Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

2544 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.35%—Dear FlipbookAI5/9/20268/9/2026
The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class attribute of .dvcss element)' parameter in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping. This makes…
AplazadaMedia (5.3)0.32%—E-cab E CAB Taxi Booking ManagerAI4/9/20268/9/2026
The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing unauthenticated attackers to manipulate the order total down to zero and place real taxi-booking orders at an arbitrary…
AplazadaMedia (6.5)0.22%—Magepeople Booking AND Rental ManagerAI3/9/20263/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7.
AplazadaMedia (5.3)0.18%—Stylemixthemes BookitAI3/9/20264/9/2026
Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.
AplazadaMedia (5.9)0.32%—Fluentbooking PROAI3/9/20265/9/2026
Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
AplazadaAlta (8.8)0.42%—Liquidthemes Booking HUBAI2/9/20264/9/2026
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.
AplazadaMedia (5.3)0.22%—Motopress Appointment BookingAI2/9/20263/9/2026
The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of…
AplazadaMedia (6.5)0.30%—Booking FOR Appointments AND Events CalendarAI2/9/20263/9/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier.
AplazadaCrítica (9.8)0.51%💥 PoCAmeliabooking AmeliaAI2/9/20262/9/2026
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to…
AplazadaCrítica (9.3)0.47%—Bookstackapp BookstackAI2/9/20268/9/2026
BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed…
AplazadaMedia (6.5)0.30%—Booking AND Rental ManagerAI31/8/20261/9/2026
Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.
AplazadaAlta (8.7)1.00%—Bookstackapp BookstackAI29/8/202631/8/2026
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename…
AplazadaBaja (2.7)0.28%—Booking FOR Appointments AND Events CalendarAI29/8/202631/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were…
AplazadaAlta (7.5)0.36%—Appointment Booking Calendar Plugin AND Scheduling PluginAI29/8/202631/8/2026
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price.
AplazadaAlta (7.2)0.62%—Ameliabooking AmeliaAI28/8/202628/8/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication bypass where the AddBookingCommand explicitly skips nonce verification (Command.php line 186),…
AplazadaAlta (8.1)0.19%—Fluentbooking PROAI27/8/202628/8/2026
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
AplazadaAlta (8.8)0.52%—Booking AND Rental ManagerAI27/8/202628/8/2026
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
AplazadaMedia (5.3)0.22%—Saasproject Booking PackageAI26/8/202626/8/2026
The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a service's real price.
AplazadaMedia (6.5)0.30%—Booking FOR Appointments AND Events CalendarAI26/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.
AplazadaMedia (4.7)0.20%—Booking FOR Appointments AND Events CalendarAI26/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account.
AplazadaAlta (8.8)0.42%—Booking HUBAI24/8/202626/8/2026
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
AplazadaMedia (5.3)0.41%—Bookstackapp BookstackAI24/8/202624/9/2026
BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery API endpoints. Attackers can supply a user avatar's ID to the…
AplazadaMedia (5.3)0.31%—Booking AND Rental ManagerAI24/8/202624/8/2026
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.
AplazadaMedia (4.3)0.28%—Woocommerce BookingsAI23/8/202626/8/2026
The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.
AplazadaMedia (6.5)0.22%—Wp-base WP Base BookingAI20/8/202620/8/2026
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.