Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1060 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.36% | — | Appointment Booking Calendar Plugin AND Scheduling PluginAI | 29/8/2026 | 31/8/2026 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price. | |
| Aplazada | Alta (7.2) | 0.62% | — | Ameliabooking AmeliaAI | 28/8/2026 | 28/8/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication bypass where the AddBookingCommand explicitly skips nonce verification (Command.php line 186),… | |
| Aplazada | Alta (8.1) | 0.19% | — | Fluentbooking PROAI | 27/8/2026 | 28/8/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions. | |
| Aplazada | Alta (8.8) | 0.52% | — | Booking AND Rental ManagerAI | 27/8/2026 | 28/8/2026 | Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. | |
| Aplazada | Media (5.3) | 0.22% | — | Saasproject Booking PackageAI | 26/8/2026 | 26/8/2026 | The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a service's real price. | |
| Aplazada | Media (6.5) | 0.30% | — | Booking FOR Appointments AND Events CalendarAI | 26/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks. | |
| Aplazada | Media (4.7) | 0.20% | — | Booking FOR Appointments AND Events CalendarAI | 26/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account. | |
| Aplazada | Alta (8.8) | 0.42% | — | Booking HUBAI | 24/8/2026 | 26/8/2026 | Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Booking AND Rental ManagerAI | 24/8/2026 | 24/8/2026 | Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions. | |
| Aplazada | Media (4.3) | 0.28% | — | Woocommerce BookingsAI | 23/8/2026 | 26/8/2026 | The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products. | |
| Aplazada | Media (6.5) | 0.22% | — | Wp-base WP Base BookingAI | 20/8/2026 | 20/8/2026 | Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Bookingpress Appointment Booking PROAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | Taxi Booking ManagerAI | 19/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions. | |
| Aplazada | Alta (8.8) | 0.54% | — | Booking Calendar Appointment Booking SystemAI | 19/8/2026 | 26/8/2026 | The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary… | |
| Aplazada | Media (6.5) | 0.33% | — | Appointment Booking SystemAI | 18/8/2026 | 20/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. | |
| Aplazada | Media (6.5) | 0.35% | — | Dwbooster Appointment Hour BookingAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Gravityforms BookingsAI | 18/8/2026 | 20/8/2026 | Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | |
| Aplazada | Alta (7.2) | 0.58% | — | Booking-wp-plugin BooklyAI | 16/8/2026 | 20/8/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, and including, 27.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.68% | — | Simply Schedule Appointments Appointment Booking CalendarAI | 16/8/2026 | 20/8/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.39% | — | Booking-wp-plugin BooklyAI | 16/8/2026 | 20/8/2026 | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabinet/api/handlers/Handler1_0.php. This is… | |
| Aplazada | Media (6.4) | 0.36% | — | Hydra BookingAI | 15/8/2026 | 20/8/2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.55% | — | Booking CalendarAI | 15/8/2026 | 20/8/2026 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark… | |
| Aplazada | Alta (7.2) | 0.40% | — | Vcita Online Booking Scheduling CalendarAI | 15/8/2026 | 20/8/2026 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (5.3) | 0.61% | — | Pinpoint Booking SystemAI | 15/8/2026 | 20/8/2026 | The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and including, 2.9.9.6.8. This is due to the `dopbsp_woocommerce_add_to_cart` AJAX action being registered via `wp_ajax_nopriv_*` with no authentication, no nonce… | |
| Aplazada | Media (4.3) | 0.18% | — | Astro Booking EngineAI | 14/8/2026 | 29/9/2026 | The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request… |