Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 373 respecto a la semana anterior
Críticas / altas1323▲ 43 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

1047 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaCrítica (9.1)0.88%—Vikappointments Services Booking CalendarAI3/10/20263/10/2026
The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which…
AplazadaBaja (3.7)0.16%—Wpdevelop Booking CalendarAI2/10/20265/10/2026
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in WPdevelop Booking Calendar booking allows Leveraging Race Conditions.This issue affects Booking Calendar: from n/a through 11.8.4.
AplazadaMedia (5.3)0.27%—Appointment Booking Plugin LatepointAI2/10/20263/10/2026
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.7.1 via the OsPaypalConnectController::create_order_for_transaction() action registered as a public (unauthenticated) route through…
AplazadaAlta (7.2)0.31%—Ba-booking BA Book EverythingAI2/10/20263/10/2026
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AplazadaMedia (6.5)0.24%—Mage-people BUS Ticket Booking With Seat ReservationAI1/10/20261/10/2026
Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions.
AplazadaAlta (7.2)0.26%—Dwbooster Appointment Hour BookingAI1/10/20261/10/2026
The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer in all versions up to, and including, 1.5.97 due to insufficient input sanitization and output escaping. This makes it…
AplazadaCrítica (9.8)0.39%—Booking ActivitiesAI30/9/202630/9/2026
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
AplazadaMedia (4.3)0.28%—Webba-booking Webba BookingAI30/9/202630/9/2026
Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions.
AplazadaAlta (7.5)0.27%—Booking-wp-plugin BooklyAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
AplazadaMedia (6.5)0.28%—Booking-wp-plugin BooklyAI30/9/202630/9/2026
Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.
AplazadaMedia (5.3)0.21%—Course Booking SystemAI30/9/202630/9/2026
The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address and billing address of every customer who has booked a course.
AplazadaMedia (5.3)0.22%—Booking-wp-plugin BooklyAI28/9/202628/9/2026
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.
AplazadaMedia (4.7)0.19%—Online Scheduling AND Appointment Booking SystemAI27/9/202628/9/2026
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly…
AplazadaBaja (3.8)0.15%—Online Scheduling AND Appointment Booking SystemAI27/9/202628/9/2026
The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff…
AplazadaMedia (5.3)0.18%—Booking-wp-plugin BooklyAI25/9/202625/9/2026
The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifier to overwrite that customer's stored personal information such as name, email and address.
AplazadaAlta (7.2)0.24%—Ba-booking BA Book EverythingAI25/9/202625/9/2026
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaCrítica (9.1)0.37%—Booking-wp-plugin BooklyAI25/9/202626/9/2026
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the…
AplazadaMedia (5.3)0.32%—Booking-wp-plugin BooklyAI25/9/202625/9/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2. This is due to the `postValidateCustomer()` function using a loose PHP inequality operator (`!=`) to compare the session-stored…
AplazadaAlta (7.5)0.26%—Vcita Online Booking Scheduling CalendarAI23/9/202623/9/2026
Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.
AplazadaBaja (2.7)0.18%—Event Booking ManagerAI23/9/202623/9/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard…
AplazadaMedia (4.3)0.15%—Oplugins Booking ManagerAI23/9/202623/9/2026
The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking…
AplazadaMedia (6.8)0.23%—Oplugins Booking ManagerAI23/9/202623/9/2026
The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to perform SQL injection attacks by importing a feed they control.
AplazadaAlta (7.3)0.40%—Magepeople Taxi Booking Manager FOR WoocommerceAI22/9/202622/9/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8.
AplazadaMedia (6.1)0.37%—Booking CalendarAI22/9/202622/9/2026
The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaMedia (5.5)0.31%—Hydra BookingAI19/9/202621/9/2026
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does not perform object-level authorisation checks on several of its host-management operations, allowing users who hold its own administrator-assigned custom role to read, modify and permanently delete other hosts' records and…