Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
372 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.8) | 0.40% | — | Openreception Appointment Booking SoftwareAI | 6/8/2026 | 8/9/2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. The throttle rows live in the central `challenge_throttle` table, which is shared across all tenants. Every tenant's… | |
| Aplazada | Baja (2.7) | 0.32% | — | Easyappointments Easy AppointmentsAI | 6/8/2026 | 26/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary… | |
| Aplazada | Alta (7.1) | 0.25% | — | Simply Schedule AppointmentsAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Simply Schedule AppointmentsAI | 6/8/2026 | 12/8/2026 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. | |
| Aplazada | Alta (7.5) | 0.54% | — | VikappointmentsAI | 5/8/2026 | 12/8/2026 | VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper validation or sanitization. Because this value… | |
| Aplazada | Media (6.5) | 0.34% | — | Simply Schedule AppointmentsAI | 3/8/2026 | 26/8/2026 | The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails open for non-staff users, allowing users with the Contributor role and above to disclose all customers' appointment records,… | |
| Aplazada | Alta (7.5) | 0.41% | 💥 PoC | Simply Schedule AppointmentsAI | 2/8/2026 | 26/8/2026 | The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions, to permanently delete them. | |
| Aplazada | Baja (2.7) | 0.28% | — | Booking FOR Appointments AND Events CalendarAI | 1/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a user with the Amelia Manager role to modify arbitrary columns of any stored user record by supplying them in the import request. | |
| Aplazada | Media (5.3) | 0.34% | — | Appointment Booking PluginAI | 30/7/2026 | 30/7/2026 | The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated visitor can set through its public booking funnel, allowing an unauthenticated user to assign a privileged booking field such as the approval status and thereby bypass the site's booking approval… | |
| Aplazada | Media (4.3) | 0.29% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer… | |
| Aplazada | Media (4.3) | 0.27% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier. | |
| Aplazada | Baja (3.8) | 0.32% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system. | |
| Aplazada | Baja (3.8) | 0.26% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and… | |
| Aplazada | Baja (2.7) | 0.32% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information. | |
| Aplazada | Alta (8.6) | 0.45% | — | Online Scheduling AND Appointment Booking SystemAI | 30/7/2026 | 30/7/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive… | |
| Aplazada | Media (5.4) | 0.23% | — | Easyappointments Easy AppointmentsAI | 29/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an… | |
| Aplazada | Crítica (9.1) | 1.2% | 💥 Exploit | EasyappointmentsAICodeigniterAI | 27/7/2026 | 30/7/2026 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema… | |
| Aplazada | Alta (8.2) | 0.43% | 💥 PoC | Bookingpress Appointment Booking PROAI | 27/7/2026 | 27/7/2026 | The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings. | |
| Aplazada | Media (6.1) | 0.25% | — | Simply Schedule AppointmentsAI | 27/7/2026 | 27/7/2026 | Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Schedule Appointments… | |
| Aplazada | Alta (8.1) | 0.40% | — | Easyappointments Easy AppointmentsAI | 24/7/2026 | 24/7/2026 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.22% | — | Dwbooster Appointment Hour BookingAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. | |
| Aplazada | Media (6.5) | 0.33% | 💥 PoC | Easyappointments Easy AppointmentsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions. | |
| Aplazada | Media (5.4) | 0.14% | — | Appointment Booking PluginAI | 16/7/2026 | 16/7/2026 | The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway,… | |
| Aplazada | Alta (7.1) | 0.32% | — | EasyappointmentsAI | 14/7/2026 | 14/7/2026 | Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging to other users. Using these hashes, an attacker can modify or delete appointments of other providers,… | |
| Aplazada | Baja (3.1) | 0.21% | — | Easyappointments Easy AppointmentsAI | 14/7/2026 | 14/7/2026 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and `oauth_callback` saves the issued Google OAuth token against that row without checking the caller owns the… |