Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1060 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.38% | — | Event Booking ManagerAI | 17/9/2026 | 18/9/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys. | |
| Aplazada | Baja (3.7) | 0.26% | — | Event Booking Manager FOR WoocommerceAI | 17/9/2026 | 18/9/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom… | |
| Aplazada | Media (5.3) | 0.31% | — | Dwbooster Appointment Hour BookingAI | 16/9/2026 | 16/9/2026 | The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully booked. | |
| Aplazada | Media (5.3) | 0.34% | — | ROX Appointment BookingAI | 16/9/2026 | 17/9/2026 | The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing unauthenticated attackers to read the private internal notes stored on each service and category. | |
| Aplazada | Media (5.3) | 0.34% | — | ROX Appointment BookingAI | 16/9/2026 | 17/9/2026 | The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthenticated attackers to read staff email addresses, phone numbers, private internal notes and the linked WordPress account name for every agent. | |
| Aplazada | Alta (7.5) | 1.6% | 💥 Exploit | Booking-wp-plugin BooklyAI | 16/9/2026 | 17/9/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.2) | 0.40% | — | Motopress Hotel BookingAI | 15/9/2026 | 16/9/2026 | The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.4) | 0.24% | — | Booking FOR Appointments AND Events CalendarAI | 12/9/2026 | 14/9/2026 | The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of… | |
| Aplazada | Media (5.3) | 0.32% | — | ROX Appointment BookingAI | 12/9/2026 | 14/9/2026 | The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking… | |
| Aplazada | Media (5.3) | 0.34% | — | ROX Appointment BookingAI | 12/9/2026 | 14/9/2026 | The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method… | |
| Aplazada | Media (6.5) | 0.34% | — | ROX Appointment BookingAI | 12/9/2026 | 14/9/2026 | The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner… | |
| Aplazada | Alta (7.2) | 0.46% | — | Ameliabooking Booking FOR Appointments AND Events CalendarAI | 12/9/2026 | 14/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address… | |
| Aplazada | Media (5.3) | 0.30% | — | Booking FOR Appointments AND Events CalendarAI | 12/9/2026 | 14/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an… | |
| Aplazada | Alta (7.6) | 0.38% | — | Ameliabooking AmeliaAI | 11/9/2026 | 11/9/2026 | Editor SQL Injection in Amelia <= 2.4.9 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Salonbookingsystem Salon Booking SystemAI | 10/9/2026 | 5/10/2026 | Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.9. | |
| Aplazada | Media (5.4) | 0.21% | — | Booking-wp-plugin BooklyAI | 8/9/2026 | 8/9/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 27.2. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (5.3) | 0.32% | — | E-cab E CAB Taxi Booking ManagerAI | 4/9/2026 | 8/9/2026 | The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing unauthenticated attackers to manipulate the order total down to zero and place real taxi-booking orders at an arbitrary… | |
| Aplazada | Media (6.5) | 0.22% | — | Magepeople Booking AND Rental ManagerAI | 3/9/2026 | 3/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7. | |
| Aplazada | Media (5.9) | 0.32% | — | Fluentbooking PROAI | 3/9/2026 | 5/9/2026 | Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | Liquidthemes Booking HUBAI | 2/9/2026 | 4/9/2026 | Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1. | |
| Aplazada | Media (5.3) | 0.22% | — | Motopress Appointment BookingAI | 2/9/2026 | 3/9/2026 | The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of… | |
| Aplazada | Media (6.5) | 0.30% | — | Booking FOR Appointments AND Events CalendarAI | 2/9/2026 | 3/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier. | |
| Aplazada | Crítica (9.8) | 0.51% | 💥 PoC | Ameliabooking AmeliaAI | 2/9/2026 | 2/9/2026 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to… | |
| Aplazada | Media (6.5) | 0.30% | — | Booking AND Rental ManagerAI | 31/8/2026 | 1/9/2026 | Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions. | |
| Aplazada | Baja (2.7) | 0.28% | — | Booking FOR Appointments AND Events CalendarAI | 29/8/2026 | 31/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were… |