Show filters
182 Total Results
Displaying 111-120 of 182
Sort by:
Attacker Value
Unknown

CVE-2022-29987

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/admin/?page=user/manage_user&id=.
Attacker Value
Unknown

CVE-2022-29986

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_facility.
Attacker Value
Unknown

CVE-2022-29985

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via \scbs\classes\Master.php?f=delete_category.
Attacker Value
Unknown

CVE-2022-29317

Disclosure Date: May 11, 2022 (last updated February 23, 2025)
Simple Bus Ticket Booking System v1.0 was discovered to contain multiple SQL injection vulnerbilities via the username and password parameters at /assets/partials/_handleLogin.php.
Attacker Value
Unknown

CVE-2022-1463

Disclosure Date: May 10, 2022 (last updated February 23, 2025)
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.
Attacker Value
Unknown

CVE-2022-28094

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the fid parameter at booking.php.
Attacker Value
Unknown

CVE-2022-28093

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2021-36847

Disclosure Date: April 15, 2022 (last updated February 24, 2025)
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebbaPlugins Webba Booking plugin <= 4.2.21 at WordPress.
Attacker Value
Unknown

CVE-2022-0920

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data
Attacker Value
Unknown

CVE-2022-0919

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching bookings, allowing any unauthenticated users to search other's booking, as well as retrieve sensitive information about the bookings, such as the full name, email and phone number of the person who booked it.