Vulnerabilidades en ladela
12 resultadosAnálisis Vexday
Ladela apresenta footprint modesto de 5 CVEs sem exploração ativa registrada, reduzindo pressão operacional imediata. A vulnerabilidade dominante é CWE-79 (injeção), típica de aplicações web, com 1 divulgação recente nos últimos 90 dias indicando atividade contínua de descoberta. Ausência de críticas CVSS sugere risco contido, mas vigilância em patches recentes permanece recomendada.
CVE-2026-89063HIGHOnline Scheduling and Appointment Booking System <= 28.1 - Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' ParameterEPSS 1.6%CVE-2026-13424HIGHOnline Scheduling and Appointment Booking System <= 27.7 - Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX actionEPSS 0.6%CVE-2026-14516HIGHOnline Scheduling and Appointment Booking System <= 27.5 - Unauthenticated SQL InjectionEPSS 0.5%CVE-2023-1172HIGHThe Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 EPSS 0.5%CVE-2026-2519MEDIUMOnline Scheduling and Appointment Booking System – Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips'EPSS 0.5%CVE-2026-12905MEDIUMOnline Scheduling and Appointment Booking System – Bookly <= 27.7 - Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' ParameterEPSS 0.4%CVE-2023-1159MEDIUMThe Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due tEPSS 0.4%CVE-2026-5513HIGHOnline Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' CookieEPSS 0.3%CVE-2024-5584MEDIUMWordPress Online Booking and Scheduling Plugin – Bookly <= 23.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Color Profile ParameterEPSS 0.3%CVE-2026-2520MEDIUMOnline Scheduling and Appointment Booking System – Bookly <= 27.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin UpdateEPSS 0.2%CVE-2026-92799MEDIUMOnline Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_dataEPSS —CVE-2026-93399CRITICALOnline Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' ParameterEPSS —