Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
2544 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.40% | — | Bookingpress Appointment Booking PROAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | |
| Aplazada | Crítica (9.8) | 0.60% | 💥 PoC | Themetechmount TruebookerAI | 19/8/2026 | 21/8/2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6. This is due to the admin_user_create_cus AJAX handler lacking any authentication or capability check… | |
| Aplazada | Media (6.9) | 0.71% | — | Mybooks TalebookAI | 19/8/2026 | 9/9/2026 | MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.post handler for POST /api/user/sign_up in webserver/handlers/user.py does not enforce the ALLOW_REGISTER configuration flag, even though the frontend hides registration controls when the flag is false. An… | |
| Aplazada | Alta (8.7) | 0.45% | — | MybooksAITalebookAI | 19/8/2026 | 9/9/2026 | MyBooks is an ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler for POST /api/admin/settings in webserver/handlers/admin.py applies the auth decorator but does not check the self.admin_user property, unlike the corresponding GET handler. Any authenticated regular… | |
| Aplazada | Crítica (9.4) | 0.50% | — | MybooksAITalebookAI | 19/8/2026 | 9/9/2026 | MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler in webserver/handlers/admin.py accepts SOCIAL_AUTH key names without validating quotes or newline characters, and SettingsLoader.dumpfile in webserver/loader.py… | |
| Aplazada | Media (6.5) | 0.30% | — | Taxi Booking ManagerAI | 19/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Themetechmount TruebookerAI | 19/8/2026 | 20/8/2026 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. | |
| Aplazada | Media (5.3) | 0.30% | — | Themetechmount TruebookerAI | 19/8/2026 | 26/8/2026 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records. | |
| Aplazada | Media (5.3) | 0.34% | — | Themetechmount TruebookerAI | 19/8/2026 | 26/8/2026 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and postal address. | |
| Aplazada | Media (5.3) | 0.30% | — | Themetechmount TruebookerAI | 19/8/2026 | 26/8/2026 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Themetechmount TruebookerAI | 19/8/2026 | 26/8/2026 | The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password reset flow. | |
| Aplazada | Alta (8.8) | 0.54% | — | Booking Calendar Appointment Booking SystemAI | 19/8/2026 | 26/8/2026 | The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary… | |
| Aplazada | Media (5.3) | 0.33% | — | 3dflipbook 3D FlipbookAI | 18/8/2026 | 20/8/2026 | Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Appointment Booking SystemAI | 18/8/2026 | 20/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. | |
| Aplazada | Media (6.5) | 0.35% | — | Dwbooster Appointment Hour BookingAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Gravityforms BookingsAI | 18/8/2026 | 20/8/2026 | Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | |
| Aplazada | Media (5.3) | 0.37% | — | Gomarble-ai Facebook-ads-mcp-serverAI | 16/8/2026 | 20/8/2026 | A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file server.py. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The name of the patch is 4e53875aa22e8991c2fa4a7660d86e1caba66659.… | |
| Aplazada | Alta (7.2) | 0.58% | — | Booking-wp-plugin BooklyAI | 16/8/2026 | 20/8/2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, and including, 27.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.68% | — | Simply Schedule Appointments Appointment Booking CalendarAI | 16/8/2026 | 20/8/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.10 via the ssa_past_appointments due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.39% | — | Booking-wp-plugin BooklyAI | 16/8/2026 | 20/8/2026 | The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabinet/api/handlers/Handler1_0.php. This is… | |
| Aplazada | Baja (1.9) | 0.37% | — | Sourcecodester Online Book Store SystemAI | 15/8/2026 | 20/8/2026 | A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the component System Settings Module. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been made… | |
| Aplazada | Crítica (9.8) | 0.66% | — | Themetechmount TruebookerAI | 15/8/2026 | 20/8/2026 | The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and accepting an arbitrary truebooker_wp_user_id value, which is passed directly to wp_update_user()… | |
| Aplazada | Media (6.4) | 0.36% | — | Hydra BookingAI | 15/8/2026 | 20/8/2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.55% | — | Booking CalendarAI | 15/8/2026 | 20/8/2026 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark… | |
| Aplazada | Alta (7.2) | 0.40% | — | Vcita Online Booking Scheduling CalendarAI | 15/8/2026 | 20/8/2026 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… |