Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

76 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (8.8)0.29%—Salonbookingsystem Salon Booking SystemAI6/10/20266/10/2026
Unauthenticated Privilege Escalation in Salon booking system <= 10.31.7 versions.
AplazadaMedia (6.5)0.33%—Salonbookingsystem Salon Booking SystemAI10/9/20265/10/2026
Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.9.
AplazadaMedia (4.3)0.28%—Woocommerce BookingsAI23/8/202626/8/2026
The WooCommerce Bookings WordPress plugin before 3.9.0 does not perform a capability check on one of its AJAX actions, and its nonce check can be bypassed by omitting the token, allowing users with Subscriber-level access and above to create draft bookable products.
AplazadaAlta (8.5)0.36%—Gravityforms BookingsAI18/8/202620/8/2026
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
AplazadaCrítica (9.8)0.61%—Salonbookingsystem Salon Booking SystemAI13/8/202614/8/2026
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
AplazadaMedia (4.8)0.27%—Salonbookingsystem Salon Booking SystemAI10/8/202626/8/2026
The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection…
AplazadaAlta (7.5)0.43%—Salonbookingsystem Salon Booking SystemAI10/8/202626/8/2026
The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking…
AplazadaMedia (5.3)0.30%—Salonbookingsystem Salon Booking SystemAI10/8/202626/8/2026
The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.
AplazadaMedia (4.3)0.27%—Salonbookingsystem Salon Booking SystemAI10/8/202626/8/2026
The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's…
AplazadaAlta (7.1)0.34%—Wpbookingsystem WP Booking SystemAI23/7/202623/7/2026
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
AplazadaMedia (5.4)0.29%—WPS Bookings FOR WoocommerceAI17/7/202617/7/2026
The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers' booking orders.
AplazadaAlta (8.8)0.40%—Salonbookingsystem Salon Booking SystemAI10/7/202610/7/2026
The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.32. This is due to missing or incorrect nonce validation on the setCustomText function. This makes it possible for unauthenticated attackers to inject arbitrary PHP code…
AplazadaMedia (4.3)0.28%—Salonbookingsystem Salon Booking SystemAI1/7/20261/7/2026
The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to modify a Salon Booking System WordPress plugin before 10.30.20 setting and bypass the manual approval of new bookings.
AplazadaAlta (7.3)0.30%—Salonbookingsystem Salon Booking SystemAI17/6/202617/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.
AplazadaAlta (7.5)0.39%—Salonbookingsystem Salon Booking SystemAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.
AplazadaAlta (7.5)0.34%—Gravity Bookings PremiumAI6/5/202617/6/2026
The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append…
AplazadaAlta (7.5)0.55%—Salonbookingsystem Salon Booking SystemAI2/5/202617/6/2026
The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using those stored values as trusted paths for email attachments. This makes it…
AplazadaBaja (2)0.36%—ClassroombookingsAI17/4/202617/6/2026
A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/application/views/layout.php of the component User Display Name Handler. The manipulation of the argument displayname results in cross site scripting. The attack can be executed remotely. The exploit is…
AplazadaMedia (4.4)0.26%—Tennis Court BookingsAI19/2/202617/6/2026
The Tennis Court Bookings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to…
AplazadaMedia (6.5)0.41%—Salonbookingsystem Salon Booking SystemAI22/1/202617/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Retrieve Embedded Sensitive Data.This issue affects Salon booking system: from n/a through <= 10.30.3.
AplazadaMedia (4.3)0.16%—Salonbookingsystem Salon Booking SystemAI9/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.30.3.
AplazadaAlta (8.8)0.30%—Service Finder BookingsAI1/11/202517/6/2026
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.8)0.38%—Service Finder BookingsAI1/11/202517/6/2026
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to processing a password change request. This makes it possible for authenticated attackers…
AplazadaCrítica (9.8)0.42%—Service Finder BookingsAI19/9/202517/6/2026
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to claiming a business when using the claim_business AJAX action. This makes it possible for…
AplazadaMedia (5.3)0.29%—Salonbookingsystem Salon Booking SystemAI11/9/202517/6/2026
The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax function in all versions up to, and including, 10.22. This makes it possible for unauthenticated attackers to…