Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.36%—Codepeople WP Time Slots Booking FormAI15/6/202617/6/2026
Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.
AplazadaAlta (7.1)0.25%—Codepeople WP Time Slots Booking FormAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions.
AplazadaMedia (5.3)0.29%—Codepeople WP Time Slots Booking FormAI13/3/202617/6/2026
Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.42.
AplazadaMedia (6.5)0.29%—Codepeople WP Time Slots Booking FormAI24/12/202517/6/2026
Missing Authorization vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.39.
AplazadaMedia (5.3)0.29%—Booking Plugin FOR Wordpress Appointments Time SlotAI19/11/202517/6/2026
The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sending in versions up to, and including, 1.4.7 due to missing validation on the tslot_appt_email AJAX action. This makes it possible for unauthenticated attackers to send appointment notification emails…
AplazadaMedia (4.3)0.14%—Codepeople WP Time Slots Booking FormAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in codepeople WP Time Slots Booking Form wp-time-slots-booking-form allows Cross Site Request Forgery.This issue affects WP Time Slots Booking Form: from n/a through <= 1.2.30.
ModificadaAlta (7.2)0.71%—Codepeople WP Time Slots Booking Form9/12/202417/6/2026
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Time Slots Booking Form: from n/a through 1.1.82.
AplazadaMedia (6.5)0.25%—Time Slot Booking Time SlotAI29/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Time Slot Booking Time Slot timeslot allows DOM-Based XSS.This issue affects Time Slot: from n/a through <= 1.3.6.
ModificadaCrítica (9.8)0.40%—Codepeople WP Time Slots Booking Form10/6/202417/6/2026
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.11.
ModificadaAlta (7.5)0.42%—Codepeople WP Time Slots Booking Form9/6/202417/6/2026
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.2.06.
ModificadaMedia (6.1)0.31%—Codepeople WP Time Slots Booking Form8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople WP Time Slots Booking Form allows Stored XSS.This issue affects WP Time Slots Booking Form: from n/a through 1.2.10.
ModificadaAlta (8.8)0.47%—Codepeople WP Time Slots Booking Form17/1/202417/6/2026
Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76.
ModificadaAlta (7.5)1.1%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.
ModificadaMedia (5.4)0.46%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
Time Slots Booking Calendar 4.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
ModificadaMedia (5.4)0.46%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
Time Slots Booking Calendar 4.0 is vulnerable to Multiple HTML Injection issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
ModificadaAlta (8.8)1.2%—Phpjabbers Time Slots Booking Calendar7/12/202317/6/2026
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
ModificadaMedia (6.1)0.50%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.
ModificadaAlta (8.8)0.76%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
In PHP Jabbers Time Slots Booking Calendar 3.3 , lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.
ModificadaCrítica (9.8)0.77%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
User enumeration is found in in PHP Jabbers Time Slots Booking Calendar v3.3. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)0.99%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
Improper input validation of password parameter in PHP Jabbers Time Slots Booking Calendar v 3.3 results in insecure passwords.
ModificadaMedia (6.1)0.50%—Phpjabbers Time Slots Booking Calendar1/8/202317/6/2026
There is a Cross Site Scripting (XSS) vulnerability in "cid" parameter of preview.php in PHPJabbers Time Slots Booking Calendar v3.3.
ModificadaMedia (6.1)0.39%—Gzscripts Time Slot Booking Calendar PHP7/7/202317/6/2026
A vulnerability was found in GZ Scripts Time Slot Booking Calendar PHP 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack can be initiated…
ModificadaMedia (4.8)0.39%—Codepeople WP Time Slots Booking Form6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in CodePeople WP Time Slots Booking Form plugin <= 1.1.81 versions.
ModificadaMedia (4.8)0.60%—Codepeople WP Time Slots Booking Form7/3/202217/6/2026
The WP Time Slots Booking Form WordPress plugin before 1.1.63 does not sanitise and escape Calendar names, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.