Known Vulnerabilities for Hoteldruid by Digitaldruid
Listed below are 10 of the newest known vulnerabilities associated with "Hoteldruid" by "Digitaldruid".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-44203 json | In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is complete... | Not Provided | 2025-06-20 | 2026-07-09 |
| CVE-2023-47164 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2023-11-10 | 2023-11-16 |
| CVE-2023-43377 json | A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to e... | 5.4 - MEDIUM | 2023-09-20 | 2023-09-21 |
| CVE-2023-43376 json | A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitr... | 5.4 - MEDIUM | 2023-09-20 | 2023-09-28 |
| CVE-2023-43375 json | Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonas... | 9.8 - CRITICAL | 2023-09-20 | 2023-09-21 |
| CVE-2023-43374 json | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/pers... | 9.8 - CRITICAL | 2023-09-20 | 2023-09-21 |
| CVE-2023-43373 json | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/inter... | 9.8 - CRITICAL | 2023-09-20 | 2023-09-21 |
| CVE-2023-43371 json | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creapre... | 9.8 - CRITICAL | 2023-09-20 | 2023-09-21 |
| CVE-2023-34537 json | A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage'... | 5.4 - MEDIUM | 2023-06-13 | 2023-06-20 |
| CVE-2023-33817 json | hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability. | 8.8 - HIGH | 2023-06-13 | 2023-06-17 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Digitaldruid | Hoteldruid | 2.3.2 | |||
| Application | Digitaldruid | Hoteldruid | 2.3.1 | |||
| Application | Digitaldruid | Hoteldruid | 2.3 | |||
| Application | Digitaldruid | Hoteldruid | 2.2.4 | |||
| Application | Digitaldruid | Hoteldruid | 2.2.3 | |||
| Application | Digitaldruid | Hoteldruid | 2.2.2 | |||
| Application | Digitaldruid | Hoteldruid | 2.2.1 | |||
| Application | Digitaldruid | Hoteldruid | 2.2 | |||
| Application | Digitaldruid | Hoteldruid | 2.1.4 | |||
| Application | Digitaldruid | Hoteldruid | 2.1.3 | |||
| Application | Digitaldruid | Hoteldruid | 2.1.2 | |||
| Application | Digitaldruid | Hoteldruid | 2.1.1 | |||
| Application | Digitaldruid | Hoteldruid | 2.1 | |||
| Application | Digitaldruid | Hoteldruid | 2.0.3 | |||
| Application | Digitaldruid | Hoteldruid | 2.0.2 | |||
| Application | Digitaldruid | Hoteldruid | 2.0.1 | |||
| Application | Digitaldruid | Hoteldruid | 2.0.0 | |||
| Application | Digitaldruid | Hoteldruid | 1.3.2 |