Known Vulnerabilities for products from Digitaldruid
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Digitaldruid".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-44203 json | In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is complete... | Not Provided | 2025-06-20 | 2026-07-09 |
| CVE-2023-47164 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2023-11-10 | 2023-11-16 |
| CVE-2023-43377 json | A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to e... | 5.4 - MEDIUM | 2023-09-20 | 2023-09-21 |
| CVE-2023-43376 json | A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitr... | 5.4 - MEDIUM | 2023-09-20 | 2023-09-28 |
| CVE-2023-43375 json | Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonas... | 9.8 - CRITICAL | 2023-09-20 | 2023-09-21 |
| CVE-2023-43374 json | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/pers... | 9.8 - CRITICAL | 2023-09-20 | 2023-09-21 |
| CVE-2023-43373 json | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/inter... | 9.8 - CRITICAL | 2023-09-20 | 2023-09-21 |
| CVE-2023-43371 json | Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creapre... | 9.8 - CRITICAL | 2023-09-20 | 2023-09-21 |
| CVE-2023-34537 json | A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage'... | 5.4 - MEDIUM | 2023-06-13 | 2023-06-20 |
| CVE-2023-33817 json | hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability. | 8.8 - HIGH | 2023-06-13 | 2023-06-17 |
| CVE-2023-29839 json | A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitra... | 5.4 - MEDIUM | 2023-05-03 | 2023-05-09 |
| CVE-2022-26564 json | HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parame... | 6.1 - MEDIUM | 2022-04-26 | 2022-05-04 |
| CVE-2022-22909 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2022-03-03 | 2022-03-09 |
| CVE-2021-42949 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2022-09-16 | 2023-08-08 |
| CVE-2021-42948 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 3.7 - LOW | 2022-09-16 | 2022-09-17 |
| CVE-2021-38559 json | DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter. | 6.1 - MEDIUM | 2021-08-26 | 2021-08-27 |
| CVE-2021-37833 json | A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application... | 6.1 - MEDIUM | 2021-08-03 | 2021-08-11 |
| CVE-2021-37832 json | A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A... | 9.8 - CRITICAL | 2021-08-03 | 2021-08-11 |
| CVE-2019-9087 json | HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter. | 9.8 - CRITICAL | 2019-06-07 | 2019-07-01 |
| CVE-2019-9086 json | HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter. | 9.8 - CRITICAL | 2019-06-07 | 2019-07-01 |
Known software with vulnerabilities from Digitaldruid
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Digitaldruid | Hoteldruid | 1.3.2 |