Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

103 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.19%—Nicdark Hotel BookingAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions.
AplazadaAlta (7.2)0.40%—Motopress Hotel BookingAI15/9/202616/9/2026
The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (5.4)0.23%—Motopress Hotel BookingAI10/8/202626/8/2026
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
AplazadaMedia (5.3)0.30%—Motopress Hotel BookingAI10/8/202626/8/2026
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.
AplazadaMedia (5.3)0.16%—Thimpress WP Hotel BookingAI6/8/202626/8/2026
The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to have their bookings marked as fully paid without any payment reaching…
AplazadaMedia (5.3)0.32%—Thimpress WP Hotel BookingAI6/8/202626/8/2026
The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or at an arbitrarily reduced price.
AplazadaMedia (4.3)0.29%—Motopress Hotel BookingAI30/7/202630/7/2026
The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and…
AplazadaMedia (6.8)0.39%—Thimpress WP Hotel BookingAI30/7/202630/7/2026
The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks.
AplazadaAlta (7.5)0.42%—Byteflows Travel & Hotel BookingAI27/7/202627/7/2026
Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.
AplazadaMedia (6.4)0.33%—Thimpress WP Hotel BookingAI24/7/202624/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaMedia (6.1)0.69%—Thimpress WP Hotel BookingAI17/7/202617/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaMedia (5.3)0.26%—Thimpress WP Hotel BookingAI11/7/202614/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler selecting its PayPal validation endpoint from the attacker-controlled `$_REQUEST['test_ipn']`…
AplazadaMedia (6.1)0.45%—Thimpress WP Hotel BookingAI10/7/202614/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (6.5)0.37%—Motopress Hotel Booking LiteAI2/7/20262/7/2026
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
AplazadaAlta (7.4)0.17%—E4jvikwp Vikbooking Hotel Booking Engine AND PMSAI1/7/20261/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12.
AplazadaMedia (6.5)0.34%—Thimpress WP Hotel BookingAI19/6/202622/6/2026
The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' booking line items, enumerate active coupons, and read pricing data.
AplazadaAlta (8.1)0.44%—Alloggio Hotel BookingAI17/6/202617/6/2026
Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
AplazadaAlta (7.1)0.25%—E4jvikwp Vikbooking Hotel Booking Engine AND PMSAI1/6/202622/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows DOM-Based XSS. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.8.
AplazadaMedia (5.3)0.47%—Motopress Hotel BookingAI22/5/202623/7/2026
The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite or delete the internal…
AplazadaMedia (5.1)0.19%—Motopress Hotel Booking LiteAI10/5/202625/7/2026
Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting payloads in accommodation type fields. Attackers can inject script tags through the title and excerpt parameters when creating accommodation types, which…
AplazadaMedia (5.5)0.53%—Pratham-jaiswal Hotel Booking Management SystemAI17/4/20262/8/2026
A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea. The impacted element is an unknown function of the file /api/health/detailed of the component Health Check Endpoint. Performing a manipulation results in information disclosure. Remote exploitation…
AplazadaBaja (2.1)0.45%—Code-projects Online Hotel BookingAI7/4/202624/7/2026
A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is possible to launch the attack remotely. The…
AplazadaMedia (6.5)0.33%—Themewant Easy Hotel BookingAI20/2/202617/6/2026
Missing Authorization vulnerability in themewant Easy Hotel Booking easy-hotel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Hotel Booking: from n/a through <= 1.9.2.
AplazadaMedia (5.3)0.30%—Thimpress WP Hotel BookingAI17/1/202617/6/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.7. This is due to the plugin exposing the 'hotel_booking_fetch_customer_info' AJAX action to unauthenticated users without proper capability checks, relying only on a nonce for…
AplazadaMedia (5.3)0.26%—Awesome Hotel BookingAI7/1/202617/6/2026
The Awesome Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to incorrect authorization in the room-single.php shortcode handler in all versions up to, and including, 1.0.3. This is due to the plugin relying solely on nonce verification without capability checks. This makes it…