Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
289 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.21% | — | Course Booking SystemAI | 30/9/2026 | 30/9/2026 | The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address and billing address of every customer who has booked a course. | |
| Aplazada | Media (4.7) | 0.19% | — | Online Scheduling AND Appointment Booking SystemAI | 27/9/2026 | 28/9/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of untrusted input and does not correctly restrict a privileged maintenance feature to administrators, allowing users granted a custom booking-management capability, which an administrator must explicitly… | |
| Aplazada | Baja (3.8) | 0.15% | — | Online Scheduling AND Appointment Booking SystemAI | 27/9/2026 | 28/9/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and payment records requested through its staff-role AJAX actions belong to the requesting staff member, allowing authenticated attackers with a staff-level account to view, modify and delete other staff… | |
| Aplazada | Media (4.8) | 0.22% | — | Online Scheduling AND Appointment Booking SystemAI | 19/9/2026 | 21/9/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not verify that the requester owns the AI booking-assistant conversation named in its unauthenticated conversation actions, allowing any unauthenticated visitor to read another visitor's assistant messages and to inject messages… | |
| Aplazada | Media (6.5) | 0.33% | — | Salonbookingsystem Salon Booking SystemAI | 10/9/2026 | 2/10/2026 | Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.8. | |
| Aplazada | Alta (8.8) | 0.54% | — | Booking Calendar Appointment Booking SystemAI | 19/8/2026 | 26/8/2026 | The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary… | |
| Aplazada | Media (6.5) | 0.33% | — | Appointment Booking SystemAI | 18/8/2026 | 20/8/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. | |
| Aplazada | Media (5.3) | 0.61% | — | Pinpoint Booking SystemAI | 15/8/2026 | 20/8/2026 | The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and including, 2.9.9.6.8. This is due to the `dopbsp_woocommerce_add_to_cart` AJAX action being registered via `wp_ajax_nopriv_*` with no authentication, no nonce… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Salonbookingsystem Salon Booking SystemAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | |
| Aplazada | Alta (8.7) | 0.42% | — | Mrbs Meeting Room Booking SystemAI | 13/8/2026 | 9/9/2026 | The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched without checks. Version 1.12.2 contains a fix. No known workarounds are available. | |
| Aplazada | Media (4.8) | 0.27% | — | Salonbookingsystem Salon Booking SystemAI | 10/8/2026 | 26/8/2026 | The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection… | |
| Aplazada | Alta (7.5) | 0.43% | — | Salonbookingsystem Salon Booking SystemAI | 10/8/2026 | 26/8/2026 | The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking… | |
| Aplazada | Media (5.3) | 0.30% | — | Salonbookingsystem Salon Booking SystemAI | 10/8/2026 | 26/8/2026 | The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. | |
| Aplazada | Media (4.3) | 0.27% | — | Salonbookingsystem Salon Booking SystemAI | 10/8/2026 | 26/8/2026 | The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's… | |
| Aplazada | Media (5.3) | 0.30% | — | Pinpoint Booking SystemAI | 10/8/2026 | 26/8/2026 | The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation. | |
| Aplazada | Media (4.9) | 0.44% | — | Pinpoint Booking SystemAI | 1/8/2026 | 12/8/2026 | The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parameter in all versions up to, and including, 2.9.9.6.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Aplazada | Alta (8.6) | 0.45% | — | Online Scheduling AND Appointment Booking SystemAI | 30/7/2026 | 30/7/2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive… | |
| Aplazada | Media (6.4) | 0.42% | — | Booking System TrafftAI | 29/7/2026 | 30/7/2026 | The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17 due to a missing capability check on the `set_options` AJAX action when the plugin is operating in agency mode. The `trafftSetOptions()` handler… | |
| Aplazada | Alta (7.1) | 0.34% | — | Wpbookingsystem WP Booking SystemAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. | |
| Aplazada | Alta (8.8) | 0.40% | — | Salonbookingsystem Salon Booking SystemAI | 10/7/2026 | 10/7/2026 | The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.32. This is due to missing or incorrect nonce validation on the setCustomText function. This makes it possible for unauthenticated attackers to inject arbitrary PHP code… | |
| Aplazada | Media (4.3) | 0.28% | — | Salonbookingsystem Salon Booking SystemAI | 1/7/2026 | 1/7/2026 | The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the manual approval of new bookings. | |
| Aplazada | Alta (7.3) | 0.30% | — | Salonbookingsystem Salon Booking SystemAI | 17/6/2026 | 17/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Salonbookingsystem Salon Booking SystemAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions. | |
| Aplazada | Media (5.5) | 0.27% | — | Code-projects Simple Flight Ticket Booking SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Alta (7.5) | 0.55% | — | Salonbookingsystem Salon Booking SystemAI | 2/5/2026 | 17/6/2026 | The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using those stored values as trusted paths for email attachments. This makes it… |