Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.23%—Wpamelia AmeliaAI17/9/202618/9/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-redemption identifier as proof of payment without validating it. This makes it…
AplazadaMedia (5.4)0.17%—Ameliabooking AmeliaAI17/9/202618/9/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.2)0.46%—Ameliabooking Booking FOR Appointments AND Events CalendarAI12/9/202614/9/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address…
AplazadaAlta (7.6)0.38%—Ameliabooking AmeliaAI11/9/202611/9/2026
Editor SQL Injection in Amelia <= 2.4.9 versions.
AplazadaCrítica (9.8)0.51%—Ameliabooking AmeliaAI2/9/20262/9/2026
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to…
AplazadaAlta (7.2)0.62%—Ameliabooking AmeliaAI28/8/202628/8/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication bypass where the AddBookingCommand explicitly skips nonce verification (Command.php line 186),…
AplazadaMedia (4.9)0.41%—Ameliabooking AmeliaAI16/7/202617/7/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaCrítica (9.3)0.45%—Melograno Venture Studio AmeliaAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2.
AplazadaAlta (8.8)0.42%—Ameliabooking AmeliaAI15/6/202617/6/2026
Subscriber Privilege Escalation in Amelia <= 2.3 versions.
AplazadaMedia (6.5)0.30%—AmeliaAI15/6/202617/6/2026
Subscriber Broken Access Control in Amelia <= 2.2 versions.
AplazadaAlta (7.5)0.42%—Ameliabooking AmeliaAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.
AplazadaMedia (5.3)0.42%—Ameliabooking AmeliaAI2/5/202617/6/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting'…
AplazadaAlta (7.6)0.38%—Ameliabooking AmeliaAI8/4/202624/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.1.1.
AplazadaAlta (8.8)0.56%—Ameliabooking AmeliaAI7/4/202617/6/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to the `externalId` field when a Provider (Employee) user updates…
AplazadaMedia (6.5)0.41%—Ameliabooking AmeliaAI1/4/202617/6/2026
The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and including, 2.1.2. This is due to insufficient escaping on the user-supplied `sort` parameter and lack of sufficient…
AplazadaAlta (8.8)0.55%—Ameliabooking AmeliaAI26/3/202617/6/2026
The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers…
AplazadaAlta (7.2)0.32%—Ameliabooking AmeliaAI5/3/202617/6/2026
Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n/a through <= 1.2.38.
AplazadaMedia (5.3)0.26%—Ameliabooking AmeliaAI3/2/202617/6/2026
Missing Authorization vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <= 1.2.38.
AplazadaMedia (5.3)0.32%—Ameliabooking AmeliaAI9/1/202617/6/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger sending…
AplazadaAlta (7.5)0.32%—Ameliabooking AmeliaAI16/11/202517/6/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaMedia (6.5)0.17%—Ameliabooking Booking System TrafftAI27/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ameliabooking Booking System Trafft booking-system-trafft allows Stored XSS.This issue affects Booking System Trafft: from n/a through <= 1.0.14.
AplazadaMedia (5.3)0.39%—Wpamelia AmeliaAI28/3/202517/6/2026
The Booking for Appointments and Events Calendar &#8211; Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be…
AplazadaMedia (5.3)0.44%—Ameliabooking AmeliaAI25/2/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <= 1.2.16.
ModificadaMedia (6.5)0.35%—Tmsproducts Amelia5/9/202417/6/2026
The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the 'ameliaButtonCommand' function in all versions up to, and including, Premium 7.7 and Lite 1.2.4. This makes it possible for…
AplazadaMedia (5.3)0.44%—Wpamelia AmeliaAI8/8/202417/6/2026
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve…