Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1060 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.26%—Thimpress WP Hotel BookingAI11/7/202614/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler selecting its PayPal validation endpoint from the attacker-controlled `$_REQUEST['test_ipn']`…
AplazadaAlta (7.5)0.76%—Saasproject Booking PackageAI11/7/202614/7/2026
The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (5.9)0.44%—Wpdevart Booking CalendarAI10/7/202610/7/2026
The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpdevart_id’ parameter in all versions up to, and including, 3.2.17 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
AplazadaAlta (8.8)0.40%—Salonbookingsystem Salon Booking SystemAI10/7/202610/7/2026
The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.32. This is due to missing or incorrect nonce validation on the setCustomText function. This makes it possible for unauthenticated attackers to inject arbitrary PHP code…
AplazadaMedia (6.1)0.45%—Thimpress WP Hotel BookingAI10/7/202614/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
Pendiente de análisisAlta (8.6)1.0%💥 PoCLibrebookingAI9/7/202630/7/2026
LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. Fixed in 5.1.0.
AplazadaMedia (4.3)0.45%—Hydra BookingAI9/7/20269/7/2026
The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.2.1 via the /wp-json/hydra-booking/v1/booking/details/{id} REST endpoint. This is due to the getBookingDetails() callback only enforcing the…
AplazadaAlta (7.2)0.39%—VikbookingAI8/7/20268/7/2026
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (7.2)0.40%—VikbookingAI8/7/20268/7/2026
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaAlta (8.1)0.65%—Appointment Booking Calendar Plugin AND Scheduling PluginAI8/7/20268/7/2026
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects; where a suitable gadget chain is present on the site this can be leveraged to…
AplazadaMedia (5.3)0.56%—Motopress Appointment BookingAI3/7/20266/7/2026
The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This is due to the `POST /motopress/appointment/v1/bookings` REST endpoint being registered with `'permission_callback' => '__return_true'`, allowing…
AplazadaMedia (6.5)0.37%—Motopress Hotel Booking LiteAI2/7/20262/7/2026
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
AplazadaAlta (7.4)0.17%—E4jvikwp Vikbooking Hotel Booking Engine AND PMSAI1/7/20261/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12.
AplazadaMedia (5.3)0.32%—Webba-booking Webba BookingAI1/7/20261/7/2026
Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Webba Booking: from n/a through 6.4.13.
AplazadaMedia (6.5)0.45%—Motopress Appointment BookingAI1/7/20261/7/2026
The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 2.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaMedia (6.1)0.37%—VikbookingAI1/7/20261/7/2026
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'layoutstyle' parameter in all versions up to, and including, 1.8.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (4.3)0.28%—Salonbookingsystem Salon Booking SystemAI1/7/20261/7/2026
The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the manual approval of new bookings.
AplazadaAlta (7.5)0.46%—Bookingpress Appointment Booking PROAI1/7/20261/7/2026
The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign_staffmember_to_slots() function in versions up to and including 5.7.1. This is due to the explicit use of stripslashes_deep() on user-supplied POST data before it is…
AplazadaMedia (4.3)0.39%—Appointment Booking CalendarAI1/7/20261/7/2026
The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email…
AplazadaMedia (4.9)0.40%—Fluentbooking Fluent BookingAI30/6/202630/6/2026
The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users with at least the Calendar Manager role to retrieve attendees' PII (name, email, phone, address, payment information) from calendar groups they do…
AplazadaMedia (5.3)0.29%—Booking AND Rental ManagerAI26/6/202629/6/2026
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
AplazadaMedia (6.5)0.22%—Fluentbooking Fluent BookingAI26/6/202626/6/2026
Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.
AplazadaCrítica (9.9)0.48%—Travel BookingAI26/6/202626/6/2026
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
AplazadaCrítica (9.3)0.40%—JetbookingAI26/6/202626/6/2026
Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
AplazadaAlta (8.8)0.20%—Eagle BookingAI26/6/20265/10/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.
Orbitaley — Vulnerabilidades