All 6 CVE vulnerabilities found in Service Finder Bookings, with AI-generated Chinese analysis, references, and POCs.
Vendor: aonetheme
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-6574 | Service Finder Bookings < 6.1 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover CWE-639 | 8.8 | High | 2025-11-01 |
| CVE-2025-5949 | Service Finder Bookings <= 6.0 - Authenticated (Subscriber+) Privilege Escalation via change_candidate_password CWE-639 | 8.8 | High | 2025-11-01 |
| CVE-2025-5948 | Service Finder Bookings <= 6.0 - Unauthenticated Privilege Escalation via claim_business CWE-639 | 9.8 | Critical | 2025-09-19 |
| CVE-2025-5947 | Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie CWE-639 | 9.8 | Critical | 2025-08-01 |
| CVE-2025-2470 | Service Finder Bookings <= 5.1 - Unauthenticated Privilege Escalation via 'nsl_registration_store_extra_input' CWE-266 | 9.8 | Critical | 2025-04-25 |
| CVE-2024-13442 | Service Finder Bookings <= 5.0 - Unauthenticated Privilege Escalation via Account Takeover CWE-288 | 9.8 | Critical | 2025-03-19 |
All 6 known CVE vulnerabilities affecting Service Finder Bookings with full Chinese analysis, references, and POCs where available.