Kibokolabs
Kibokolabs Hostel: vulnerabilidades y CVE
Kibokolabs Hostel tiene 14 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-1645 | Media (4.4) | 0.19% | — | 22 sept 2026 | The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and the 'locale_url' setting in all versions up to, and including, 1.1.8 due to insufficient input… |
| CVE-2026-3907 | Media (6.4) | 0.42% | — | 10 jul 2026 | The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all versions up to and including 1.1.7. This is due to insufficient input sanitization and output… |
| CVE-2026-1838 | Media (6.1) | 0.32% | — | 18 abr 2026 | The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping.… |
| CVE-2023-32120 | Media (5.9) | 0.20% | — | 24 dic 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bob Hostel allows DOM-Based XSS.This issue affects Hostel: from n/a through 1.1.5.1. |
| CVE-2025-66119 | Alta (7.1) | 0.17% | — | 18 dic 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel allows Reflected XSS.This issue affects Hostel: from n/a through <= 1.1.5.9. |
| CVE-2025-6236 | Media (4.8) | 0.23% | — | 10 jul 2025 | The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2025-6234 | Media (6.1) | 0.25% | — | 10 jul 2025 | The Hostel WordPress plugin before 1.1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users… |
| CVE-2025-39566 | Alta (7.6) | 0.62% | — | 16 abr 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Hostel hostel allows Blind SQL Injection.This issue affects Hostel: from n/a through <= 1.1.5.6. |
| CVE-2025-30848 | Alta (7.1) | 0.31% | — | 1 abr 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel allows Reflected XSS.This issue affects Hostel: from n/a through <= 1.1.5. |
| CVE-2025-31102 | Alta (7.1) | 0.22% | — | 28 mar 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel allows Reflected XSS.This issue affects Hostel: from n/a through <= 1.1.5.5. |
| CVE-2024-3753 | Media (5.9) | 0.80% | — | 13 jul 2024 | The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users… |
| CVE-2024-4314 | Media (4.3) | 0.21% | — | 14 may 2024 | The Hostel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5.3. This is due to missing or incorrect nonce validation when managing rooms. This makes it possible… |
| CVE-2023-0545 | Media (4.8) | 0.44% | — | 5 jun 2023 | The Hostel WordPress plugin before 1.1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2019-12345 | Media (6.1) | 1.2% | — | 27 may 2019 | XSS exists in the Kiboko Hostel plugin before 1.1.4 for WordPress. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.