bookingcore records
6 published records for vendor bookingcore.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-613 Insufficient Session Expiration1
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-37333No exploit | Laravel Booking System Booking Core 2.0 is vulnerable to Session Management.bookingcore · booking core · CWE-613 | Critical9.8 | — | 1.5% | Oct 4, 2021 |
31Monitor | CVE-2020-25445No exploit | The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection.bookingcore · booking core · CWE-1236 | High7.8 | — | 0.9% | Jul 14, 2021 |
26Monitor | CVE-2020-27379No exploit | Cross Site Request Forgery (CSRF) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 .bookingcore · booking core · CWE-352 | Medium6.5 | — | 0.5% | Jul 14, 2021 |
21Monitor | CVE-2021-37331No exploit | Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control.bookingcore · booking core · CWE-639 | Medium5.3 | — | 1.0% | Oct 4, 2021 |
21Monitor | CVE-2020-25444No exploit | Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About Yourself” section ubookingcore · booking core · CWE-79 | Medium5.4 | — | 0.6% | Jul 14, 2021 |
21Monitor | CVE-2021-37330No exploit | Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS).bookingcore · booking core · CWE-79 | Medium5.4 | — | 0.6% | Oct 4, 2021 |
- CVE-2021-3733339Monitor
Laravel Booking System Booking Core 2.0 is vulnerable to Session Management.
CriticalCVSS 9.8No exploitEPSS 1%bookingcore · booking coreOct 4, 2021
- CVE-2020-2544531Monitor
The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection.
HighCVSS 7.8No exploitEPSS 1%bookingcore · booking coreJul 14, 2021
- CVE-2020-2737926Monitor
Cross Site Request Forgery (CSRF) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 .
MediumCVSS 6.5No exploitEPSS 0%bookingcore · booking coreJul 14, 2021
- CVE-2021-3733121Monitor
Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control.
MediumCVSS 5.3No exploitEPSS 1%bookingcore · booking coreOct 4, 2021
- CVE-2020-2544421Monitor
Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About Yourself” section u
MediumCVSS 5.4No exploitEPSS 1%bookingcore · booking coreJul 14, 2021
- CVE-2021-3733021Monitor
Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS).
MediumCVSS 5.4No exploitEPSS 1%bookingcore · booking coreOct 4, 2021