📦 Salon Booking System

by Salonbookingsystem

🔍 What is Salon Booking System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-3229

CRITICAL CVSS 9.8 Jun 19, 2024

This vulnerability allows unauthenticated attackers to upload arbitrary files to WordPress sites using the Salon booking system plugin. It affects all versions up to 10.2 due to missing file type vali...

CVE-2024-4442

CRITICAL CVSS 9.1 May 21, 2024

This vulnerability allows unauthenticated attackers to delete arbitrary files on WordPress sites using the Salon booking system plugin. Attackers can delete critical files like wp-config.php, potentia...

CVE-2022-0920

HIGH CVSS 7.5 Apr 11, 2022

The Salon booking system WordPress plugins (Free and Pro) before version 7.6.3 have improper authorization in some API endpoints. This allows customers to access all bookings and other customers' pers...

CVE-2025-32220

MEDIUM CVSS 5.4 Apr 4, 2025

A missing authorization vulnerability in the Dimitri Grassi Salon booking system WordPress plugin allows attackers to bypass access controls and perform unauthorized actions. This affects all versions...

CVE-2024-4468

MEDIUM CVSS 4.3 Jun 8, 2024

The Salon booking system WordPress plugin has an authorization bypass vulnerability that allows authenticated users with subscriber-level access or higher to modify plugin settings and view other user...

CVE-2023-48319

MEDIUM CVSS 6.8 May 17, 2024

This vulnerability allows attackers with editor-level access in WordPress to escalate their privileges to administrator level in the Salon Booking System plugin. It affects all WordPress sites running...