Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ameliabooking — Vulnerabilities & Security Advisories 20

Browse all 20 CVE security advisories affecting ameliabooking. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Ameliabooking serves as a medical appointment scheduling platform, enabling healthcare providers to manage patient bookings and appointments. Historically, it has been susceptible to multiple vulnerability classes, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, with 19 CVEs documented to date. Notable security characteristics reveal consistent authentication and authorization flaws, often leading to unauthorized access or data exposure. While no major public incidents have been widely reported, the high CVE count suggests ongoing security challenges that require robust patch management and input validation to mitigate risks associated with web-based medical management systems.

CVE ID Title CVSS Severity Published
CVE-2026-8791 Booking System Trafft <= 1.0.17 - Authenticated (Subscriber+) Stored Cross-Site Scripting — Booking System Trafft CWE-79 6.4 Medium 2026-07-29
CVE-2026-6449 Booking for Appointments and Events Calendar – Amelia <= 2.1.2 - Unauthenticated Authorization Bypass via Remote Approval Endpoint — Booking for Appointments and Events Calendar – Amelia CWE-285 5.3 Medium 2026-05-02
CVE-2026-39487 WordPress Amelia plugin <= 2.1.1 - SQL Injection vulnerability — Amelia CWE-89 7.6 High 2026-04-08
CVE-2026-5465 Amelia <= 2.1.3 - Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter — Booking for Appointments and Events Calendar – Amelia CWE-639 8.8 High 2026-04-07
CVE-2026-4668 Amelia <= 2.1.2 - Authenticated (Manager+) SQL Injection via 'sort' Parameter — Booking for Appointments and Events Calendar – Amelia CWE-89 6.5 Medium 2026-03-31
CVE-2026-2931 Amelia Booking <= 9.1.2 - Authenticated (Customer+) Insecure Direct Object Reference to Arbitrary User Password Change — Booking for Appointments and Events Calendar – Amelia CWE-269 8.8 High 2026-03-26
CVE-2026-24963 WordPress Amelia plugin <= 1.2.38 - Privilege Escalation vulnerability — Amelia CWE-266 7.2 High 2026-03-05
CVE-2026-24967 WordPress Amelia plugin <= 1.2.38 - Broken Access Control vulnerability — Amelia CWE-862 5.3 Medium 2026-02-03
CVE-2025-14720 Booking for Appointments and Events Calendar – Amelia <= 1.2.38 - Missing Authorization to Unauthenticated Multiple AJAX Actions — Booking for Appointments and Events Calendar – Amelia CWE-862 5.3 Medium 2026-01-09
CVE-2025-12482 Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via search — Booking for Appointments and Events Calendar – Amelia CWE-89 7.5 High 2025-11-16
CVE-2025-58213 WordPress Booking System Trafft Plugin <= 1.0.14 - Cross Site Scripting (XSS) Vulnerability — Booking System Trafft CWE-79 6.5 Medium 2025-08-27
CVE-2025-2578 Booking for Appointments and Events Calendar – Amelia <= 1.2.19 - Unauthenticated Full Path Disclosure — Booking for Appointments and Events Calendar – Amelia CWE-200 5.3 Medium 2025-03-28
CVE-2025-26965 WordPress Amelia plugin <= 1.2.16 - Insecure Direct Object References (IDOR) vulnerability — Amelia CWE-639 5.3 Medium 2025-02-25
CVE-2024-11754 Booking System Trafft <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting — Booking System Trafft CWE-79 6.4 Medium 2024-12-13
CVE-2024-6332 Booking for Appointments and Events Calendar – Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure — Booking for Appointments and Events Calendar – Amelia CWE-862 6.5 Medium 2024-09-05
CVE-2024-6552 Booking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path Disclosure — Booking for Appointments and Events Calendar – Amelia CWE-200 5.3 Medium 2024-08-08
CVE-2024-6225 Amelia <= 1.1.5 & Amelia (Pro) <= 7.5.1 - Authenticated (Admin+) Stored Cross-Site Scripting — Booking for Appointments and Events Calendar – Amelia CWE-79 4.4 Medium 2024-06-21
CVE-2024-1484 Booking for Appointments and Events Calendar – Amelia <= 1.0.98 - Reflected Cross-Site Scripting — Booking for Appointments and Events Calendar – Amelia CWE-79 6.1 Medium 2024-03-13
CVE-2023-6808 Booking for Appointments and Events Calendar – Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode — Booking for Appointments and Events Calendar – Amelia CWE-79 6.4 Medium 2024-02-05
CVE-2022-0834 Amelia <= 1.0.46 - Stored Cross Site Scripting via lastName — Booking for Appointments and Events Calendar – Amelia CWE-79 7.2 High 2022-03-23

This page lists every published CVE security advisory associated with ameliabooking. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.