Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

1060 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.36%—Appointment Booking Calendar Plugin AND Scheduling PluginAI29/8/202631/8/2026
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.
AplazadaAlta (7.2)0.62%—Ameliabooking AmeliaAI28/8/202628/8/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication bypass where the AddBookingCommand explicitly skips nonce verification (Command.php line 186),…
AplazadaAlta (8.1)0.19%—Fluentbooking PROAI27/8/202628/8/2026
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
AplazadaAlta (8.8)0.52%—Booking AND Rental ManagerAI27/8/202628/8/2026
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
AplazadaMedia (5.3)0.22%—Saasproject Booking PackageAI26/8/202626/8/2026
The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a service's real price.
AplazadaMedia (6.5)0.30%—Booking FOR Appointments AND Events CalendarAI26/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
AplazadaMedia (4.7)0.20%—Booking FOR Appointments AND Events CalendarAI26/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account.
AplazadaAlta (8.8)0.42%—Booking HUBAI24/8/202626/8/2026
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
AplazadaMedia (5.3)0.31%—Booking AND Rental ManagerAI24/8/202624/8/2026
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.
AplazadaMedia (4.3)0.28%—Woocommerce BookingsAI23/8/202626/8/2026
The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.
AplazadaMedia (6.5)0.22%—Wp-base WP Base BookingAI20/8/202620/8/2026
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
AplazadaCrítica (9.3)0.40%—Bookingpress Appointment Booking PROAI20/8/202620/8/2026
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
AplazadaMedia (6.5)0.30%—Taxi Booking ManagerAI19/8/202620/8/2026
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.
AplazadaAlta (8.8)0.54%—Booking Calendar Appointment Booking SystemAI19/8/202626/8/2026
The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary…
AplazadaMedia (6.5)0.33%—Appointment Booking SystemAI18/8/202620/8/2026
Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.
AplazadaMedia (6.5)0.35%—Dwbooster Appointment Hour BookingAI18/8/202620/8/2026
Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.
AplazadaAlta (8.5)0.36%—Gravityforms BookingsAI18/8/202620/8/2026
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
AplazadaAlta (7.2)0.58%—Booking-wp-plugin BooklyAI16/8/202620/8/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, and including, 27.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaMedia (6.5)0.68%—Simply Schedule Appointments Appointment Booking CalendarAI16/8/202620/8/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. This makes it possible for…
AplazadaMedia (4.3)0.39%—Booking-wp-plugin BooklyAI16/8/202620/8/2026
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabinet/api/handlers/Handler1_0.php. This is…
AplazadaMedia (6.4)0.36%—Hydra BookingAI15/8/202620/8/2026
The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.55%—Booking CalendarAI15/8/202620/8/2026
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark…
AplazadaAlta (7.2)0.40%—Vcita Online Booking Scheduling CalendarAI15/8/202620/8/2026
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
AplazadaMedia (5.3)0.61%—Pinpoint Booking SystemAI15/8/202620/8/2026
The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and including, 2.9.9.6.8. This is due to the `dopbsp_woocommerce_add_to_cart` AJAX action being registered via `wp_ajax_nopriv_*` with no authentication, no nonce…
AplazadaMedia (4.3)0.18%—Astro Booking EngineAI14/8/202629/9/2026
The Astro Booking Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing nonce validation on the options deletion functionality. This makes it possible for unauthenticated attackers to delete all plugin settings via a forged request…
Orbitaley — Vulnerabilidades