All 5 CVE vulnerabilities found in Salon Booking System – Free Version, with AI-generated Chinese analysis, references, and POCs.
Vendor: wordpresschef
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-8492 | Salon Booking System <= 10.22 - Missing Authorization to Unauthenticated AJAX Actions Execution CWE-862 | 5.3 | Medium | 2025-09-11 |
| CVE-2024-3229 | Salon Booking System <= 10.2 - Unauthenticated Arbitrary File Upload CWE-434 | 9.8 | Critical | 2024-06-19 |
| CVE-2024-4468 | Salon booking system <= 9.9 - Missing Authorization CWE-280 | 4.3 | Medium | 2024-06-08 |
| CVE-2024-4442 | Salon booking system <= 9.9 - Unauthenticated Arbitrary File Deletion CWE-22 | 9.1 | Critical | 2024-05-21 |
| CVE-2023-3427 | Salon Booking System <= 8.4.6 - Cross-Site Request Forgery to Admin Role Change to Customer, User Meta Update via save_customer CWE-352 | 5.4 | Medium | 2023-06-28 |
All 5 known CVE vulnerabilities affecting Salon Booking System – Free Version with full Chinese analysis, references, and POCs where available.