Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.23% | — | Vikwp Vikbooking Hotel Booking Engine & PMS | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Vikwp Vikbooking Hotel Booking Engine & PMS | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.11 versions. | |
| Modificada | Alta (8) | 0.39% | — | Thimpress WP Hotel Booking | 22/8/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress. | |
| Modificada | Alta (7.2) | 0.83% | — | Online Hotel Booking Project Online Hotel Booking | 12/7/2022 | 17/6/2026 | A vulnerability was found in Online Hotel Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file edit_room_cat.php of the component Room Handler. The manipulation of the argument roomname leads to sql injection. The attack may be launched remotely. The exploit… | |
| Modificada | Alta (7.2) | 0.83% | — | Online Hotel Booking Project Online Hotel Booking | 12/7/2022 | 17/6/2026 | A vulnerability has been found in Online Hotel Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file edit_all_room.php of the component Room Handler. The manipulation of the argument id with the input… | |
| Modificada | Crítica (9.8) | 1.2% | — | Bestsoftinc Online Hotel Booking System | 30/6/2022 | 17/6/2026 | A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.91% | — | Bestsoftinc Online Hotel Booking System | 30/6/2022 | 17/6/2026 | A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unknown function of the file /front/roomtype-details.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Media (5.4) | 0.51% | — | Nicdark Hotel Booking | 15/6/2022 | 17/6/2026 | Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin <= 3.0 at WordPress. | |
| Modificada | Alta (7.2) | 1.5% | — | Vikwp Hotel Booking Engine & PMS | 16/5/2022 | 17/6/2026 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malicious PHP code | |
| Modificada | Media (4.8) | 0.60% | — | Vikwp Hotel Booking Engine & PMS | 16/5/2022 | 17/6/2026 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed | |
| Modificada | Media (6.5) | 0.54% | — | Vikwp Hotel Booking Engine & PMS | 16/5/2022 | 17/6/2026 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields when outputting them In attributes. As a result, attackers could make a logged in admin add tracking campaign with XSS payloads in them via… | |
| Modificada | Media (5.3) | 1.1% | — | Vikwp Vikbooking Hotel Booking Engine & Property Management System Plugin | 19/4/2022 | 17/6/2026 | Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests. | |
| Modificada | Crítica (9.8) | 1.7% | — | Vikwp Vikbooking Hotel Booking Engine & Property Management System Plugin | 19/4/2022 | 17/6/2026 | Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form. | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Thimpress WP Hotel Booking | 3/3/2021 | 17/6/2026 | The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php. | |
| Modificada | Media (5.4) | 0.60% | — | Online Hotel Booking System PRO Project Online Hotel Booking System PRO | 27/8/2020 | 17/6/2026 | Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags. | |
| Modificada | Media (6.1) | 1.2% | — | Online Hotel Booking System Project Online Hotel Booking System | 5/7/2020 | 17/6/2026 | An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields. | |
| Modificada | Crítica (9.8) | 2.2% | — | Scriptzee Hotel Booking Engine | 19/6/2019 | 17/6/2026 | SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter. | |
| Modificada | Media (6.5) | 1.1% | — | Hotel Booking Script Project Hotel Booking Script | 10/8/2018 | 17/6/2026 | PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, or Address field. | |
| Modificada | Media (5.4) | 0.55% | — | Hotel Booking Script Project Hotel Booking Script | 10/8/2018 | 17/6/2026 | PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field. | |
| Modificada | Crítica (9.1) | 2.3% | — | Google-adsense-and-hotel-booking Project Google-adsense-and-hotel-booking | 6/10/2016 | 17/6/2026 | Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05 | |
| Modificada | Media (4.3) | 3.3% | 💥 Exploit | Bestsoftinc Advance Hotel Booking System | 11/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Useasdf 4444 Hotel Booking Portal | 11/4/2012 | 16/6/2026 | SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote attackers to execute arbitrary SQL commands via the country parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Bestsoftinc Advance Hotel Booking System | 8/7/2011 | 16/6/2026 | SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Tourismscripts Tourism Script Accomodation Hotel Booking Portal Script | 18/1/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attackers to execute arbitrary SQL commands via the hotel_id parameter to (1) hotel.php, (2) details.php, (3) roomtypes.php, (4) photos.php, (5) map.php, (6) weather.php, (7) reviews.php, and (8) book.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomlahbs COM LowcosthotelsJoomlahbs Hotel Booking Reservation System | 8/1/2009 | 16/6/2026 | SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php. |