Saasproject
Saasproject Booking Package: vulnerabilidades y CVE
Saasproject Booking Package tiene 10 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-16986 | Media (5.3) | 0.22% | — | 26 ago 2026 | The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an… |
| CVE-2026-15335 | Alta (7.5) | 0.76% | — | 11 jul 2026 | The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and including, 1.7.20 due to insufficient escaping on the user supplied… |
| CVE-2026-9851 | Alta (7.2) | 0.61% | — | 6 jun 2026 | The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the… |
| CVE-2026-4911 | Media (5.3) | 0.53% | — | 28 abr 2026 | The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 This is due to the intentForStripe() function passing user-controlled $_POST['amount'] directly to… |
| CVE-2024-30516 | Alta (7.5) | 0.26% | — | 5 ene 2026 | Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking Package: from n/a through 1.6.27. |
| CVE-2024-13508 | Media (6.1) | 0.29% | — | 19 feb 2025 | The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all versions up to, and including, 1.6.72 due to insufficient input sanitization and output escaping.… |
| CVE-2023-37389 | Alta (8.8) | 0.67% | — | 17 may 2024 | Improper Privilege Management vulnerability in SAASPROJECT Booking Package Booking Package allows Privilege Escalation.This issue affects Booking Package: from n/a through 1.5.98. |
| CVE-2023-39918 | Media (6.1) | 0.39% | — | 4 sept 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SAASPROJECT Booking Package Booking Package plugin <= 1.6.01 versions. |
| CVE-2022-0709 | Alta (7.5) | 1.6% | — | 4 abr 2022 | The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a… |
| CVE-2021-20840 | Media (6.1) | 1.3% | — | 24 nov 2021 | Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions prior to 1.5.11 allows a remote attacker to inject an arbitrary script via unspecified vectors. |