Known Vulnerabilities for Kea-hotel-erp by Kea-hotel-erp Project
Listed below are 1 of the newest known vulnerabilities associated with "Kea-hotel-erp" by "Kea-hotel-erp Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-57723 json | Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. Thi... | Not Provided | 2026-07-01 | 2026-07-01 |
| CVE-2026-57347 json | Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions. | Not Provided | 2026-07-02 | 2026-07-02 |
| CVE-2026-54419 json | claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c1042... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-42762 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hot... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-42737 json | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Boo... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-42683 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hot... | Not Provided | 2026-06-01 | 2026-06-01 |
| CVE-2026-39539 json | Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions. | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-15494 json | A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/netwo... | Not Provided | 2026-07-12 | 2026-07-13 |
| CVE-2026-15094 json | The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter i... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-14764 json | A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the fi... | Not Provided | 2026-07-05 | 2026-07-06 |