Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1060 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Booking CalendarAI | 27/7/2026 | 27/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Byteflows Travel & Hotel BookingAI | 27/7/2026 | 27/7/2026 | Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions. | |
| Aplazada | Alta (7.5) | 0.37% | — | Booking AND Rental ManagerAI | 27/7/2026 | 27/7/2026 | Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions. | |
| Aplazada | Alta (8.2) | 0.43% | 💥 PoC | Bookingpress Appointment Booking PROAI | 27/7/2026 | 27/7/2026 | The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings. | |
| Aplazada | Alta (7.2) | 0.60% | — | VikbookingAI | 24/7/2026 | 24/7/2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.1) | 0.46% | — | VikbookingAI | 24/7/2026 | 24/7/2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, and including, 1.8.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (6.4) | 0.33% | — | Thimpress WP Hotel BookingAI | 24/7/2026 | 24/7/2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Media (6.5) | 0.22% | — | Dwbooster Appointment Hour BookingAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | JetbookingAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. | |
| Aplazada | Media (4.9) | 0.19% | — | JetbookingAI | 23/7/2026 | 23/7/2026 | Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Booking-wp-plugin BooklyAI | 23/7/2026 | 23/7/2026 | Unauthenticated SQL Injection in Bookly <= 27.7 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Booking-wp-plugin BooklyAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | Wp-base BookingAI | 23/7/2026 | 23/7/2026 | Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. | |
| Aplazada | Alta (7.1) | 0.34% | — | Wpbookingsystem WP Booking SystemAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Joomdonation Events BookingAI | 22/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information. | |
| Aplazada | Alta (8.8) | 0.20% | — | Joomdonation Events BookingAI | 17/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Joomdonation Events BookingAI | 17/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets. | |
| Aplazada | Media (5.3) | 0.34% | — | Joomdonation Events BookingAI | 17/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses. | |
| Aplazada | Media (5.4) | 0.29% | — | WPS Bookings FOR WoocommerceAI | 17/7/2026 | 17/7/2026 | The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers' booking orders. | |
| Aplazada | Media (6.1) | 0.69% | 💥 Exploit | Thimpress WP Hotel BookingAI | 17/7/2026 | 17/7/2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (4.9) | 0.41% | — | Ameliabooking AmeliaAI | 16/7/2026 | 17/7/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Media (5.4) | 0.14% | — | Appointment Booking PluginAI | 16/7/2026 | 16/7/2026 | The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway,… | |
| Aplazada | Media (5.3) | 0.29% | — | Wpdevart Booking CalendarAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in wpdevart Booking calendar, Appointment Booking System booking-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through <= 3.2.36. | |
| Aplazada | Media (6.5) | 0.33% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.9. | |
| Aplazada | Alta (7.1) | 0.25% | — | Themefic Hydra-bookingAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.44. |