Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2636▼ 301 respecto a la semana anterior
Críticas / altas1348▲ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.27%—Booking-wp-plugin BooklyAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
AplazadaMedia (6.5)0.28%—Booking-wp-plugin BooklyAI30/9/202630/9/2026
Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.
AplazadaMedia (5.3)0.22%—Booking-wp-plugin BooklyAI28/9/202628/9/2026
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.
AplazadaMedia (5.3)0.18%—Booking-wp-plugin BooklyAI25/9/202625/9/2026
The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's primary identifier to overwrite that customer's stored personal information such as name, email and address.
AplazadaCrítica (9.1)0.37%—Booking-wp-plugin BooklyAI25/9/202626/9/2026
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actions. This is due to the 'bookly_get_form_id' handler blindly storing the…
AplazadaMedia (5.3)0.32%—Booking-wp-plugin BooklyAI25/9/202625/9/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up to, and including, 28.2. This is due to the `postValidateCustomer()` function using a loose PHP inequality operator (`!=`) to compare the session-stored…
AplazadaAlta (7.5)1.6%—Booking-wp-plugin BooklyAI16/9/202617/9/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 28.1 via the 'conversation_id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to…
AplazadaMedia (5.4)0.21%—Booking-wp-plugin BooklyAI8/9/20268/9/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 27.2. This makes it possible for authenticated attackers, with Subscriber-level…
AplazadaAlta (7.2)0.58%—Booking-wp-plugin BooklyAI16/8/202620/8/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, and including, 27.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaMedia (4.3)0.39%—Booking-wp-plugin BooklyAI16/8/202620/8/2026
The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in frontend/modules/mobile_staff_cabinet/api/handlers/Handler1_0.php. This is…
AplazadaAlta (7.5)0.48%—Booking-wp-plugin BooklyAI28/7/202628/7/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
AplazadaCrítica (9.3)0.40%—Booking-wp-plugin BooklyAI23/7/202623/7/2026
Unauthenticated SQL Injection in Bookly <= 27.7 versions.
AplazadaAlta (7.1)0.25%—Booking-wp-plugin BooklyAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
AplazadaAlta (7.5)0.42%—Booking-wp-plugin BooklyAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.
AplazadaAlta (7.2)0.32%—Booking-wp-plugin BooklyAI13/6/202623/7/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaMedia (5.3)0.45%—Booking-wp-plugin BooklyAI9/4/202617/6/2026
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation against the configured price. This makes it…
AplazadaAlta (7.1)0.25%—Booking-wp-plugin BooklyAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bookly Bookly bookly-responsive-appointment-booking-tool allows Reflected XSS.This issue affects Bookly: from n/a through <= 26.7.
AplazadaMedia (6.4)0.31%—Booking-wp-plugin BooklyAI11/6/202417/6/2026
The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Color Profile parameter in all versions up to, and including, 23.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.7)0.91%—Booking-wp-plugin BooklyAI17/5/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Nota-Info Bookly allows Path Traversal, Manipulating Web Input to File System Calls.This issue affects Bookly: from n/a through 21.7.1.
ModificadaMedia (4.8)0.45%—Booking-wp-plugin Bookly27/11/202317/6/2026
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (7.2)0.72%—Booking-wp-plugin Bookly16/10/202317/6/2026
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
ModificadaMedia (4.8)0.37%—Booking-wp-plugin Bookly2/6/202317/6/2026
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to inject arbitrary web scripts in pages…
ModificadaMedia (6.1)0.46%—Booking-wp-plugin Bookly17/3/202317/6/2026
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
ModificadaMedia (5.4)0.62%—Booking-wp-plugin Bookly6/12/202117/6/2026
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue
ModificadaMedia (6.1)1.00%—Booking-wp-plugin Bookly11/2/201817/6/2026
Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.