Vulnerabilities (CVE)

Filtered by vendor Vikwp Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-32501 1 Vikwp 1 Vikbooking Hotel Booking Engine \& Pms 2023-11-15 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.6.1 versions.
CVE-2022-1409 1 Vikwp 1 Hotel Booking Engine \& Pms 2022-05-24 6.5 MEDIUM 7.2 HIGH
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malicious PHP code