25/9/2026 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Crítica (9.1) | 0.37% | 💥 PoC | Booking-wp-plugin BooklyAI | 25/9/2026 | 26/9/2026 | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the… | |
| Aplazada | Media (5.3) | 0.32% | — | Booking-wp-plugin BooklyAI | 25/9/2026 | 25/9/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2. This is due to the `postValidateCustomer()` function using a loose PHP inequality operator (`!=`) to compare the session-stored… | |
| Aplazada | Alta (7.5) | 0.26% | — | Vcita Online Booking Scheduling CalendarAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions. | |
| Aplazada | Baja (2.7) | 0.18% | — | Event Booking ManagerAI | 23/9/2026 | 23/9/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard… | |
| Aplazada | Media (4.3) | 0.15% | — | Oplugins Booking ManagerAI | 23/9/2026 | 23/9/2026 | The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking… | |
| Aplazada | Media (6.8) | 0.23% | — | Oplugins Booking ManagerAI | 23/9/2026 | 23/9/2026 | The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to perform SQL injection attacks by importing a feed they control. | |
| Aplazada | Alta (7.3) | 0.40% | — | Magepeople Taxi Booking Manager FOR WoocommerceAI | 22/9/2026 | 22/9/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8. | |
| Aplazada | Media (6.1) | 0.37% | — | Booking CalendarAI | 22/9/2026 | 22/9/2026 | The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (5.5) | 0.31% | — | Hydra BookingAI | 19/9/2026 | 21/9/2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-assigned custom role to read, modify and permanently delete other hosts' records and… | |
| Aplazada | Media (4.7) | 0.29% | — | Hydra BookingAI | 19/9/2026 | 21/9/2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does not verify that the host record being modified belongs to the user making the request, allowing authenticated users holding a Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3-assigned… | |
| Aplazada | Baja (3.8) | 0.32% | — | Hydra BookingAI | 19/9/2026 | 21/9/2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booking belongs to the requesting user before modifying or deleting it on two of its booking endpoints, allowing a booking-provider-level user to cancel and permanently delete other providers' bookings on… | |
| Aplazada | Media (4.8) | 0.22% | — | Online Scheduling AND Appointment Booking SystemAI | 19/9/2026 | 21/9/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages… | |
| Aplazada | Alta (7.2) | 0.66% | — | Booking CalendarAI | 18/9/2026 | 18/9/2026 | The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function applies per-option safeguards only to names explicitly registered via… | |
| Aplazada | Media (6.1) | 0.41% | — | Booking CalendarAI | 18/9/2026 | 18/9/2026 | The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Baja (2.7) | 0.32% | — | Bookit Booking Appointment CalendarAI | 18/9/2026 | 18/9/2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment… | |
| Aplazada | Alta (8.8) | 0.51% | — | Igms Direct BookingAI | 18/9/2026 | 18/9/2026 | The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowing unauthenticated users to store arbitrary web scripts that execute in the context of an administrator viewing the iGMS Direct Booking WordPress plugin before 2.0 settings, and in the browser of any… | |
| Aplazada | Alta (8.8) | 0.45% | — | VikbookingAI | 18/9/2026 | 18/9/2026 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation. | |
| Aplazada | Media (5.4) | 0.17% | — | Ameliabooking AmeliaAI | 17/9/2026 | 18/9/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Openreception Appointment Booking SoftwareAI | 17/9/2026 | 30/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an authenticated session, does not call WebAuthnService.verifyRegistration, and does not bind… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Eduadmin BookingAI | 17/9/2026 | 17/9/2026 | Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Booking CalendarAI | 17/9/2026 | 19/9/2026 | Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions. |