Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.7) | 0.32% | — | Bookit Booking Appointment CalendarAI | 18/9/2026 | 18/9/2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on one of its appointment-retrieval actions, allowing users with a low-privilege Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5-specific role to read other users' appointment… | |
| Aplazada | Baja (2.7) | 0.28% | — | Stylemixthemes BookitAI | 18/9/2026 | 18/9/2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one of its appointment-deletion functions, allowing users with its low-privileged custom Staff role to delete arbitrary appointments. | |
| Aplazada | Media (5.3) | 0.34% | — | Stylemixthemes BookitAI | 13/9/2026 | 14/9/2026 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information. | |
| Aplazada | Media (5.3) | 0.18% | — | Stylemixthemes BookitAI | 3/9/2026 | 4/9/2026 | Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. | |
| Aplazada | Alta (7.2) | 0.27% | — | OttokitAI | 18/8/2026 | 20/8/2026 | Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | OttokitAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions. | |
| Aplazada | Alta (7.5) | 0.48% | — | Stellarwp BookitAILiquidweb BookitAI | 2/6/2026 | 22/7/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation. This issue affects BookIt: from n/a before 2.5.4.1. | |
| Aplazada | Alta (8.1) | 0.34% | — | Androthemes CookiteerAI | 2/6/2026 | 22/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. This issue affects Cookiteer: from n/a through 1.4.8. | |
| Aplazada | Alta (8.6) | 0.45% | — | OttokitAI | 8/5/2026 | 17/6/2026 | The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before using it in a SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks. | |
| Aplazada | Alta (7.6) | 0.38% | — | Brainstormforce OttokitAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force OttoKit suretriggers allows Blind SQL Injection.This issue affects OttoKit: from n/a through <= 1.1.20. | |
| Aplazada | Alta (8.8) | 0.29% | — | Iqonicdesign Wpbookit PROAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This issue affects WPBookit Pro: from n/a through <= 1.6.18. | |
| Aplazada | Crítica (9.9) | 0.33% | — | Iqonicdesign Wpbookit PROAI | 25/3/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affects WPBookit Pro: from n/a through <= 1.6.18. | |
| Analizada | Crítica (9.8) | 0.45% | — | Oracle Okit | 17/3/2026 | 17/6/2026 | Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source Projects (component: Desktop). The supported version that is affected is 0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Edge… | |
| Aplazada | Media (5.3) | 0.83% | — | Iqonic WpbookitAI | 4/3/2026 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on the 'get_customer_list' route in all versions up to, and including, 1.0.8. This makes it possible for unauthenticated attackers to retrieve sensitive customer information including names, emails,… | |
| Aplazada | Alta (7.2) | 0.33% | — | Iqonic WpbookitAI | 4/3/2026 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_email' parameters in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.22% | — | Iqonicdesign Wpbookit PROAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPBookit Pro: from n/a through <= 1.6.18. | |
| Aplazada | Media (6.5) | 0.15% | — | Iqonic WpbookitAI | 2/1/2026 | 17/6/2026 | The WPBookit WordPress plugin through 1.0.7 lacks a CSRF check when deleting customers. This could allow an unauthenticated attacker to delete any customer through a CSRF attack. | |
| Aplazada | Media (5.3) | 0.70% | — | Stylemixthemes BookitAI | 12/12/2025 | 17/6/2026 | The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows unauthenticated update of the plugins Stripe payment options. | |
| Aplazada | Alta (7.2) | 0.29% | — | Iqonic WpbookitAI | 21/11/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versions up to, and including, 1.0.6 due to a missing capability check on the save_custome_code() function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Alta (7.5) | 0.26% | — | Stylemixthemes BookitAI | 12/11/2025 | 17/6/2026 | The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '/wp-json/bookit/v1/commerce/stripe/return' REST API Endpoint in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.24% | — | DominokitAI | 4/11/2025 | 17/6/2026 | The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_nopriv_dominokit_option_admin_action AJAX endpoint in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to update plugin settings. | |
| Aplazada | Crítica (9.8) | 1.5% | — | Iqonic WpbookitAI | 24/7/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_new_customer' route in all versions up to, and including, 1.0.6. The plugin’s image‐upload handler calls move_uploaded_file() on client‐supplied files… | |
| Analizada | Crítica (9.8) | 6.0% | — | Iqonic Wpbookit | 12/7/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_booking_type' route in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Analizada | Alta (8.8) | 0.71% | — | Iqonic Wpbookit | 12/7/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the… | |
| Analizada | Crítica (9.8) | 0.75% | — | Iqonic Wpbookit | 9/5/2025 | 17/6/2026 | The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due to the plugin not properly validating a user's identity prior to updating their details like email through the edit_newdata_customer_callback() function. This makes it… |