Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2554▼ 405 respecto a la semana anterior
Críticas / altas1317▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
–

393 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.40%—Motopress Hotel BookingAI15/9/202616/9/2026
The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (6.6)0.23%—Digitaldruid HoteldruidAI14/9/202622/9/2026
HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
AplazadaMedia (5.5)0.53%—Code-projects Hotel AND Tourism ReservationAI6/9/202611/9/2026
A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may…
AplazadaBaja (2.1)0.47%—Code-projects Hotel AND Tourism ReservationAIPHPAI6/9/20268/9/2026
A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may…
AplazadaMedia (5.4)0.23%—Motopress Hotel BookingAI10/8/202626/8/2026
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
AplazadaMedia (5.3)0.30%—Motopress Hotel BookingAI10/8/202626/8/2026
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.
AplazadaMedia (5.3)0.16%—Thimpress WP Hotel BookingAI6/8/202626/8/2026
The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to have their bookings marked as fully paid without any payment reaching…
AplazadaMedia (5.3)0.32%—Thimpress WP Hotel BookingAI6/8/202626/8/2026
The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or at an arbitrarily reduced price.
AplazadaMedia (4.3)0.29%—Motopress Hotel BookingAI30/7/202630/7/2026
The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and…
AplazadaMedia (6.8)0.39%—Thimpress WP Hotel BookingAI30/7/202630/7/2026
The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks.
AplazadaAlta (7.5)0.42%—Byteflows Travel & Hotel BookingAI27/7/202627/7/2026
Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.
AplazadaMedia (6.4)0.33%—Thimpress WP Hotel BookingAI24/7/202624/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
AplazadaMedia (6.1)0.69%—Thimpress WP Hotel BookingAI17/7/202617/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaBaja (2)0.33%—Amtt Hotel Broadband Operation SystemAI12/7/202613/7/2026
A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/network/switch_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The…
AplazadaMedia (5.3)0.26%—Thimpress WP Hotel BookingAI11/7/202614/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is due to the `web_hook_process_paypal_standard()` IPN handler selecting its PayPal validation endpoint from the attacker-controlled `$_REQUEST['test_ipn']`…
AplazadaMedia (6.1)0.45%—Thimpress WP Hotel BookingAI10/7/202614/7/2026
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (5.5)0.43%—Code-projects Hotel AND Tourism ReservationAI5/7/20266/7/2026
A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the file /admin/add_event.php of the component Event Management Page. Such manipulation of the argument fdetails leads to sql injection. The attack can be launched remotely. The exploit has been…
AplazadaMedia (5.5)0.43%—Code-projects Hotel AND Tourism ReservationAI5/7/20266/7/2026
A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. This affects an unknown function of the file /admin/tour_reserves.php of the component Tour Reservations Page. This manipulation of the argument tour causes sql injection. The attack can be initiated remotely. The exploit has been published and…
AplazadaMedia (5.5)0.43%—Code-projects Hotel AND Tourism ReservationAI5/7/20267/7/2026
A vulnerability was detected in code-projects Hotel and Tourism Reservation 1.0. The impacted element is an unknown function of the file /admin/rooms.php of the component Room Management Page. The manipulation of the argument delete results in sql injection. It is possible to launch the attack remotely. The exploit is…
AplazadaMedia (5.5)0.43%—Code-projects Hotel AND Tourism ReservationAI5/7/20267/7/2026
A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component Tour Management Page. The manipulation of the argument delete_image results in sql injection. The attack may be launched remotely. The…
AplazadaMedia (5.5)0.43%—Code-projects Hotel AND Tourism ReservationAI5/7/20266/7/2026
A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reservations.php of the component Reservations Management Page. The manipulation of the argument delete leads to sql injection. The attack may be initiated…
AplazadaMedia (5.5)0.43%—Code-projects Hotel AND Tourism ReservationAI5/7/20266/7/2026
A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. Affected is an unknown function of the file /admin/add_room.php. Executing a manipulation of the argument delete_image/edit/description/number/price/rooms/type can lead to sql injection. The attack can be launched remotely. The exploit has been…
AplazadaMedia (5.5)0.43%—Itsourcecode Online Hotel Management SystemAI5/7/20266/7/2026
A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. The affected element is an unknown function of the file /admin/login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
AplazadaMedia (6.5)0.37%—Motopress Hotel Booking LiteAI2/7/20262/7/2026
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
AplazadaAlta (7.4)0.17%—E4jvikwp Vikbooking Hotel Booking Engine AND PMSAI1/7/20261/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12.