Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

VikBooking Hotel Booking Engine & PMS — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in VikBooking Hotel Booking Engine & PMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the VikBooking Hotel Booking Engine and Property Management System, categorized under web application weaknesses and identified by the vendor Vikjoomla. It compiles a comprehensive list of known security flaws, ranging from critical remote code execution risks to less severe cross-site scripting and information disclosure issues, covering the period from 2019 through early 2025. This aggregation serves as a centralized resource for security professionals, developers, and hotel administrators to assess the risk landscape surrounding this specific software ecosystem. Users can discover detailed information regarding the chronological progression of disclosed vulnerabilities, allowing them to track how the vendor has responded to advisories over time. The page facilitates a deeper understanding of specific weakness classes within the context of hotel booking platforms, enabling users to analyze whether certain defect patterns are recurring or isolated. By providing a structured view of the product's vulnerability history, this resource helps stakeholders make informed decisions about patch management, system hardening, and migration strategies. It eliminates the need to search through disparate bulletin boards or individual release notes, offering a consolidated timeline of security incidents. This approach supports proactive defense mechanisms by highlighting which components of the engine have been historically targeted and how effective recent remediation efforts have been in closing identified gaps.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-42683 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.8 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2026-06-01
CVE-2026-42762 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2026-05-27
CVE-2026-42737 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Arbitrary File Deletion vulnerability CWE-22 8.6 High2026-05-27
CVE-2025-49918 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.2 - Sensitive Data Exposure vulnerability CWE-201 5.9 Medium2025-12-18
CVE-2025-5803 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.2 - Broken Access Control vulnerability CWE-862 5.3 Medium2025-11-06
CVE-2024-13616 VikBooking < 1.7.2 - Admin+ Stored XSS 4.8AIMediumAI2025-05-15
CVE-2025-22670 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.7.2 - CSRF to Settings Change vulnerability CWE-862 6.5 Medium2025-03-27
CVE-2024-11641 VikBooking Hotel Booking Engine & PMS <= 1.7.2 - Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload CWE-352 8.8 High2025-01-26
CVE-2024-2749 VikBooking < 1.6.8 - Broken Access Control 6.5 -2024-05-10
CVE-2024-2441 VikBooking < 1.6.8 - Insecure Direct Object References 4.3 -2024-05-10
CVE-2024-32563 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.6.7 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-04-18
CVE-2023-32501 WordPress VikBooking Hotel Booking Engine & PMS Plugin <= 1.6.1 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium2023-11-09
CVE-2023-25707 WordPress VikBooking Hotel Booking Engine & PMS Plugin <= 1.5.12 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 6.3 Medium2023-05-23
CVE-2023-24396 WordPress VikBooking Hotel Booking Engine & PMS Plugin <= 1.5.11 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium2023-04-06
CVE-2022-1528 VikBooking < 1.5.9 - Reflected Cross-Site Scripting CWE-79 6.1 -2022-05-30
CVE-2022-1409 VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ PHP File Upload CWE-434 7.2 -2022-05-16
CVE-2022-1408 VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ Stored Cross-Site Scripting CWE-79 4.8 -2022-05-16
CVE-2022-1407 VikBooking Hotel Booking Engine & PMS < 1.5.7 - Stored Cross-Site Scripting via CSRF CWE-352 6.5 -2022-05-16

All 18 known CVE vulnerabilities affecting VikBooking Hotel Booking Engine & PMS with full Chinese analysis, references, and POCs where available.