Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

VikBooking Hotel Booking Engine & PMS — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in VikBooking Hotel Booking Engine & PMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting VikBooking Hotel Booking Engine & PMS, a hotel property management system developed by Vik Software. It collects publicly disclosed security flaws identified in this specific product, covering advisories released over the past five years. Readers can use this page to track the vendor's recent security updates, understand the distribution of weakness types such as SQL injection or authentication bypasses, and review the full vulnerability history for this product. The data enables security teams to assess exposure, prioritize patching efforts, and monitor emerging threat patterns without manual cross-referencing across multiple sources.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-85127 VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment - - 2026-09-18
CVE-2026-15401 VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter CWE-79 7.2 High 2026-07-24
CVE-2026-15346 VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Reflected Cross-Site Scripting via 'category_id' Parameter CWE-79 6.1 Medium 2026-07-24
CVE-2026-6820 VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via Booking Form Email Field CWE-79 7.2 High 2026-07-08
CVE-2026-6818 VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via 'special_requests' Parameter CWE-79 7.2 High 2026-07-08
CVE-2026-57723 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.12 - CSRF to Arbitrary File Deletion vulnerability CWE-352 7.4 High 2026-07-01
CVE-2026-12754 VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Reflected Cross-Site Scripting via 'layoutstyle' Parameter CWE-79 6.1 Medium 2026-07-01
CVE-2026-42683 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.8 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-06-01
CVE-2026-42762 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-05-27
CVE-2026-42737 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Arbitrary File Deletion vulnerability CWE-22 8.6 High 2026-05-27
CVE-2025-49918 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.2 - Sensitive Data Exposure vulnerability CWE-201 5.9 Medium 2025-12-18
CVE-2025-5803 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.2 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-11-06
CVE-2024-13616 VikBooking < 1.7.2 - Admin+ Stored XSS 4.8AI Medium AI 2025-05-15
CVE-2025-22670 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.7.2 - CSRF to Settings Change vulnerability CWE-862 6.5 Medium 2025-03-27
CVE-2024-11641 VikBooking Hotel Booking Engine & PMS <= 1.7.2 - Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload CWE-352 8.8 High 2025-01-26
CVE-2024-2749 VikBooking < 1.6.8 - Broken Access Control 6.5 - 2024-05-10
CVE-2024-2441 VikBooking < 1.6.8 - Insecure Direct Object References 4.3 - 2024-05-10
CVE-2024-32563 WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.6.7 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2024-04-18
CVE-2023-32501 WordPress VikBooking Hotel Booking Engine & PMS Plugin <= 1.6.1 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 4.3 Medium 2023-11-09
CVE-2023-25707 WordPress VikBooking Hotel Booking Engine & PMS Plugin <= 1.5.12 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 6.3 Medium 2023-05-23
CVE-2023-24396 WordPress VikBooking Hotel Booking Engine & PMS Plugin <= 1.5.11 is vulnerable to Cross Site Scripting (XSS) CWE-79 5.9 Medium 2023-04-06
CVE-2022-1528 VikBooking < 1.5.9 - Reflected Cross-Site Scripting CWE-79 6.1 - 2022-05-30
CVE-2022-1409 VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ PHP File Upload CWE-434 7.2 - 2022-05-16
CVE-2022-1408 VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ Stored Cross-Site Scripting CWE-79 4.8 - 2022-05-16
CVE-2022-1407 VikBooking Hotel Booking Engine & PMS < 1.5.7 - Stored Cross-Site Scripting via CSRF CWE-352 6.5 - 2022-05-16

All 25 known CVE vulnerabilities affecting VikBooking Hotel Booking Engine & PMS with full Chinese analysis, references, and POCs where available.