CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-39658HIGH | WordPress Salon Booking System plugin <= 10.7 - Authenticated SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salon Booking System Salon booking system allows SQL Injection.This issue affects Salon booking system: from n/a through 10.7. CWE-89Aug 29, 2024 | CVSS7.6v3.1 | EPSS0.438% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43280MEDIUM | WordPress Salon Booking System plugin <= 10.8.1 - Open Redirection vulnerabilityURL Redirection to Untrusted Site ('Open Redirect') vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 10.8.1. CWE-601Aug 19, 2024 | CVSS4.7v3.1 | EPSS0.257% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37231HIGH | WordPress Salon booking system plugin <= 9.9 - Arbitrary File Deletion vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salon Booking System Salon booking system allows File Manipulation.This issue affects Salon booking system: from n/a through 9.9. CWE-22Jun 24, 2024 | CVSS8.6v3.1 | EPSS0.581% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-48319MEDIUM | WordPress Salon booking system plugin < 8.7 - Editor+ Privilege Escalation vulnerabilityImproper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6. CWE-269May 17, 2024 | CVSS6.8v3.1 | EPSS0.524% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30510CRITICAL | WordPress Salon booking system plugin <= 9.5 - Arbitrary File Upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5. CWE-434Mar 29, 2024 | CVSS10.0v3.1 | EPSS0.668% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-43487MEDIUM | Cross-site scripting vulnerability in Salon booking system versions prior to 7.9 allows a remote unauthenticated attacker to inject an arbitrary script. CWE-79Dec 5, 2022 | CVSS6.1v3.1 | EPSS0.785% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24429MEDIUM | Salon Booking System < 6.3.1 - Unauthenticated Stored Cross-Site Scripting (XSS)The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability. The Payload will then be triggered when an admin visits the "Calendar" page and the malicious script is executed in the admin context. CWE-79Jul 12, 2021 | CVSS6.1v3.1 | EPSS1.24% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |