Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

150 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.80%—Booking Calendar Project Booking Calendar3/1/202217/6/2026
The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaAlta (8.8)1.6%—Wpsimplebookingcalendar WP Simple Booking Calendar13/9/202117/6/2026
The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue
ModificadaMedia (5.4)0.62%—Elbtide Advanced Booking Calendar22/4/202117/6/2026
The Advanced Booking Calendar WordPress plugin before 1.6.8 does not sanitise the license error message when output in the settings page, leading to an authenticated reflected Cross-Site Scripting issue
ModificadaMedia (5.4)0.69%—Elbtide Advanced Booking Calendar12/4/202117/6/2026
The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & Calendars" page before outputing it in an A tag, leading to a reflected XSS issue
ModificadaAlta (7.8)8.6%💥 ExploitCodepeople Appointment Booking Calendar4/3/202017/6/2026
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via the Bookings list tab in /wp-admin/admin.php?page=cpabc_appointments.php. The attacker could achieve remote code…
ModificadaMedia (4.8)3.3%💥 ExploitCodepeople Appointment Booking Calendar4/3/202017/6/2026
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php file, the Calendar Name input could allow attackers to inject arbitrary JavaScript or HTML.
ModificadaCrítica (9.8)1.8%—Codepeople Appointment Booking Calendar22/8/201917/6/2026
The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CVE-2015-7319.
ModificadaMedia (6.1)0.91%—Mediaburst Booking Calendar21/8/201917/6/2026
The booking-sms plugin before 1.1.0 for WordPress has XSS.
ModificadaCrítica (9.8)1.8%—Codepeople Booking Calendar Contact Form21/8/201917/6/2026
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
ModificadaMedia (6.1)0.91%—Codepeople Booking Calendar Contact Form21/8/201917/6/2026
The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
ModificadaMedia (6.1)1.4%—Codepeople Appointment Booking Calendar9/8/201917/6/2026
The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea parameter.
ModificadaAlta (8.8)19%💥 ExploitBooking Calendar Project Booking Calendar21/3/201917/6/2026
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.
ModificadaAlta (7.5)1.4%—Wpdevart Booking Calendar13/6/201817/6/2026
An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.
ModificadaAlta (8.8)0.77%—Booking Calendar Project Booking Calendar13/1/201817/6/2026
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php.
ModificadaMedia (4.8)0.62%—Booking Calendar Project Booking Calendar13/1/201817/6/2026
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label] parameter.
ModificadaMedia (4.8)0.62%—Booking Calendar Project Booking Calendar13/1/201817/6/2026
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php extra_field1[items][field_item1][price_percent] parameter.
ModificadaMedia (4.8)0.62%—Booking Calendar Project Booking Calendar13/1/201817/6/2026
An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_conditions[count][] parameter.
ModificadaMedia (6.1)0.95%—Mediaburst Booking Calendar SMSMediaburst Clockwork SMS NotficationsMediaburst Contact Form 7 SMSMediaburst Fast Secure Contact Form SMS+420/12/201717/6/2026
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2,…
ModificadaMedia (6.1)0.85%—Booking Calendar Project Booking Calendar28/4/201717/6/2026
Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.3)2.4%—Booking Calendar Project Booking Calendar28/4/201717/6/2026
Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter.
ModificadaMedia (4.3)2.1%—Codepeople Appointment Booking Calendar29/9/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in cpabc_appointments_admin_int_bookings_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)2.4%—Codepeople Appointment Booking Calendar29/9/201517/6/2026
SQL injection vulnerability in cpabc_appointments_admin_int_calendar_list.inc.php in the Appointment Booking Calendar plugin before 1.1.8 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to updating the username.
ModificadaAlta (7.5)1.2%💥 ExploitPhpjabbers Event Booking Calendar13/1/201517/6/2026
SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaMedia (6.8)2.0%💥 ExploitPhpjabbers Event Booking Calendar13/1/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change the username and password of the administrator via an update action to the AdminOptions controller or conduct cross-site…
ModificadaMedia (4.3)1.5%💥 ExploitJjwdesign PHP Booking Calendar30/12/201116/6/2026
Cross-site scripting (XSS) vulnerability in details_view.php in PHP Booking Calendar 10e allows remote attackers to inject arbitrary web script or HTML via the page_info_message parameter.
Orbitaley — Vulnerabilidades