VYPR

Salon Booking System

by WordPress

Source repositories

CVEs (36)

  • CVE-2024-30510CriMar 29, 2024
    risk 0.65cvss 10.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5.

  • CVE-2026-66453CriAug 13, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.

  • CVE-2024-3229CriJun 19, 2024
    risk 0.57cvss 9.8epss 0.01

    The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_ImportAssistants function along with missing authorization checks in all versions up to, and including, 10.2. This makes it possible…

  • CVE-2024-37231HigJun 24, 2024
    risk 0.56cvss 8.6epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salon Booking System Salon booking system allows File Manipulation.This issue affects Salon booking system: from n/a through 9.9.

  • CVE-2024-4442CriMay 21, 2024
    risk 0.52cvss 9.1epss 0.01

    The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 9.8. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated…

  • CVE-2026-17022HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal…

  • CVE-2026-42666HigJun 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.

  • CVE-2024-39658HigAug 29, 2024
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salon Booking System Salon booking system allows SQL Injection.This issue affects Salon booking system: from n/a through 10.7.

  • CVE-2022-0920HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data

  • CVE-2026-40768HigJun 17, 2026
    risk 0.47cvss 7.3epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.

  • CVE-2025-31560HigApr 1, 2025
    risk 0.47cvss 7.2epss 0.01

    Incorrect Privilege Assignment vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Privilege Escalation.This issue affects Salon booking system: from n/a through < 10.15.

  • CVE-2023-48319MedMay 17, 2024
    risk 0.44cvss 6.8epss 0.01

    Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6.

  • CVE-2026-6320HigMay 2, 2026
    risk 0.42cvss 7.5epss 0.00

    The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using those stored values as trusted…

  • CVE-2025-67954MedJan 22, 2026
    risk 0.42cvss 6.5epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Retrieve Embedded Sensitive Data.This issue affects Salon booking system: from n/a through <= 10.30.3.

  • CVE-2024-2603MedApr 26, 2024
    risk 0.41cvss 6.3epss 0.00

    The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site…

  • CVE-2022-43487MedDec 5, 2022
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Salon booking system versions prior to 7.9 allows a remote unauthenticated attacker to inject an arbitrary script.

  • CVE-2021-24429MedJul 12, 2021
    risk 0.40cvss 6.1epss 0.01

    The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability.…

  • CVE-2024-2101MedApr 17, 2024
    risk 0.37cvss 5.7epss 0.01

    The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers'…

  • CVE-2025-47583MedMay 19, 2025
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.16.

  • CVE-2025-32220MedApr 4, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through <= 10.30.23.

Page 1 of 2