Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

2544 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3.8)0.26%—Booking FOR Appointments AND Events CalendarAI10/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating…
AplazadaMedia (5.3)0.30%—Dwbooster Appointment Hour BookingAI8/8/202626/8/2026
The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting…
AplazadaCrítica (9.8)0.56%—Themetechmount TruebookerAI7/8/202612/8/2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…
AplazadaCrítica (9.8)0.51%—Themetechmount TruebookerAI7/8/202612/8/2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before resetting their password. This makes it…
AplazadaCrítica (9.4)0.38%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on the platform without authentication.…
AplazadaCrítica (9.8)0.57%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration cookie's email but never validates that the…
AplazadaCrítica (9.9)0.44%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any tenant admin updating…
AplazadaAlta (7.4)0.39%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can submit unlimited wrong passphrase guesses against any known email address, capped only by the Argon2 verification cost…
AplazadaMedia (6.5)0.36%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, applies no schema validation to the message body, writes attacker-controlled content directly into the application's stdout…
AplazadaBaja (3.7)0.39%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at `/api/tenants/{id}/appointments/bootstrap-challenge` issues a SHA-256 proof-of-work with `difficulty=4` hex zeros, equivalent to 16 bits of work.…
AplazadaAlta (8.1)0.24%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` configuration (`website`, `imprint`, `privacyStatement`). These values are returned to the patient-facing landing page…
AplazadaAlta (8)0.47%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/tenants/{id}` endpoint returns the full tenant record to any authenticated `TENANT_ADMIN` of that tenant, including the `databaseUrl` field. This field contains the live…
AplazadaAlta (7.4)0.50%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side load handler deletes the `access_token` cookie before calling `/api/auth/logout` via an internal `event.fetch()`. The…
AplazadaMedia (5.3)0.34%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticated `/api/tenants/{id}/schedule` endpoint returns every non-archived channel for a tenant regardless of the channel's `isPublic` flag. Channels marked `isPublic = false`…
AplazadaMedia (5.3)0.43%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler at `/api/tenants/{id}/appointments/{appointmentId}` performs no authorization check before returning the appointment record. Any party who knows or obtains a valid…
AplazadaMedia (6.5)0.33%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1.0.1 and prior consists of three calls: `bootstrap-challenge` (returns a 16-bit PoW challenge with `difficulty=4` leading hex zeroes), `bootstrap-verify` (validates the…
AplazadaMedia (6.5)0.42%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunnel` endpoint creates a new appointment row in any client tunnel without any caller authentication. A request that supplies any valid `tunnelId` and any valid `emailHash`…
AplazadaBaja (2.7)0.29%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, when a TENANT_ADMIN deletes an existing staff user, the underlying `StaffService.deleteStaffMember()` runs an additional invite cleanup that deletes from the central `user_invite` table…
AplazadaMedia (5.8)0.40%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type challenge throttle uses `emailHash` as the only key. The throttle rows live in the central `challenge_throttle` table, which is shared across all tenants. Every tenant's…
AplazadaMedia (5.3)0.32%—Event Booking Manager FOR WoocommerceAI6/8/202626/8/2026
The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to…
AplazadaMedia (5.3)0.16%—Thimpress WP Hotel BookingAI6/8/202626/8/2026
The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to have their bookings marked as fully paid without any payment reaching…
AplazadaMedia (5.3)0.32%—Thimpress WP Hotel BookingAI6/8/202626/8/2026
The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or at an arbitrarily reduced price.
AplazadaMedia (5.3)0.32%—Easy BookingAI6/8/202626/8/2026
The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking duration on the server side when adding to cart and calculating the booking price, allowing unauthenticated users to place below-minimum bookings and complete underpriced orders.
AplazadaAlta (7.1)0.25%—Facebook FOR WoocommerceAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
AplazadaAlta (7.1)0.25%—Facebook FOR WordpressAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.