Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.65% | — | Projectworlds Online Hotel Booking | 5/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in projectworlds Online Hotel Booking 1.0. Affected is an unknown function of the file /admin/login.php. The manipulation of the argument emailusername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.65% | — | Projectworlds Online Hotel Booking | 5/3/2025 | 17/6/2026 | A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been rated as critical. This issue affects some unknown processing of the file /booknow.php?roomname=Duplex. The manipulation of the argument checkin leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.60% | — | Projectworlds Online Hotel Booking | 5/3/2025 | 17/6/2026 | A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /reservation.php. The manipulation of the argument checkin leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.54% | — | Projectworlds Online Hotel Booking | 5/3/2025 | 17/6/2026 | A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been classified as critical. This affects an unknown part of the file /admin/addroom.php. The manipulation of the argument roomname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.8) | 0.61% | — | Phpjabbers Hotel Booking System | 19/2/2025 | 17/6/2026 | PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. | |
| Modificada | Alta (7.5) | 0.75% | — | Phpjabbers Hotel Booking System | 19/2/2025 | 17/6/2026 | A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Modificada | Media (6.1) | 0.39% | — | Phpjabbers Hotel Booking System | 19/2/2025 | 17/6/2026 | PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters. | |
| Modificada | Media (6.1) | 0.39% | — | Phpjabbers Hotel Booking System | 19/2/2025 | 17/6/2026 | PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters. | |
| Analizada | Media (6.5) | 0.55% | — | Phpjabbers Hotel Booking System | 19/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Analizada | Alta (8.8) | 0.34% | — | Vikwp Vikbooking Hotel Booking Engine & PMS | 26/1/2025 | 17/6/2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to change plugin access privileges… | |
| Analizada | Crítica (9.8) | 0.49% | — | Kwhotel | 23/1/2025 | 17/6/2026 | KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function. | |
| Analizada | Crítica (9.8) | 0.37% | — | Kwhotel | 23/1/2025 | 17/6/2026 | KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function. | |
| Analizada | Media (4.3) | 0.36% | — | Thimpress WP Hotel Booking | 22/1/2025 | 17/6/2026 | The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve… | |
| Analizada | Media (5.3) | 0.32% | — | Thimpress WP Hotel Booking | 17/1/2025 | 17/6/2026 | The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add rooms with custom prices. | |
| Analizada | Media (5.3) | 0.68% | — | Fabian Responsive Hotel Site | 5/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Responsive Hotel Site 1.0. Affected is an unknown function of the file /admin/print.php. The manipulation of the argument pid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.72% | — | Fabian Responsive Hotel Site | 29/12/2024 | 17/6/2026 | A vulnerability has been found in code-projects Responsive Hotel Site 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/newsletter.php. The manipulation of the argument eid leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (4.8) | 0.35% | — | Code-projects Hotel Management System | 5/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Hotel Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file hotelnew.c of the component Available Room Handler. The manipulation of the argument admin_entry leads to stack-based buffer overflow. Local access is required to… | |
| Analizada | Media (4.8) | 0.35% | — | Code-projects Hotel Management System | 5/12/2024 | 17/6/2026 | A vulnerability has been found in code-projects Hotel Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Administrator Login Password Handler. The manipulation of the argument Str2 leads to stack-based buffer overflow. An attack has to be approached locally.… | |
| Aplazada | Alta (7.1) | 0.15% | — | Cultbooking Hotel Booking EngineAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CultBooking CultBooking Hotel Booking Engine cultbooking-booking-engine allows Stored XSS.This issue affects CultBooking Hotel Booking Engine: from n/a through <= 2.1. | |
| Analizada | Media (5.3) | 0.68% | — | Fabian Responsive Hotel Site | 28/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Responsive Hotel Site 1.0. Affected by this issue is some unknown functionality of the file /admin/room.php. The manipulation of the argument troom leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (6.5) | 0.32% | — | Minical Hotel Booking PluginAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pankaj9296 Minical Hotel Booking Plugin minical allows Stored XSS.This issue affects Minical Hotel Booking Plugin: from n/a through <= 1.0.2. | |
| Modificada | Alta (8.8) | 0.53% | — | Thimpress WP Hotel Booking | 4/11/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9. | |
| Analizada | Media (5.3) | 0.53% | — | Janobe Online Hotel Reservation System | 27/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is the function upload of the file /guest/update.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.44% | — | Janobe Online Hotel Reservation System | 27/10/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Online Hotel Reservation System 1.0. It has been classified as critical. Affected is the function doCancelRoom/doCancel/doConfirm/doCancel/doCheckin/doCheckout of the file /marimar/admin/mod_room/controller.php. The manipulation of the argument id leads to sql injection. It… | |
| Analizada | Media (5.3) | 1.2% | 💥 PoC | Janobe Online Hotel Reservation System | 27/10/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely.… |