VendorsSalon Booking Systemsalon_booking_systemany version
Vulnerabilities

Salon Booking System Salon Booking System any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2024-30510
WordPress Salon booking system plugin <= 9.5 - Arbitrary File Upload vulnerability
Published 2024-03-29 · Modified
10.0EPSS 0.007
CVE-2024-3229
Salon Booking System <= 10.2 - Unauthenticated Arbitrary File Upload
Published 2024-06-19 · Modified
9.8EPSS 0.009
CVE-2024-4442
Salon booking system <= 9.9 - Unauthenticated Arbitrary File Deletion
Published 2024-05-21 · Modified
9.1EPSS 0.012
CVE-2024-37231
WordPress Salon booking system plugin <= 9.9 - Arbitrary File Deletion vulnerability
Published 2024-06-24 · Analyzed
9.1EPSS 0.006
CVE-2025-32220
WordPress Salon booking system plugin <= 10.30.23 - Broken Access Control vulnerability
Published 2025-04-04 · Modified
8.8EPSS 0.005
CVE-2024-47316
WordPress Salon Booking Wordpress Plugin plugin <= 10.9 - Insecure Direct Object References (IDOR) vulnerability
Published 2024-10-05 · Modified
8.8EPSS 0.003
CVE-2024-39658
WordPress Salon Booking System plugin <= 10.7 - Authenticated SQL Injection vulnerability
Published 2024-08-29 · Analyzed
7.6EPSS 0.004
CVE-2022-0920
Salon booking system < 7.6.3 - Customer+ Bookings/Customers Data Disclosure
Published 2022-04-11 · Modified
7.5EPSS 0.015
CVE-2025-31560
WordPress Salon booking system plugin < 10.15 - Privilege Escalation vulnerability
Published 2025-04-01 · Modified
7.2EPSS 0.006
CVE-2023-48319
WordPress Salon booking system plugin < 8.7 - Editor+ Privilege Escalation vulnerability
Published 2024-05-17 · Analyzed
7.2EPSS 0.005
CVE-2024-2603
Salon booking system <= 9.6.5 - Editor+ Stored XSS via Email Settings
Published 2024-04-26 · Analyzed
6.3EPSS 0.005
CVE-2021-24429
Salon Booking System < 6.3.1 - Unauthenticated Stored Cross-Site Scripting (XSS)
Published 2021-07-12 · Modified
6.1EPSS 0.012
CVE-2022-43487
Cross-site scripting vulnerability in Salon booking system versions prior to 7.9 allows a remote unauthenticated attacker to inject an arbitrary script.
Published 2022-12-05 · Modified
6.1EPSS 0.008
CVE-2024-43280
WordPress Salon Booking System plugin <= 10.8.1 - Open Redirection vulnerability
Published 2024-08-19 · Analyzed
6.1EPSS 0.003
CVE-2024-2101
WordPress Plugin Salon Booking System < 9.6.3 - Unauthenticated Stored Cross-Site Scripting (XSS)
Published 2024-04-17 · Analyzed
5.7EPSS 0.006
CVE-2024-4468
Salon booking system <= 9.9 - Missing Authorization
Published 2024-06-08 · Modified
5.4EPSS 0.004
CVE-2023-3427
Salon Booking System <= 8.4.6 - Cross-Site Request Forgery to Admin Role Change to Customer, User Meta Update via save_customer
Published 2023-06-28 · Modified
5.4EPSS 0.003
CVE-2022-0919
Salon booking system < 7.6.3 - Unauthenticated Sensitive Data Disclosure
Published 2022-04-11 · Modified
5.3EPSS 0.012
CVE-2024-2439
Salon booking system <= 9.6.5 - Editor+ Stored XSS
Published 2024-04-26 · Analyzed
4.8EPSS 0.004
CVE-2024-9882
Salon Booking System < 10.9.4 - Admin+ Stored XSS
Published 2025-05-15 · Analyzed
4.8EPSS 0.003
CVE-2024-2102
Salon booking system < 9.6.3 - Unauthenticated Stored XSS
Published 2024-04-17 · Analyzed
4.7EPSS 0.005
CVE-2024-2429
Salon booking system <= 9.6.5 - Settings Update via CSRF
Published 2024-04-26 · Analyzed
4.3EPSS 0.002