Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

394 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.42%💥 PoCDigitaldruid Hoteldruid11/3/202517/6/2026
A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is…
AnalizadaMedia (5.4)0.55%💥 PoCDigitaldruid Hoteldruid11/3/202517/6/2026
Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint
ModificadaMedia (4.8)0.89%💥 ExploitReservit Hotel7/3/202517/6/2026
The Reservit Hotel WordPress plugin before 3.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaMedia (6.9)0.65%—Projectworlds Online Hotel Booking5/3/202517/6/2026
A vulnerability classified as critical has been found in projectworlds Online Hotel Booking 1.0. Affected is an unknown function of the file /admin/login.php. The manipulation of the argument emailusername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.9)0.65%—Projectworlds Online Hotel Booking5/3/202517/6/2026
A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been rated as critical. This issue affects some unknown processing of the file /booknow.php?roomname=Duplex. The manipulation of the argument checkin leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed…
AnalizadaMedia (6.9)0.60%—Projectworlds Online Hotel Booking5/3/202517/6/2026
A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /reservation.php. The manipulation of the argument checkin leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.9)0.54%—Projectworlds Online Hotel Booking5/3/202517/6/2026
A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been classified as critical. This affects an unknown part of the file /admin/addroom.php. The manipulation of the argument roomname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AnalizadaAlta (8.8)0.61%—Phpjabbers Hotel Booking System19/2/202517/6/2026
PHPJabbers Hotel Booking System v4.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file.
ModificadaAlta (7.5)0.75%—Phpjabbers Hotel Booking System19/2/202517/6/2026
A lack of rate limiting in the "Login Section, Forgot Email" feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
ModificadaMedia (6.1)0.39%—Phpjabbers Hotel Booking System19/2/202517/6/2026
PHPJabbers Hotel Booking System v4.0 is vulnerable to Cross-Site Scripting (XSS) vulnerabilities in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key" parameters.
ModificadaMedia (6.1)0.39%—Phpjabbers Hotel Booking System19/2/202517/6/2026
PHPJabbers Hotel Booking System v4.0 is vulnerable to HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.
AnalizadaMedia (6.5)0.55%—Phpjabbers Hotel Booking System19/2/202517/6/2026
A lack of rate limiting in the 'Email Settings' feature of PHPJabbers Hotel Booking System v4.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
AnalizadaAlta (8.8)0.34%—Vikwp Vikbooking Hotel Booking Engine & PMS26/1/202517/6/2026
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to change plugin access privileges…
AnalizadaCrítica (9.8)0.49%—Kwhotel23/1/202517/6/2026
KWHotel 0.47 is vulnerable to CSV Formula Injection in the invoice adding function.
AnalizadaCrítica (9.8)0.37%—Kwhotel23/1/202517/6/2026
KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function.
AnalizadaMedia (4.3)0.36%—Thimpress WP Hotel Booking22/1/202517/6/2026
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve…
AnalizadaMedia (5.3)0.32%—Thimpress WP Hotel Booking17/1/202517/6/2026
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to add rooms with custom prices.
AnalizadaMedia (5.3)0.68%—Fabian Responsive Hotel Site5/1/202517/6/2026
A vulnerability, which was classified as critical, was found in code-projects Responsive Hotel Site 1.0. Affected is an unknown function of the file /admin/print.php. The manipulation of the argument pid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (6.9)0.74%💥 PoCInfotel Tasklists30/12/202417/6/2026
Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version 2.0.4 contains a patch for the vulnerability.
AnalizadaMedia (5.3)0.72%—Fabian Responsive Hotel Site29/12/202417/6/2026
A vulnerability has been found in code-projects Responsive Hotel Site 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/newsletter.php. The manipulation of the argument eid leads to sql injection. The attack can be launched remotely. The exploit has been…
AnalizadaMedia (4.8)0.35%—Code-projects Hotel Management System5/12/202417/6/2026
A vulnerability was found in code-projects Hotel Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file hotelnew.c of the component Available Room Handler. The manipulation of the argument admin_entry leads to stack-based buffer overflow. Local access is required to…
AnalizadaMedia (4.8)0.35%—Code-projects Hotel Management System5/12/202417/6/2026
A vulnerability has been found in code-projects Hotel Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Administrator Login Password Handler. The manipulation of the argument Str2 leads to stack-based buffer overflow. An attack has to be approached locally.…
AplazadaAlta (7.1)0.15%—Cultbooking Hotel Booking EngineAI2/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CultBooking CultBooking Hotel Booking Engine cultbooking-booking-engine allows Stored XSS.This issue affects CultBooking Hotel Booking Engine: from n/a through <= 2.1.
AnalizadaMedia (5.3)0.68%—Fabian Responsive Hotel Site28/11/202417/6/2026
A vulnerability, which was classified as critical, has been found in code-projects Responsive Hotel Site 1.0. Affected by this issue is some unknown functionality of the file /admin/room.php. The manipulation of the argument troom leads to sql injection. The attack may be launched remotely. The exploit has been…
AplazadaMedia (6.5)0.32%—Minical Hotel Booking PluginAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pankaj9296 Minical Hotel Booking Plugin minical allows Stored XSS.This issue affects Minical Hotel Booking Plugin: from n/a through <= 1.0.2.
Orbitaley — Vulnerabilidades