Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (8.8) | 0.29% | — | Salonbookingsystem Salon Booking SystemAI | 6/10/2026 | 6/10/2026 | Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Salonbookingsystem Salon Booking SystemAI | 10/9/2026 | 5/10/2026 | Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.9. | |
| Aplazada | Media (4.3) | 0.28% | — | Woocommerce BookingsAI | 23/8/2026 | 26/8/2026 | The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products. | |
| Aplazada | Alta (8.5) | 0.36% | — | Gravityforms BookingsAI | 18/8/2026 | 20/8/2026 | Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | |
| Aplazada | Crítica (9.8) | 0.61% | — | Salonbookingsystem Salon Booking SystemAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | |
| Aplazada | Media (4.8) | 0.27% | — | Salonbookingsystem Salon Booking SystemAI | 10/8/2026 | 26/8/2026 | The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection… | |
| Aplazada | Alta (7.5) | 0.43% | — | Salonbookingsystem Salon Booking SystemAI | 10/8/2026 | 26/8/2026 | The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking… | |
| Aplazada | Media (5.3) | 0.30% | — | Salonbookingsystem Salon Booking SystemAI | 10/8/2026 | 26/8/2026 | The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings. | |
| Aplazada | Media (4.3) | 0.27% | — | Salonbookingsystem Salon Booking SystemAI | 10/8/2026 | 26/8/2026 | The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's… | |
| Aplazada | Alta (7.1) | 0.34% | — | Wpbookingsystem WP Booking SystemAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | WPS Bookings FOR WoocommerceAI | 17/7/2026 | 17/7/2026 | The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers' booking orders. | |
| Aplazada | Alta (8.8) | 0.40% | — | Salonbookingsystem Salon Booking SystemAI | 10/7/2026 | 10/7/2026 | The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.32. This is due to missing or incorrect nonce validation on the setCustomText function. This makes it possible for unauthenticated attackers to inject arbitrary PHP code… | |
| Aplazada | Media (4.3) | 0.28% | — | Salonbookingsystem Salon Booking SystemAI | 1/7/2026 | 1/7/2026 | The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the manual approval of new bookings. | |
| Aplazada | Alta (7.3) | 0.30% | — | Salonbookingsystem Salon Booking SystemAI | 17/6/2026 | 17/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Salonbookingsystem Salon Booking SystemAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions. | |
| Aplazada | Alta (7.5) | 0.34% | — | Gravity Bookings PremiumAI | 6/5/2026 | 17/6/2026 | The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append… | |
| Aplazada | Alta (7.5) | 0.55% | — | Salonbookingsystem Salon Booking SystemAI | 2/5/2026 | 17/6/2026 | The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using those stored values as trusted paths for email attachments. This makes it… | |
| Aplazada | Baja (2) | 0.36% | — | ClassroombookingsAI | 17/4/2026 | 17/6/2026 | A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/application/views/layout.php of the component User Display Name Handler. The manipulation of the argument displayname results in cross site scripting. The attack can be executed remotely. The exploit is… | |
| Aplazada | Media (4.4) | 0.26% | — | Tennis Court BookingsAI | 19/2/2026 | 17/6/2026 | The Tennis Court Bookings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Media (6.5) | 0.41% | — | Salonbookingsystem Salon Booking SystemAI | 22/1/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Retrieve Embedded Sensitive Data.This issue affects Salon booking system: from n/a through <= 10.30.3. | |
| Aplazada | Media (4.3) | 0.16% | — | Salonbookingsystem Salon Booking SystemAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.30.3. | |
| Aplazada | Alta (8.8) | 0.30% | — | Service Finder BookingsAI | 1/11/2025 | 17/6/2026 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.38% | — | Service Finder BookingsAI | 1/11/2025 | 17/6/2026 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to processing a password change request. This makes it possible for authenticated attackers… | |
| Aplazada | Crítica (9.8) | 0.42% | — | Service Finder BookingsAI | 19/9/2025 | 17/6/2026 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to claiming a business when using the claim_business AJAX action. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.29% | — | Salonbookingsystem Salon Booking SystemAI | 11/9/2025 | 17/6/2026 | The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax function in all versions up to, and including, 10.22. This makes it possible for unauthenticated attackers to… |