Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1060 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Booking CalendarAI27/7/202627/7/2026
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
AplazadaAlta (7.5)0.42%—Byteflows Travel & Hotel BookingAI27/7/202627/7/2026
Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.
AplazadaAlta (7.5)0.37%—Booking AND Rental ManagerAI27/7/202627/7/2026
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
AplazadaAlta (8.2)0.43%💥 PoCBookingpress Appointment Booking PROAI27/7/202627/7/2026
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.
AplazadaAlta (7.2)0.60%—VikbookingAI24/7/202624/7/2026
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (6.1)0.46%—VikbookingAI24/7/202624/7/2026
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (6.4)0.33%—Thimpress WP Hotel BookingAI24/7/202624/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaMedia (6.5)0.22%—Dwbooster Appointment Hour BookingAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions.
AplazadaMedia (5.3)0.29%—JetbookingAI23/7/202623/7/2026
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.
AplazadaMedia (4.9)0.19%—JetbookingAI23/7/202623/7/2026
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.
AplazadaCrítica (9.3)0.40%—Booking-wp-plugin BooklyAI23/7/202623/7/2026
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
AplazadaAlta (7.1)0.25%—Booking-wp-plugin BooklyAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
AplazadaAlta (8.8)0.42%—Wp-base BookingAI23/7/202623/7/2026
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
AplazadaAlta (7.1)0.34%—Wpbookingsystem WP Booking SystemAI23/7/202623/7/2026
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
AplazadaAlta (7.5)0.39%—Joomdonation Events BookingAI22/7/202623/7/2026
Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.
AplazadaAlta (8.8)0.20%—Joomdonation Events BookingAI17/7/202623/7/2026
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.
AplazadaCrítica (9.8)0.55%—Joomdonation Events BookingAI17/7/202623/7/2026
Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.
AplazadaMedia (5.3)0.34%—Joomdonation Events BookingAI17/7/202623/7/2026
Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.
AplazadaMedia (5.4)0.29%—WPS Bookings FOR WoocommerceAI17/7/202617/7/2026
The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers' booking orders.
AplazadaMedia (6.1)0.69%💥 ExploitThimpress WP Hotel BookingAI17/7/202617/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaMedia (4.9)0.41%—Ameliabooking AmeliaAI16/7/202617/7/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaMedia (5.4)0.14%—Appointment Booking PluginAI16/7/202616/7/2026
The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway,…
AplazadaMedia (5.3)0.29%—Wpdevart Booking CalendarAI13/7/202613/7/2026
Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36.
AplazadaMedia (6.5)0.33%—Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI13/7/202613/7/2026
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.9.
AplazadaAlta (7.1)0.25%—Themefic Hydra-bookingAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.44.
Orbitaley — Vulnerabilidades