Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1060 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.40%—Gravityforms BookingAI25/6/202625/6/2026
The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AnalizadaAlta (8.8)0.49%—Joombooking JB Visa19/6/202619/8/2026
Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the visatype parameter. Attackers can send GET requests to index.php with the option=com_bookpro and view=popup parameters, injecting SQL…
AplazadaMedia (6.5)0.34%—Thimpress WP Hotel BookingAI19/6/202622/6/2026
The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' booking line items, enumerate active coupons, and read pricing data.
AplazadaMedia (6.4)0.33%—Appointment Booking CalendarAI19/6/202622/6/2026
The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and…
AplazadaMedia (4.3)0.28%—Appointment Booking CalendarAI18/6/202618/6/2026
The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.4.01. This is due to insufficient authorization and missing per-calendar ownership checks in the cpabc_appointments_calendar_load2() function, which is reachable via the…
AplazadaAlta (8.5)0.36%—Wpwax Directorist BookingAI17/6/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Directorist Booking: from n/a through 3.0.3.
AplazadaAlta (7.3)0.30%—Salonbookingsystem Salon Booking SystemAI17/6/202617/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.
AplazadaAlta (8.1)0.44%—Alloggio Hotel BookingAI17/6/202617/6/2026
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
AplazadaAlta (8.8)0.48%—Pixel Makers Creative Entrepreneur Booking FOR Small BusinessesAI17/6/20266/10/2026
Deserialization of Untrusted Data vulnerability in Pixel Makers Creative INC. Entrepreneur - Booking for Small Businesses WordPress Theme allows Object Injection. This issue affects Entrepreneur - Booking for Small Businesses WordPress Theme: from n/a before 3.1.5.
AplazadaAlta (8.8)0.42%—Ameliabooking AmeliaAI15/6/202617/6/2026
Subscriber Privilege Escalation in Amelia <= 2.3 versions.
AplazadaAlta (8.5)0.36%—Codepeople WP Time Slots Booking FormAI15/6/202617/6/2026
Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.
AplazadaAlta (7.5)0.42%—Booking-wp-plugin BooklyAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.
AplazadaAlta (7.5)0.39%—Salonbookingsystem Salon Booking SystemAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.
AplazadaAlta (7.1)0.25%💥 PoCCodepeople WP Time Slots Booking FormAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions.
AplazadaAlta (7.5)0.42%—Ameliabooking AmeliaAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.
AplazadaAlta (7.5)0.35%—Booking PackageAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions.
AplazadaAlta (8.1)0.37%—Wp-base BookingAI15/6/202617/6/2026
Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.
AplazadaMedia (6.5)0.33%—Booking ActivitiesAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.
AplazadaMedia (5.1)0.24%—Appointment Booking CalendarAI15/6/202617/6/2026
WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify calendar settings and inject persistent cross-site scripting payloads through the admin.php page parameters. Attackers can inject malicious JavaScript into the 'ict' and…
AplazadaMedia (6.9)0.78%—Dharma BookingAI15/6/202617/6/2026
WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the gateway parameter. Attackers can supply file paths with directory traversal sequences or null byte injection to the gateway parameter in…
AplazadaMedia (5.1)0.22%—Wordpress Booking Calendar Contact FormAI15/6/202617/6/2026
WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin options and inject malicious scripts by failing to verify user privileges and sanitize input parameters. Attackers with subscriber-level accounts…
AplazadaAlta (8.8)0.24%—Wordpress Booking Calendar Contact FormAI15/6/202617/6/2026
WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to sanitize the calendar parameter before using it in database queries. Attackers can inject SQL commands through the calendar shortcode parameter to execute arbitrary SQL…
AplazadaAlta (8.8)0.30%—Wordpress Booking Calendar Contact FormAI15/6/202617/6/2026
WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send requests to the admin-ajax.php endpoint with the action parameter…
AplazadaAlta (7.2)0.32%💥 PoCBooking-wp-plugin BooklyAI13/6/202623/7/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaAlta (8.8)0.26%—CAR Park BookingAI9/6/202621/7/2026
WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the space_id parameter. Attackers can send GET requests to the booking-page endpoint with malicious space_id…