Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.42% | 💥 PoC | Digitaldruid Hoteldruid | 11/3/2025 | 17/6/2026 | A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is… | |
| Analizada | Media (5.4) | 0.55% | 💥 PoC | Digitaldruid Hoteldruid | 11/3/2025 | 17/6/2026 | Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint | |
| Modificada | Media (4.8) | 0.89% | 💥 Exploit | Reservit Hotel | 7/3/2025 | 17/6/2026 | The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (6.9) | 0.65% | — | Projectworlds Online Hotel Booking | 5/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in projectworlds Online Hotel Booking 1.0. Affected is an unknown function of the file /admin/login.php. The manipulation of the argument emailusername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.65% | — | Projectworlds Online Hotel Booking | 5/3/2025 | 17/6/2026 | A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been rated as critical. This issue affects some unknown processing of the file /booknow.php?roomname=Duplex. The manipulation of the argument checkin leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.60% | — | Projectworlds Online Hotel Booking | 5/3/2025 | 17/6/2026 | A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /reservation.php. The manipulation of the argument checkin leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.54% | — | Projectworlds Online Hotel Booking | 5/3/2025 | 17/6/2026 | A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been classified as critical. This affects an unknown part of the file /admin/addroom.php. The manipulation of the argument roomname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.8) | 0.61% | — | Phpjabbers Hotel Booking System | 19/2/2025 | 17/6/2026 | PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. | |
| Modificada | Alta (7.5) | 0.75% | — | Phpjabbers Hotel Booking System | 19/2/2025 | 17/6/2026 | A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Modificada | Media (6.1) | 0.39% | — | Phpjabbers Hotel Booking System | 19/2/2025 | 17/6/2026 | PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters. | |
| Modificada | Media (6.1) | 0.39% | — | Phpjabbers Hotel Booking System | 19/2/2025 | 17/6/2026 | PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters. | |
| Analizada | Media (6.5) | 0.55% | — | Phpjabbers Hotel Booking System | 19/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Analizada | Alta (8.8) | 0.34% | — | Vikwp Vikbooking Hotel Booking Engine & PMS | 26/1/2025 | 17/6/2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to change plugin access privileges… | |
| Analizada | Crítica (9.8) | 0.49% | — | Kwhotel | 23/1/2025 | 17/6/2026 | KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function. | |
| Analizada | Crítica (9.8) | 0.37% | — | Kwhotel | 23/1/2025 | 17/6/2026 | KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function. | |
| Analizada | Media (4.3) | 0.36% | — | Thimpress WP Hotel Booking | 22/1/2025 | 17/6/2026 | The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve… | |
| Analizada | Media (5.3) | 0.32% | — | Thimpress WP Hotel Booking | 17/1/2025 | 17/6/2026 | The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add rooms with custom prices. | |
| Analizada | Media (5.3) | 0.68% | — | Fabian Responsive Hotel Site | 5/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Responsive Hotel Site 1.0. Affected is an unknown function of the file /admin/print.php. The manipulation of the argument pid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.74% | 💥 PoC | Infotel Tasklists | 30/12/2024 | 17/6/2026 | Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version 2.0.4 contains a patch for the vulnerability. | |
| Analizada | Media (5.3) | 0.72% | — | Fabian Responsive Hotel Site | 29/12/2024 | 17/6/2026 | A vulnerability has been found in code-projects Responsive Hotel Site 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/newsletter.php. The manipulation of the argument eid leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (4.8) | 0.35% | — | Code-projects Hotel Management System | 5/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Hotel Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file hotelnew.c of the component Available Room Handler. The manipulation of the argument admin_entry leads to stack-based buffer overflow. Local access is required to… | |
| Analizada | Media (4.8) | 0.35% | — | Code-projects Hotel Management System | 5/12/2024 | 17/6/2026 | A vulnerability has been found in code-projects Hotel Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Administrator Login Password Handler. The manipulation of the argument Str2 leads to stack-based buffer overflow. An attack has to be approached locally.… | |
| Aplazada | Alta (7.1) | 0.15% | — | Cultbooking Hotel Booking EngineAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CultBooking CultBooking Hotel Booking Engine cultbooking-booking-engine allows Stored XSS.This issue affects CultBooking Hotel Booking Engine: from n/a through <= 2.1. | |
| Analizada | Media (5.3) | 0.68% | — | Fabian Responsive Hotel Site | 28/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Responsive Hotel Site 1.0. Affected by this issue is some unknown functionality of the file /admin/room.php. The manipulation of the argument troom leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (6.5) | 0.32% | — | Minical Hotel Booking PluginAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pankaj9296 Minical Hotel Booking Plugin minical allows Stored XSS.This issue affects Minical Hotel Booking Plugin: from n/a through <= 1.0.2. |