Salon Booking System
by WordPress
Source repositories
CVEs (36)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-30510 | Cri | 0.65 | 10.0 | 0.01 | Mar 29, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5. | ||
| CVE-2026-66453 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2026 | Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. | ||
| CVE-2024-3229 | Cri | 0.57 | 9.8 | 0.01 | Jun 19, 2024 | The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_ImportAssistants function along with missing authorization checks in all versions up to, and including, 10.2. This makes it possible… | ||
| CVE-2024-37231 | Hig | 0.56 | 8.6 | 0.01 | Jun 24, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salon Booking System Salon booking system allows File Manipulation.This issue affects Salon booking system: from n/a through 9.9. | ||
| CVE-2024-4442 | Cri | 0.52 | 9.1 | 0.01 | May 21, 2024 | The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 9.8. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated… | ||
| CVE-2026-17022 | Hig | 0.49 | 7.5 | 0.00 | Aug 10, 2026 | The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal… | ||
| CVE-2026-42666 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2026 | Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions. | ||
| CVE-2024-39658 | Hig | 0.49 | 7.6 | 0.00 | Aug 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salon Booking System Salon booking system allows SQL Injection.This issue affects Salon booking system: from n/a through 10.7. | ||
| CVE-2022-0920 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data | ||
| CVE-2026-40768 | Hig | 0.47 | 7.3 | 0.00 | Jun 17, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions. | ||
| CVE-2025-31560 | Hig | 0.47 | 7.2 | 0.01 | Apr 1, 2025 | Incorrect Privilege Assignment vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Privilege Escalation.This issue affects Salon booking system: from n/a through < 10.15. | ||
| CVE-2023-48319 | Med | 0.44 | 6.8 | 0.01 | May 17, 2024 | Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6. | ||
| CVE-2026-6320 | Hig | 0.42 | 7.5 | 0.00 | May 2, 2026 | The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using those stored values as trusted… | ||
| CVE-2025-67954 | Med | 0.42 | 6.5 | 0.00 | Jan 22, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Retrieve Embedded Sensitive Data.This issue affects Salon booking system: from n/a through <= 10.30.3. | ||
| CVE-2024-2603 | Med | 0.41 | 6.3 | 0.00 | Apr 26, 2024 | The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site… | ||
| CVE-2022-43487 | Med | 0.40 | 6.1 | 0.01 | Dec 5, 2022 | Cross-site scripting vulnerability in Salon booking system versions prior to 7.9 allows a remote unauthenticated attacker to inject an arbitrary script. | ||
| CVE-2021-24429 | Med | 0.40 | 6.1 | 0.01 | Jul 12, 2021 | The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability.… | ||
| CVE-2024-2101 | Med | 0.37 | 5.7 | 0.01 | Apr 17, 2024 | The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers'… | ||
| CVE-2025-47583 | Med | 0.35 | 5.4 | 0.00 | May 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.16. | ||
| CVE-2025-32220 | Med | 0.35 | 5.4 | 0.00 | Apr 4, 2025 | Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through <= 10.30.23. |
- risk 0.65cvss 10.0epss 0.01
Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
- risk 0.57cvss 9.8epss 0.01
The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_ImportAssistants function along with missing authorization checks in all versions up to, and including, 10.2. This makes it possible…
- risk 0.56cvss 8.6epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salon Booking System Salon booking system allows File Manipulation.This issue affects Salon booking system: from n/a through 9.9.
- risk 0.52cvss 9.1epss 0.01
The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 9.8. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated…
- risk 0.49cvss 7.5epss 0.00
The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal…
- risk 0.49cvss 7.5epss 0.00
Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.
- risk 0.49cvss 7.6epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salon Booking System Salon booking system allows SQL Injection.This issue affects Salon booking system: from n/a through 10.7.
- risk 0.49cvss 7.5epss 0.01
The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data
- risk 0.47cvss 7.3epss 0.00
Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.
- risk 0.47cvss 7.2epss 0.01
Incorrect Privilege Assignment vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Privilege Escalation.This issue affects Salon booking system: from n/a through < 10.15.
- risk 0.44cvss 6.8epss 0.01
Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6.
- risk 0.42cvss 7.5epss 0.00
The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 10.30.25. This is due to the public booking flow accepting attacker-controlled file-field values and later using those stored values as trusted…
- risk 0.42cvss 6.5epss 0.00
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Retrieve Embedded Sensitive Data.This issue affects Salon booking system: from n/a through <= 10.30.3.
- risk 0.41cvss 6.3epss 0.00
The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin (or editor depending on Salon booking system WordPress plugin through 9.6.5 configuration) to perform Stored Cross-Site…
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting vulnerability in Salon booking system versions prior to 7.9 allows a remote unauthenticated attacker to inject an arbitrary script.
- risk 0.40cvss 6.1epss 0.01
The Salon booking system WordPress plugin before 6.3.1 does not properly sanitise and escape the First Name field when booking an appointment, allowing low privilege users such as subscriber to set JavaScript in them, leading to a Stored Cross-Site Scripting (XSS) vulnerability.…
- risk 0.37cvss 5.7epss 0.01
The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers'…
- risk 0.35cvss 5.4epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.16.
- risk 0.35cvss 5.4epss 0.00
Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through <= 10.30.23.
Page 1 of 2