Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.36% | — | Codepeople WP Time Slots Booking FormAI | 15/6/2026 | 17/6/2026 | Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Codepeople WP Time Slots Booking FormAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Codepeople WP Time Slots Booking FormAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.42. | |
| Aplazada | Media (6.5) | 0.29% | — | Codepeople WP Time Slots Booking FormAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.39. | |
| Aplazada | Media (5.3) | 0.29% | — | Booking Plugin FOR Wordpress Appointments Time SlotAI | 19/11/2025 | 17/6/2026 | The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 due to missing validation on the tslot_appt_email AJAX action. This makes it possible for unauthenticated attackers to send appointment notification emails… | |
| Aplazada | Media (4.3) | 0.14% | — | Codepeople WP Time Slots Booking FormAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Cross Site Request Forgery.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.30. | |
| Modificada | Alta (7.2) | 0.71% | — | Codepeople WP Time Slots Booking Form | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through 1.1.82. | |
| Aplazada | Media (6.5) | 0.25% | — | Time Slot Booking Time SlotAI | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Time Slot Booking Time Slot timeslot allows DOM-Based XSS.This issue affects Time Slot: from n/a through <= 1.3.6. | |
| Modificada | Crítica (9.8) | 0.40% | — | Codepeople WP Time Slots Booking Form | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.11. | |
| Modificada | Alta (7.5) | 0.42% | — | Codepeople WP Time Slots Booking Form | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.06. | |
| Modificada | Media (6.1) | 0.31% | — | Codepeople WP Time Slots Booking Form | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople WP Time Slots Booking Form allows Stored XSS.This issue affects WP Time Slots Booking Form: from n/a through 1.2.10. | |
| Modificada | Alta (8.8) | 0.47% | — | Codepeople WP Time Slots Booking Form | 17/1/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion. | |
| Modificada | Media (5.4) | 0.46% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. | |
| Modificada | Media (5.4) | 0.46% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Phpjabbers Time Slots Booking Calendar | 7/12/2023 | 17/6/2026 | Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List. | |
| Modificada | Media (6.1) | 0.50% | — | Phpjabbers Time Slots Booking Calendar | 1/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3. | |
| Modificada | Alta (8.8) | 0.76% | — | Phpjabbers Time Slots Booking Calendar | 1/8/2023 | 17/6/2026 | In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. | |
| Modificada | Crítica (9.8) | 0.77% | — | Phpjabbers Time Slots Booking Calendar | 1/8/2023 | 17/6/2026 | User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.99% | — | Phpjabbers Time Slots Booking Calendar | 1/8/2023 | 17/6/2026 | Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords. | |
| Modificada | Media (6.1) | 0.50% | — | Phpjabbers Time Slots Booking Calendar | 1/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3. | |
| Modificada | Media (6.1) | 0.39% | — | Gzscripts Time Slot Booking Calendar PHP | 7/7/2023 | 17/6/2026 | A vulnerability was found in GZ Scripts Time Slot Booking Calendar PHP 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack can be initiated… | |
| Modificada | Media (4.8) | 0.39% | — | Codepeople WP Time Slots Booking Form | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CodePeople WP Time Slots Booking Form plugin <= 1.1.81 versions. | |
| Modificada | Media (4.8) | 0.60% | — | Codepeople WP Time Slots Booking Form | 7/3/2022 | 17/6/2026 | The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. |