Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High1
Medium0
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2026-08-10

CVE-2026-17022 - Through 10 Plugin

The Salon Booking System WordPress plugin through 10.30.33 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal information, by supplying a sequential booking identifier.

PLUGIN Through 10

CVE-2026-17022

HIGH CVSS 7.5 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-17023 - Through 10 Plugin

The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the site's stored Google Calendar connection tokens with attacker-controlled ones and hijack the integration. Exploitation requires the site to have configured its own Google OAuth client for the calendar feature.

PLUGIN Through 10

CVE-2026-17023

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-17021 - Through 10 Plugin

The Salon Booking System WordPress plugin through 10.30.33 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary bookings.

PLUGIN Through 10

CVE-2026-17021

UNKNOWN CVSS 0.0 2026-08-10
Threat Entry Updated 2026-08-10

CVE-2026-17020 - Through 10 Plugin

The Salon Booking System WordPress plugin through 10.30.33 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer account) to disclose any customer's booking personal data such as name, email, phone number, address and private notes by enumerating booking identifiers.

PLUGIN Through 10

CVE-2026-17020

UNKNOWN CVSS 0.0 2026-08-10
Scroll to top