Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.23% | — | Wpamelia AmeliaAI | 17/9/2026 | 18/9/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-redemption identifier as proof of payment without validating it. This makes it… | |
| Aplazada | Media (5.4) | 0.17% | — | Ameliabooking AmeliaAI | 17/9/2026 | 18/9/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to, and including, 2.4.4. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.2) | 0.46% | — | Ameliabooking Booking FOR Appointments AND Events CalendarAI | 12/9/2026 | 14/9/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address… | |
| Aplazada | Alta (7.6) | 0.38% | — | Ameliabooking AmeliaAI | 11/9/2026 | 11/9/2026 | Editor SQL Injection in Amelia <= 2.4.9 versions. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Ameliabooking AmeliaAI | 2/9/2026 | 2/9/2026 | The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to… | |
| Aplazada | Alta (7.2) | 0.62% | — | Ameliabooking AmeliaAI | 28/8/2026 | 28/8/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication bypass where the AddBookingCommand explicitly skips nonce verification (Command.php line 186),… | |
| Aplazada | Media (4.9) | 0.41% | — | Ameliabooking AmeliaAI | 16/7/2026 | 17/7/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Crítica (9.3) | 0.45% | — | Melograno Venture Studio AmeliaAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2. | |
| Aplazada | Alta (8.8) | 0.42% | — | Ameliabooking AmeliaAI | 15/6/2026 | 17/6/2026 | Subscriber Privilege Escalation in Amelia <= 2.3 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | AmeliaAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Amelia <= 2.2 versions. | |
| Aplazada | Alta (7.5) | 0.42% | — | Ameliabooking AmeliaAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions. | |
| Aplazada | Media (5.3) | 0.42% | — | Ameliabooking AmeliaAI | 2/5/2026 | 17/6/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 2.1.2. This is due to a logical short-circuit flaw in authorization logic that causes token validation to be entirely skipped when a booking has a 'waiting'… | |
| Aplazada | Alta (7.6) | 0.38% | — | Ameliabooking AmeliaAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.1.1. | |
| Aplazada | Alta (8.8) | 0.56% | — | Ameliabooking AmeliaAI | 7/4/2026 | 17/6/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.3. This is due to the `UpdateProviderCommandHandler` failing to validate changes to the `externalId` field when a Provider (Employee) user updates… | |
| Aplazada | Media (6.5) | 0.41% | — | Ameliabooking AmeliaAI | 1/4/2026 | 17/6/2026 | The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `sort` parameter in the payments listing endpoint in all versions up to, and including, 2.1.2. This is due to insufficient escaping on the user-supplied `sort` parameter and lack of sufficient… | |
| Aplazada | Alta (8.8) | 0.55% | — | Ameliabooking AmeliaAI | 26/3/2026 | 17/6/2026 | The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9.1.2. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers… | |
| Aplazada | Alta (7.2) | 0.32% | — | Ameliabooking AmeliaAI | 5/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in ameliabooking Amelia ameliabooking allows Privilege Escalation.This issue affects Amelia: from n/a through <= 1.2.38. | |
| Aplazada | Media (5.3) | 0.26% | — | Ameliabooking AmeliaAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <= 1.2.38. | |
| Aplazada | Media (5.3) | 0.32% | — | Ameliabooking AmeliaAI | 9/1/2026 | 17/6/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on multiple AJAX actions in all versions up to, and including, 1.2.38. This makes it possible for unauthenticated attackers to mark payments as refunded, trigger sending… | |
| Aplazada | Alta (7.5) | 0.32% | — | Ameliabooking AmeliaAI | 16/11/2025 | 17/6/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Media (6.5) | 0.17% | — | Ameliabooking Booking System TrafftAI | 27/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ameliabooking Booking System Trafft booking-system-trafft allows Stored XSS.This issue affects Booking System Trafft: from n/a through <= 1.0.14. | |
| Aplazada | Media (5.3) | 0.39% | — | Wpamelia AmeliaAI | 28/3/2025 | 17/6/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2.19 via the 'wpAmeliaApiCall' function. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be… | |
| Aplazada | Media (5.3) | 0.44% | — | Ameliabooking AmeliaAI | 25/2/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in ameliabooking Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through <= 1.2.16. | |
| Modificada | Media (6.5) | 0.35% | — | Tmsproducts Amelia | 5/9/2024 | 17/6/2026 | The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the 'ameliaButtonCommand' function in all versions up to, and including, Premium 7.7 and Lite 1.2.4. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.44% | — | Wpamelia AmeliaAI | 8/8/2024 | 17/6/2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve… |