Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

103 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.23%—Vikwp Vikbooking Hotel Booking Engine & PMS23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions.
ModificadaMedia (4.8)0.39%—Vikwp Vikbooking Hotel Booking Engine & PMS6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.11 versions.
ModificadaAlta (8)0.39%—Thimpress WP Hotel Booking22/8/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.
ModificadaAlta (7.2)0.83%—Online Hotel Booking Project Online Hotel Booking12/7/202217/6/2026
A vulnerability was found in Online Hotel Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file edit_room_cat.php of the component Room Handler. The manipulation of the argument roomname leads to sql injection. The attack may be launched remotely. The exploit…
ModificadaAlta (7.2)0.83%—Online Hotel Booking Project Online Hotel Booking12/7/202217/6/2026
A vulnerability has been found in Online Hotel Booking System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file edit_all_room.php of the component Room Handler. The manipulation of the argument id with the input…
ModificadaCrítica (9.8)1.2%—Bestsoftinc Online Hotel Booking System30/6/202217/6/2026
A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the…
ModificadaAlta (8.8)0.91%—Bestsoftinc Online Hotel Booking System30/6/202217/6/2026
A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unknown function of the file /front/roomtype-details.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
ModificadaMedia (5.4)0.51%—Nicdark Hotel Booking15/6/202217/6/2026
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark's Hotel Booking plugin <= 3.0 at WordPress.
ModificadaAlta (7.2)1.5%—Vikwp Hotel Booking Engine & PMS16/5/202217/6/2026
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malicious PHP code
ModificadaMedia (4.8)0.60%—Vikwp Hotel Booking Engine & PMS16/5/202217/6/2026
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
ModificadaMedia (6.5)0.54%—Vikwp Hotel Booking Engine & PMS16/5/202217/6/2026
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields when outputting them In attributes. As a result, attackers could make a logged in admin add tracking campaign with XSS payloads in them via…
ModificadaMedia (5.3)1.1%—Vikwp Vikbooking Hotel Booking Engine & Property Management System Plugin19/4/202217/6/2026
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests.
ModificadaCrítica (9.8)1.7%—Vikwp Vikbooking Hotel Booking Engine & Property Management System Plugin19/4/202217/6/2026
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.
ModificadaCrítica (9.8)16%💥 ExploitThimpress WP Hotel Booking3/3/202117/6/2026
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.
ModificadaMedia (5.4)0.60%—Online Hotel Booking System PRO Project Online Hotel Booking System PRO27/8/202017/6/2026
Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags.
ModificadaMedia (6.1)1.2%—Online Hotel Booking System Project Online Hotel Booking System5/7/202017/6/2026
An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields.
ModificadaCrítica (9.8)2.2%—Scriptzee Hotel Booking Engine19/6/201917/6/2026
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
ModificadaMedia (6.5)1.1%—Hotel Booking Script Project Hotel Booking Script10/8/201817/6/2026
PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, or Address field.
ModificadaMedia (5.4)0.55%—Hotel Booking Script Project Hotel Booking Script10/8/201817/6/2026
PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.
ModificadaCrítica (9.1)2.3%—Google-adsense-and-hotel-booking Project Google-adsense-and-hotel-booking6/10/201617/6/2026
Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05
ModificadaMedia (4.3)3.3%💥 ExploitBestsoftinc Advance Hotel Booking System11/6/201417/6/2026
Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
ModificadaAlta (7.5)2.2%💥 ExploitUseasdf 4444 Hotel Booking Portal11/4/201216/6/2026
SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote attackers to execute arbitrary SQL commands via the country parameter.
ModificadaAlta (7.5)0.99%💥 ExploitBestsoftinc Advance Hotel Booking System8/7/201116/6/2026
SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.
ModificadaAlta (7.5)1.00%💥 ExploitTourismscripts Tourism Script Accomodation Hotel Booking Portal Script18/1/201016/6/2026
Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attackers to execute arbitrary SQL commands via the hotel_id parameter to (1) hotel.php, (2) details.php, (3) roomtypes.php, (4) photos.php, (5) map.php, (6) weather.php, (7) reviews.php, and (8) book.php.
ModificadaAlta (7.5)0.97%💥 ExploitJoomlahbs COM LowcosthotelsJoomlahbs Hotel Booking Reservation System8/1/200916/6/2026
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.
Orbitaley — Vulnerabilidades