Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Salon booking system — Vulnerabilities & Security Advisories 29

All 29 CVE vulnerabilities found in Salon booking system, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page catalogs known security flaws in the Salon booking system, categorized by their specific weakness type. It consolidates vulnerability disclosures, tracking security advisories and bug fixes over the product's available lifecycle. Readers can use this resource to monitor the vendor's patch history, analyze the distribution of different weakness classes, and review the complete vulnerability timeline for this application. The data helps security teams assess risk exposure and prioritize remediation efforts based on historical incident patterns.

Vendor: Salon Booking System

CVE ID Title CVSS Severity Published
CVE-2026-81793 WordPress Salon booking system plugin <= 10.31.5 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-09-10
CVE-2026-66453 WordPress Salon booking system plugin <= 10.30.26 - Broken Authentication vulnerability CWE-288 9.8 Critical 2026-08-13
CVE-2026-17023 Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback - - 2026-08-10
CVE-2026-17022 Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard - - 2026-08-10
CVE-2026-17021 Salon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering - - 2026-08-10
CVE-2026-17020 Salon Booking System – Free Version <= 10.31.0 - Subscriber+ Arbitrary Booking PII Disclosure - - 2026-08-10
CVE-2026-11887 Salon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass - - 2026-07-01
CVE-2026-40768 WordPress Salon booking system plugin <= 10.30.24 - Insecure Direct Object References (IDOR) vulnerability CWE-639 7.3 High 2026-06-17
CVE-2026-42666 WordPress Salon booking system plugin <= 10.30.25 - Broken Access Control vulnerability CWE-862 7.5 High 2026-06-15
CVE-2025-67954 WordPress Salon booking system plugin <= 10.30.3 - Sensitive Data Exposure vulnerability CWE-497 6.5 Medium 2026-01-22
CVE-2025-66531 WordPress Salon booking system plugin <= 10.30.3 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 4.3 Medium 2025-12-09
CVE-2025-47583 WordPress Salon booking system plugin <= 10.16 - CSRF to Arbitrary Content Deletion vulnerability CWE-352 5.4 Medium 2025-05-19
CVE-2025-32220 WordPress Salon booking system plugin <= 10.30.23 - Broken Access Control vulnerability CWE-862 5.4 Medium 2025-04-04
CVE-2025-31560 WordPress Salon booking system plugin < 10.15 - Privilege Escalation vulnerability CWE-266 7.2 High 2025-04-01
CVE-2024-47316 WordPress Salon Booking Wordpress Plugin plugin <= 10.9 - Insecure Direct Object References (IDOR) vulnerability CWE-639 4.3 Medium 2024-10-05
CVE-2024-39658 WordPress Salon Booking System plugin <= 10.7 - Authenticated SQL Injection vulnerability CWE-89 7.6 High 2024-08-29
CVE-2024-43280 WordPress Salon Booking System plugin <= 10.8.1 - Open Redirection vulnerability CWE-601 4.7 Medium 2024-08-19
CVE-2024-37231 WordPress Salon booking system plugin <= 9.9 - Arbitrary File Deletion vulnerability CWE-22 8.6 High 2024-06-24
CVE-2023-48319 WordPress Salon booking system plugin < 8.7 - Editor+ Privilege Escalation vulnerability CWE-269 6.8 Medium 2024-05-17
CVE-2024-2603 Salon booking system <= 9.6.5 - Editor+ Stored XSS via Email Settings 4.8AI Medium AI 2024-04-26
CVE-2024-2429 Salon booking system <= 9.6.5 - Settings Update via CSRF 4.3AI Medium AI 2024-04-26
CVE-2024-2439 Salon booking system <= 9.6.5 - Editor+ Stored XSS 4.8AI Medium AI 2024-04-26
CVE-2024-2102 Salon booking system < 9.6.3 - Unauthenticated Stored XSS 5.4AI Medium AI 2024-04-17
CVE-2024-2101 WordPress Plugin Salon Booking System < 9.6.3 - Unauthenticated Stored Cross-Site Scripting (XSS) 5.4AI Medium AI 2024-04-17
CVE-2024-30510 WordPress Salon booking system plugin <= 9.5 - Arbitrary File Upload vulnerability CWE-434 10.0 Critical 2024-03-29
CVE-2022-43487 WordPress plugin Salon booking system 跨站脚本漏洞 6.1 - 2022-12-05
CVE-2022-0920 Salon booking system < 7.6.3 - Customer+ Bookings/Customers Data Disclosure CWE-863 7.5 - 2022-04-11
CVE-2022-0919 Salon booking system < 7.6.3 - Unauthenticated Sensitive Data Disclosure CWE-862 5.3 - 2022-04-11
CVE-2021-24429 Salon Booking System < 6.3.1 - Unauthenticated Stored Cross-Site Scripting (XSS) CWE-79 5.4 - 2021-07-12

All 29 known CVE vulnerabilities affecting Salon booking system with full Chinese analysis, references, and POCs where available.