Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

2544 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.42%—Themetechmount TruebookerAI16/9/202616/9/2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…
AplazadaCrítica (9.1)0.46%—Bookstackapp BookstackAI15/9/202616/9/2026
BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers can authenticate at one enabled social…
AplazadaAlta (7.2)0.40%—Motopress Hotel BookingAI15/9/202616/9/2026
The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (5.3)0.27%—3D Flipbook PDF EmbedderAI15/9/202617/9/2026
The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible for unauthenticated attackers to extract sensitive data including the full…
AplazadaMedia (6.9)0.42%—GrowthbookAI14/9/202616/9/2026
GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data warehouse query text, schema, table names,…
AplazadaBaja (2.1)0.32%—Gongshengyue OnlinebooksAI13/9/202616/9/2026
A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column results in sql injection. The attack may…
AplazadaAlta (8.3)0.41%—Open NotebookAI13/9/202624/9/2026
Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application…
AplazadaMedia (5.3)0.34%—Stylemixthemes BookitAI13/9/202614/9/2026
The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.
AplazadaMedia (6.4)0.24%—Booking FOR Appointments AND Events CalendarAI12/9/202614/9/2026
The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of…
AplazadaMedia (5.3)0.32%—ROX Appointment BookingAI12/9/202614/9/2026
The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking…
AplazadaMedia (5.3)0.34%—ROX Appointment BookingAI12/9/202614/9/2026
The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method…
AplazadaMedia (6.5)0.34%—ROX Appointment BookingAI12/9/202614/9/2026
The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner…
AplazadaAlta (7.2)0.46%—Ameliabooking Booking FOR Appointments AND Events CalendarAI12/9/202614/9/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address…
AplazadaMedia (5.3)0.30%—Booking FOR Appointments AND Events CalendarAI12/9/202614/9/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an…
AplazadaMedia (5.3)0.29%—BookticsAI11/9/202611/9/2026
Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions.
AplazadaAlta (7.6)0.38%—Ameliabooking AmeliaAI11/9/202611/9/2026
Editor SQL Injection in Amelia <= 2.4.9 versions.
AplazadaMedia (5.3)0.24%—BookticsAI11/9/202611/9/2026
The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.0.23. This is due to the create_order_permission() permission callback on the POST /wp-json/booktics/v1/orders REST route…
AplazadaMedia (6.5)0.33%—Salonbookingsystem Salon Booking SystemAI10/9/20265/10/2026
Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.9.
Pendiente de análisisAlta (7)0.20%—Facebook Zstd-jniAI9/9/202614/9/2026
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or…
AplazadaMedia (5.4)0.21%—Booking-wp-plugin BooklyAI8/9/20268/9/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 27.2. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaBaja (2.1)0.39%—Bookstackapp BookstackAI7/9/20269/9/2026
A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. The manipulation of the argument ID results in improper access controls. The attack…
AplazadaAlta (7.1)0.42%—Joinbookwyrm BookwyrmAI5/9/20268/9/2026
BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit sequential ReadThrough IDs to overwrite arbitrary users' start dates, finish dates, progress, and progress mode, affecting…
AplazadaMedia (5.3)0.30%—Joinbookwyrm BookwyrmAI5/9/202610/9/2026
BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access. Attackers can POST to the favorite endpoint with a status ID to create unauthorized interactions,…
AplazadaAlta (7.1)0.44%—Joinbookwyrm BookwyrmAI5/9/20268/9/2026
BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the…
AplazadaMedia (6.4)0.36%—Dear FlipbookAI5/9/20268/9/2026
The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom HTML block inner HTML)' parameter in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping. This makes it…