Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.37% | — | Motopress Hotel Booking LiteAI | 2/7/2026 | 2/7/2026 | Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions. | |
| Aplazada | Media (5.1) | 0.19% | — | Motopress Hotel Booking LiteAI | 10/5/2026 | 25/7/2026 | Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting payloads in accommodation type fields. Attackers can inject script tags through the title and excerpt parameters when creating accommodation types, which… | |
| Aplazada | Crítica (9.1) | 0.37% | — | Jetmonsters Motopress-hotel-booking-liteAI | 18/12/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote Code Inclusion.This issue affects Hotel Booking Lite: from n/a through <= 5.2.3. | |
| Aplazada | Crítica (9.8) | 0.85% | — | Motopress Hotel Booking LiteAI | 14/5/2024 | 17/6/2026 | The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is… | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Motopress Hotel Booking Lite | 26/12/2023 | 17/6/2026 | The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server | |
| Modificada | Alta (8.8) | 0.31% | — | Motopress Hotel Booking Lite | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MotoPress Hotel Booking Lite plugin <= 4.6.0 versions. |