Extension WordPress

Vulnérabilités Salon Booking System – Free Version

Cette page rassemble les failles publiées pour Salon Booking System – Free Version, leurs plages de versions affectées et les correctifs signalés dans la base locale.

31Vulnérabilités
4Critiques
30Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Salon Booking System – Free Version

31 fiches

CVE-2026-15070 Élevée · 8,8
Salon Booking System – Free Version

Salon Booking System <= 10.30.32 – Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.32. This is due to missing or incorrect nonce validation on the setCustomText function. This…

Versions affectées

*-10.30.32

Correctif

10.30.33

Publication

09/07/2026

CVE-2026-6320 Élevée · 7,5
Salon Booking System – Free Version

Salon Booking System – Free Version <= 10.30.25 – Unauthenticated Arbitrary File Read via Booking File Field Path Traversal

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using…

Versions affectées

*-10.30.25

Correctif

10.30.26

Publication

01/05/2026

CVE-2026-40768 Moyenne · 5,3
Salon Booking System – Free Version

Salon Booking System – Free Version <= 10.30.24 – Unauthenticated Insecure Direct Object Reference

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 10.30.24 due to missing validation on a user controlled key. This makes it possible…

Versions affectées

*-10.30.24

Correctif

10.30.25

Publication

21/04/2026

CVE-2025-67954 Faible · 3,1
Salon Booking System – Free Version

Salon booking system <= 10.30.3 – Authenticated (Subscriber+) Information Exposure

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.30.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract…

Versions affectées

*-10.30.3

Correctif

10.30.4

Publication

21/01/2026

CVE-2025-8492 Moyenne · 5,3
Salon Booking System – Free Version

Salon Booking System <= 10.22 – Missing Authorization to Unauthenticated AJAX Actions Execution

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax function in all versions up to, and…

Versions affectées

*-10.22

Correctif

10.24

Publication

10/09/2025

CVE-2025-47583 Moyenne · 4,3
Salon Booking System – Free Version

Salon booking system <= 10.16 – Cross-Site Request Forgery to Arbitrary Post/Page Deletion

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.16. This is due to missing or incorrect nonce validation…

Versions affectées

*-10.16

Correctif

10.17

Publication

15/05/2025

CVE-2025-31560 Élevée · 8,8
Salon Booking System – Free Version

Salon booking system <= 10.11 – Authenticated Privilege Escalation

The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.11. This makes it possible for authenticated attackers, with Custom-level access…

Versions affectées

*-10.11

Correctif

10.15

Publication

01/04/2025

CVE-2024-47316 Moyenne · 4,3
Salon Booking System – Free Version

Salon booking system <= 10.9 – Authenticated (Subscriber+) Insecure Direct Object Reference

The Salon Booking System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 10.9 due to missing validation on a user controlled key. This makes it possible for authenticated attackers,…

Versions affectées

*-10.9

Correctif

10.9.1

Publication

25/09/2024

CVE-2024-9882 Moyenne · 4,4
Salon Booking System – Free Version

Salon Booking System <= 10.9.3 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Salon Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-10.9.3

Correctif

10.9.4

Publication

13/09/2024

CVE-2024-3229 Critique · 9,8
Salon Booking System – Free Version

Salon Booking System <= 10.2 – Unauthenticated Arbitrary File Upload

The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_ImportAssistants function along with missing authorization checks in all versions up to, and including, 10.2. This makes…

Versions affectées

*-10.2

Correctif

10.3

Publication

18/06/2024

CVE-2024-2439 Moyenne · 4,4
Salon Booking System – Free Version

Salon booking system <= 9.6.5 – Authenticated (Editor+) Stored Cross-Site Scripting

The Salon booking system plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 9.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-9.6.5

Correctif

9.6.6

Publication

05/04/2024

CVE-2024-2603 Moyenne · 4,4
Salon Booking System – Free Version

Salon booking system <= 9.6.5 – Authenticated (Editor+) Stored Cross-Site Scripting via Email Settings

The Salon booking system plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email settings in all versions up to, and including, 9.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-9.6.5

Correctif

9.6.6

Publication

05/04/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités