Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2544 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.35% | — | Dear FlipbookAI | 5/9/2026 | 8/9/2026 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class attribute of .dvcss element)' parameter in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Media (5.3) | 0.32% | — | E-cab E CAB Taxi Booking ManagerAI | 4/9/2026 | 8/9/2026 | The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing unauthenticated attackers to manipulate the order total down to zero and place real taxi-booking orders at an arbitrary… | |
| Aplazada | Media (6.5) | 0.22% | — | Magepeople Booking AND Rental ManagerAI | 3/9/2026 | 3/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7. | |
| Aplazada | Media (5.3) | 0.18% | — | Stylemixthemes BookitAI | 3/9/2026 | 4/9/2026 | Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. | |
| Aplazada | Media (5.9) | 0.32% | — | Fluentbooking PROAI | 3/9/2026 | 5/9/2026 | Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | Liquidthemes Booking HUBAI | 2/9/2026 | 4/9/2026 | Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1. | |
| Aplazada | Media (5.3) | 0.22% | — | Motopress Appointment BookingAI | 2/9/2026 | 3/9/2026 | The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of… | |
| Aplazada | Media (6.5) | 0.30% | — | Booking FOR Appointments AND Events CalendarAI | 2/9/2026 | 3/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking action chain, allowing an unauthenticated user to trigger booking notifications and integration callbacks for a booking by enumerating its identifier. | |
| Aplazada | Crítica (9.8) | 0.51% | 💥 PoC | Ameliabooking AmeliaAI | 2/9/2026 | 2/9/2026 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to… | |
| Aplazada | Crítica (9.3) | 0.47% | — | Bookstackapp BookstackAI | 2/9/2026 | 8/9/2026 | BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute in administrator browsers when accessed… | |
| Aplazada | Media (6.5) | 0.30% | — | Booking AND Rental ManagerAI | 31/8/2026 | 1/9/2026 | Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions. | |
| Aplazada | Alta (8.7) | 1.00% | — | Bookstackapp BookstackAI | 29/8/2026 | 31/8/2026 | BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by embedding a PHP file with a .php filename… | |
| Aplazada | Baja (2.7) | 0.28% | — | Booking FOR Appointments AND Events CalendarAI | 29/8/2026 | 31/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including approving their own bookings that were… | |
| Aplazada | Alta (7.5) | 0.36% | — | Appointment Booking Calendar Plugin AND Scheduling PluginAI | 29/8/2026 | 31/8/2026 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment approved for a fraction of its price. | |
| Aplazada | Alta (7.2) | 0.62% | — | Ameliabooking AmeliaAI | 28/8/2026 | 28/8/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication bypass where the AddBookingCommand explicitly skips nonce verification (Command.php line 186),… | |
| Aplazada | Alta (8.1) | 0.19% | — | Fluentbooking PROAI | 27/8/2026 | 28/8/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions. | |
| Aplazada | Alta (8.8) | 0.52% | — | Booking AND Rental ManagerAI | 27/8/2026 | 28/8/2026 | Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. | |
| Aplazada | Media (5.3) | 0.22% | — | Saasproject Booking PackageAI | 26/8/2026 | 26/8/2026 | The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a service's real price. | |
| Aplazada | Media (6.5) | 0.30% | — | Booking FOR Appointments AND Events CalendarAI | 26/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks. | |
| Aplazada | Media (4.7) | 0.20% | — | Booking FOR Appointments AND Events CalendarAI | 26/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password and take over their account. | |
| Aplazada | Alta (8.8) | 0.42% | — | Booking HUBAI | 24/8/2026 | 26/8/2026 | Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions. | |
| Aplazada | Media (5.3) | 0.41% | — | Bookstackapp BookstackAI | 24/8/2026 | 24/9/2026 | BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery API endpoints. Attackers can supply a user avatar's ID to the… | |
| Aplazada | Media (5.3) | 0.31% | — | Booking AND Rental ManagerAI | 24/8/2026 | 24/8/2026 | Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions. | |
| Aplazada | Media (4.3) | 0.28% | — | Woocommerce BookingsAI | 23/8/2026 | 26/8/2026 | The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products. | |
| Aplazada | Media (6.5) | 0.22% | — | Wp-base WP Base BookingAI | 20/8/2026 | 20/8/2026 | Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions. |