Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

VikBooking Hotel Booking Engine & PMS — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in VikBooking Hotel Booking Engine & PMS, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities affecting VikBooking, a hotel booking engine and property management system developed by the vendor VikRabbits, categorized under common weakness types such as cross-site scripting and broken access control. The collection comprises verified vulnerability reports and security advisories covering the period from January 2020 through December 2023, reflecting the historical security posture of the software during this timeframe. Here, users can track a vendor's advisories to stay informed about official patches and mitigation strategies released by the development team. Additionally, visitors can understand a weakness class by analyzing recurring patterns and technical details associated with specific flaws in the booking engine’s architecture. The resource also allows users to look up a product's vulnerability history, providing a chronological view of issues discovered and resolved, which aids in assessing long-term maintenance quality. This aggregated data serves as a reference for security researchers, system administrators, and hoteliers evaluating the risk profile of VikBooking implementations. By centralizing these records, the page facilitates transparency regarding known defects without promoting or discouraging the use of the software. It offers a factual baseline for auditing third-party components and making informed decisions about system integrity, compliance, and potential exposure to exploitation in live environments. The information presented is strictly technical and intended for professional security analysis purposes only.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-15401 VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter CWE-79 7.2 High2026-07-24
CVE-2026-15346 VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Reflected Cross-Site Scripting via 'category_id' Parameter CWE-79 6.1 Medium2026-07-24
CVE-2026-6820 VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via Booking Form Email Field CWE-79 7.2 High2026-07-08
CVE-2026-6818 VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via 'special_requests' Parameter CWE-79 7.2 High2026-07-08
CVE-2026-57723 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.12 - CSRF to Arbitrary File Deletion vulnerability CWE-352 7.4 High2026-07-01
CVE-2026-12754 VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Reflected Cross-Site Scripting via 'layoutstyle' Parameter CWE-79 6.1 Medium2026-07-01
CVE-2026-42683 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.8 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2026-06-01
CVE-2026-42762 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2026-05-27
CVE-2026-42737 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Arbitrary File Deletion vulnerability CWE-22 8.6 High2026-05-27
CVE-2025-49918 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.2 - Sensitive Data Exposure vulnerability CWE-201 5.9 Medium2025-12-18
CVE-2025-5803 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.2 - Broken Access Control vulnerability CWE-862 5.3 Medium2025-11-06
CVE-2024-13616 VikBooking < 1.7.2 - Admin+ Stored XSS 4.8AIMediumAI2025-05-15
CVE-2025-22670 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.7.2 - CSRF to Settings Change vulnerability CWE-862 6.5 Medium2025-03-27
CVE-2024-11641 VikBooking Hotel Booking Engine & PMS <= 1.7.2 - Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload CWE-352 8.8 High2025-01-26
CVE-2024-2749 VikBooking < 1.6.8 - Broken Access Control 6.5 -2024-05-10
CVE-2024-2441 VikBooking < 1.6.8 - Insecure Direct Object References 4.3 -2024-05-10
CVE-2024-32563 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.6.7 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-04-18
CVE-2023-32501 WordPress VikBooking Hotel Booking Engine & PMS Plugin <= 1.6.1 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium2023-11-09
CVE-2023-25707 WordPress VikBooking Hotel Booking Engine & PMS Plugin <= 1.5.12 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 6.3 Medium2023-05-23
CVE-2023-24396 WordPress VikBooking Hotel Booking Engine & PMS Plugin <= 1.5.11 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium2023-04-06
CVE-2022-1528 VikBooking < 1.5.9 - Reflected Cross-Site Scripting CWE-79 6.1 -2022-05-30
CVE-2022-1409 VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ PHP File Upload CWE-434 7.2 -2022-05-16
CVE-2022-1408 VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ Stored Cross-Site Scripting CWE-79 4.8 -2022-05-16
CVE-2022-1407 VikBooking Hotel Booking Engine & PMS < 1.5.7 - Stored Cross-Site Scripting via CSRF CWE-352 6.5 -2022-05-16

All 24 known CVE vulnerabilities affecting VikBooking Hotel Booking Engine & PMS with full Chinese analysis, references, and POCs where available.