| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-13135 | HotelRunner Booking Widget <= 5.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | integrationshotelrunner | HotelRunner Booking Widget | Medium | 6.4 | 2025-11-21 07:31:57 | Deep Dive |
| CVE-2025-60168 | WordPress HotelRunner Booking Widget Plugin <= 1.6 - Cross Site Request Forgery (CSRF) Vulnerability | integrationshotelrunner | HotelRunner Booking Widget | - | - | 2025-10-22 14:32:42 | Deep Dive |
| CVE-2025-4296 | Open Redirect in HotelRunner's B2B | HotelRunner | B2B | Medium | 4.7 | 2025-07-23 11:21:58 | Deep Dive |
| CVE-2025-4295 | Host Header Injection in HotelRunner's B2B | HotelRunner | B2B | Medium | 4.6 | 2025-07-22 13:58:01 | Deep Dive |
| CVE-2025-4294 | XSS in HotelRunner's B2B | HotelRunner | B2B | Medium | 4.8 | 2025-07-22 13:54:00 | Deep Dive |