浏览 28+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-25334 | WordPress Salon Booking System Pro plugin < 10.30.12 - Account Takeover vulnerability | wordpresschef | Salon Booking System Pro | High | 8.1 | 2026-03-25 16:14:42 | Deep Dive |
| CVE-2025-67954 | WordPress Salon booking system plugin <= 10.30.3 - Sensitive Data Exposure vulnerability | Dimitri Grassi | Salon booking system | - | - | 2026-01-22 16:51:56 | Deep Dive |
| CVE-2025-66531 | WordPress Salon booking system plugin <= 10.30.3 - Cross Site Request Forgery (CSRF) vulnerability | Dimitri Grassi | Salon booking system | Medium | 4.3 | 2025-12-09 14:13:55 | Deep Dive |
| CVE-2025-8492 | Salon Booking System <= 10.22 - Missing Authorization to Unauthenticated AJAX Actions Execution | wordpresschef | Salon Booking System – Free Version | Medium | 5.3 | 2025-09-11 07:24:57 | Deep Dive |
| CVE-2025-47583 | WordPress Salon booking system plugin <= 10.16 - CSRF to Arbitrary Content Deletion vulnerability | Dimitri Grassi | Salon booking system | Medium | 5.4 | 2025-05-19 16:07:01 | Deep Dive |
| CVE-2024-9882 | Salon Booking System < 10.9.4 - Admin+ Stored XSS | Unknown | Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses | - | - | 2025-05-15 20:07:25 | Deep Dive |
| CVE-2025-32220 | WordPress Salon booking system plugin <= 10.30.26 - Broken Access Control vulnerability | Dimitri Grassi | Salon booking system | Medium | 5.4 | 2025-04-04 15:59:15 | Deep Dive |
| CVE-2025-31560 | WordPress Salon booking system plugin < 10.15 - Privilege Escalation vulnerability | Dimitri Grassi | Salon booking system | High | 7.2 | 2025-04-01 20:58:13 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-47316 | WordPress Salon Booking Wordpress Plugin plugin <= 10.9 - Insecure Direct Object References (IDOR) vulnerability | Dimitri Grassi | Salon booking system | Medium | 4.3 | 2024-10-05 12:27:13 | Deep Dive |
| CVE-2024-39658 | WordPress Salon Booking System plugin <= 10.7 - Authenticated SQL Injection vulnerability | Salon Booking System | Salon booking system | High | 7.6 | 2024-08-29 14:42:19 | Deep Dive |
| CVE-2024-43280 | WordPress Salon Booking System plugin <= 10.8.1 - Open Redirection vulnerability | Salon Booking System | Salon booking system | Medium | 4.7 | 2024-08-19 17:45:40 | Deep Dive |
| CVE-2024-37231 | WordPress Salon booking system plugin <= 9.9 - Arbitrary File Deletion vulnerability | Salon Booking System | Salon booking system | High | 8.6 | 2024-06-24 12:39:17 | Deep Dive |
| CVE-2024-3229 | Salon Booking System <= 10.2 - Unauthenticated Arbitrary File Upload | wordpresschef | Salon Booking System – Free Version | Critical | 9.8 | 2024-06-19 04:31:59 | Deep Dive |
| CVE-2024-4468 | Salon booking system <= 9.9 - Missing Authorization | wordpresschef | Salon Booking System – Free Version | Medium | 4.3 | 2024-06-08 07:37:39 | Deep Dive |
| CVE-2024-4442 | Salon booking system <= 9.9 - Unauthenticated Arbitrary File Deletion | wordpresschef | Salon Booking System – Free Version | Critical | 9.1 | 2024-05-21 06:49:55 | Deep Dive |
| CVE-2023-48319 | WordPress Salon booking system plugin < 8.7 - Editor+ Privilege Escalation vulnerability | Salon Booking System | Salon booking system | Medium | 6.8 | 2024-05-17 08:37:58 | Deep Dive |
| CVE-2024-2603 | Salon booking system <= 9.6.5 - Editor+ Stored XSS via Email Settings | Unknown | Salon booking system | - | - | 2024-04-26 05:00:03 | Deep Dive |
| CVE-2024-2439 | Salon booking system <= 9.6.5 - Editor+ Stored XSS | Unknown | Salon booking system | - | - | 2024-04-26 05:00:03 | Deep Dive |
| CVE-2024-2429 | Salon booking system <= 9.6.5 - Settings Update via CSRF | Unknown | Salon booking system | - | - | 2024-04-26 05:00:03 | Deep Dive |