Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
314 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.60% | — | Phpgurukul Restaurant Table Booking System | 4/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/check_availability.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.57% | — | Phpgurukul Restaurant Table Booking System | 4/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /add-table.php. The manipulation of the argument tableno leads to sql injection. The attack may be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.57% | — | Phpgurukul Restaurant Table Booking System | 4/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /search-result.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (6.5) | 0.43% | — | Phpjabbers Restaurant Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters. | |
| Modificada | Media (5.4) | 0.35% | — | Phpjabbers Restaurant Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "seat_name, plugin_sms_api_key, plugin_sms_country_code, title, name" parameters. | |
| Modificada | Alta (7.5) | 0.75% | — | Phpjabbers Restaurant Booking System | 20/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Forgot Password', 'Email Settings' feature of PHPJabbers Restaurant Booking System v3.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Analizada | Alta (8.8) | 0.61% | — | Phpjabbers Restaurant Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. | |
| Modificada | Media (5.4) | 0.35% | — | Phpjabbers Restaurant Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Restaurant Booking System v3.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Reservations menu, Schedule section date parameter. | |
| Analizada | Media (5.3) | 0.38% | — | Janobe Multi Restaurant Table Reservation System | 12/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0. It has been classified as critical. Affected is an unknown function of the file select-menu.php. The manipulation of the argument table leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.52% | — | Janobe Multi Restaurant Table Reservation System | 12/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/approve-reject.php. The manipulation of the argument breject_id leads to sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Media (6.4) | 0.33% | — | Alex Reservations Smart Restaurant BookingAI | 30/1/2025 | 17/6/2026 | The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rr_form' shortcode in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.35% | — | Saurav Sharma Generate Dummy PostsAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Saurav Sharma Generate Dummy Posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Generate Dummy Posts: from n/a through 1.0.0. | |
| Aplazada | Media (4.3) | 0.36% | — | Best Restaurant Menu BY PricelistoAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in PriceListo Best Restaurant Menu by PriceListo best-restaurant-menu-by-pricelisto.This issue affects Best Restaurant Menu by PriceListo: from n/a through <= 1.4.2. | |
| Modificada | Media (5.4) | 0.41% | — | Nicheaddons Restaurant & Cafe Addon FOR Elementor | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Restaurant & Cafe Addon for Elementor restaurant-cafe-addon-for-elementor allows DOM-Based XSS.This issue affects Restaurant & Cafe Addon for Elementor: from n/a through <= 1.5.8. | |
| Aplazada | Alta (7.3) | 0.52% | — | Redi Restaurant ReservationAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReDi Restaurant Reservation: from n/a through 23.0211. | |
| Modificada | Crítica (9.8) | 0.49% | — | Nicheaddons Restaurant & Cafe Addon FOR Elementor | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in NicheAddons Restaurant & Cafe Addon for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restaurant & Cafe Addon for Elementor: from n/a through 1.5.3. | |
| Analizada | Media (4.3) | 0.39% | — | Nicheaddons Restaurant & Cafe Addon FOR Elementor | 28/11/2024 | 17/6/2026 | The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.9 via the 'narestaurant_elementor_template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.1) | 0.32% | — | Oracle Restaurant Menu - Food Ordering System - Table Reservation | 20/11/2024 | 17/6/2026 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.5) | 0.39% | — | Marco Piarulli MY Restaurant MenuAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Piarulli My Restaurant Menu my-restaurant-menu allows Stored XSS.This issue affects My Restaurant Menu: from n/a through <= 0.2.0. | |
| Aplazada | Media (6.5) | 0.39% | — | Shahjahan Jewel Trendy Restaurant MenuAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shahjahan Jewel Trendy Restaurant Menu trendy-restaurant-menu allows DOM-Based XSS.This issue affects Trendy Restaurant Menu: from n/a through <= 1.0.0. | |
| Modificada | Media (5.4) | 0.26% | — | Nicheaddons Restaurant & Cafe Addon FOR Elementor | 10/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Restaurant & Cafe Addon for Elementor restaurant-cafe-addon-for-elementor allows Stored XSS.This issue affects Restaurant & Cafe Addon for Elementor: from n/a through <= 1.5.6. | |
| Aplazada | Alta (7.1) | 0.29% | — | Laura20 Wp-basicsAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in laura20 WP-Basics wp-basics allows Reflected XSS.This issue affects WP-Basics: from n/a through <= 2.0. | |
| Analizada | Media (6.9) | 0.65% | — | Carmelogarcia Restaurant Order System | 3/11/2024 | 17/6/2026 | A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (5.4) | 0.30% | — | Redi Restaurant ReservationAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ReDi Restaurant Reservation: from n/a through 24.0422. | |
| Aplazada | Alta (7.1) | 0.27% | — | Rconnect305 Restaurant Reservations WidgetAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rconnect305 Restaurant Reservations Widget restaurantconnect-reswidget allows Reflected XSS.This issue affects Restaurant Reservations Widget: from n/a through <= 1.0. |