| CVE-2023-2298 | Online Booking & Scheduling Calendar for WordPress by vcita <= 4.3.0 - Unauthenticated Stored Cross-Site Scripting | vcita | Online Booking & Scheduling Calendar for WordPress by vcita | High | 7.2 | 2023-06-03 04:35:16 | Deep Dive |
| CVE-2023-2415 | Online Booking & Scheduling Calendar for WordPress by vcita <= 4.2.10 - Missing Authorization to Account Logout | vcita | Online Booking & Scheduling Calendar for WordPress by vcita | Medium | 5.4 | 2023-06-03 04:35:16 | Deep Dive |
| CVE-2023-2299 | Online Booking & Scheduling Calendar for WordPress by vcita <= 4.4.2 - Missing Authorization on REST-API | vcita | Online Booking & Scheduling Calendar for WordPress by vcita | Medium | 5.3 | 2023-06-03 04:35:14 | Deep Dive |
| CVE-2023-1159 | WordPress plugin Bookly 跨站脚本漏洞 | ladela | WordPress Online Booking and Scheduling Plugin – Bookly | Medium | 4.0 | 2023-06-02 06:06:48 | Deep Dive |
| CVE-2022-46816 | WordPress Booking Ultra Pro Plugin <= 1.1.4 is vulnerable to Cross Site Request Forgery (CSRF) | Booking Ultra Pro | Booking Ultra Pro Appointments Booking Calendar Plugin | Medium | 4.3 | 2023-05-24 15:45:23 | Deep Dive |
| CVE-2023-25707 | WordPress VikBooking Hotel Booking Engine & PMS Plugin <= 1.5.12 is vulnerable to Cross Site Request Forgery (CSRF) | E4J s.r.l. | VikBooking Hotel Booking Engine & PMS | Medium | 6.3 | 2023-05-23 12:36:41 | Deep Dive |
| CVE-2023-27918 | WordPress plugin Appointment and Event Booking Calendar for WordPress 跨站脚本漏洞 | TMS | Appointment and Event Booking Calendar for WordPress - Amelia | 中危 | - | 2023-05-10 00:00:00 | Deep Dive |
| CVE-2023-0768 | Avirato hotels online booking engine <= 5.0.5 - Subscriber+ SQLi | Unknown | Avirato hotels online booking engine | 高危 | - | 2023-05-08 13:58:02 | Deep Dive |
| CVE-2023-24402 | WordPress WP Booking System Plugin <= 2.0.18 is vulnerable to Cross Site Scripting (XSS) | Veribo, Roland Murg | WP Booking System – Booking Calendar | Medium | 5.9 | 2023-04-07 08:48:20 | Deep Dive |
| CVE-2023-25062 | WordPress Pinpoint Booking System Plugin <= 2.9.9.2.8 is vulnerable to Cross Site Scripting (XSS) | PINPOINT.WORLD | Pinpoint Booking System | Medium | 5.9 | 2023-04-06 13:59:51 | Deep Dive |
| CVE-2023-24396 | WordPress VikBooking Hotel Booking Engine & PMS Plugin <= 1.5.11 is vulnerable to Cross Site Scripting (XSS) | E4J s.r.l. | VikBooking Hotel Booking Engine & PMS | Medium | 5.9 | 2023-04-06 13:14:37 | Deep Dive |
| CVE-2023-23971 | WordPress WP Time Slots Booking Form Plugin <= 1.1.81 is vulnerable to Cross Site Scripting (XSS) | CodePeople | WP Time Slots Booking Form | Medium | 5.9 | 2023-04-06 05:04:11 | Deep Dive |
| CVE-2022-47438 | WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.3 is vulnerable to Cross Site Scripting (XSS) | WpDevArt | Booking calendar, Appointment Booking System | Medium | 5.9 | 2023-03-29 12:29:04 | Deep Dive |
| CVE-2023-1172 | WordPress Plugin Bookly 跨站脚本漏洞 | ladela | WordPress Online Booking and Scheduling Plugin – Bookly | High | 7.2 | 2023-03-17 12:20:31 | Deep Dive |
| CVE-2023-1374 | Solidres <= 0.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting | solidres | Solidres – Hotel booking plugin for WordPress | Medium | 4.4 | 2023-03-13 12:31:14 | Deep Dive |
| CVE-2023-24388 | WordPress Booking calendar, Appointment Booking System Plugin <= 3.2.3 is vulnerable to Cross Site Request Forgery (CSRF) | WpDevArt | Booking calendar, Appointment Booking System | Medium | 5.4 | 2023-02-17 14:25:11 | Deep Dive |
| CVE-2023-0220 | Pinpoint Booking System < 2.9.9.2.9 - Subscriber+ SQLi | Unknown | Pinpoint Booking System | 高危 | - | 2023-02-13 14:32:08 | Deep Dive |
| CVE-2023-0283 | SourceCodester Online Flight Booking Management System POST Parameter review_search.php sql injection | SourceCodester | Online Flight Booking Management System | Medium | 6.3 | 2023-01-13 09:20:41 | Deep Dive |
| CVE-2023-0281 | SourceCodester Online Flight Booking Management System judge_panel.php sql injection | SourceCodester | Online Flight Booking Management System | Medium | 6.3 | 2023-01-13 09:18:28 | Deep Dive |
| CVE-2023-0245 | SourceCodester Online Flight Booking Management System add_contestant.php sql injection | SourceCodester | Online Flight Booking Management System | Medium | 6.3 | 2023-01-12 14:52:11 | Deep Dive |