Bookingcore develops a focused booking and reservation management platform that serves as a backend component for hospitality and service-industry applications. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through web-application weakness classes including cross-site scripting, authorization bypass, cross-site request forgery, and insufficient session management, which are characteristic of platforms handling user authentication and transaction workflows. Defenders should prioritize patching this vendor's disclosures given the elevation toward critical severity; live exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bookingcore over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-37333CRITICAL Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session | Oct 4, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-25445HIGH The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the a | Jul 14, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-37330MEDIUM Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile section could be exploited to upload a malicious SVG file w | Oct 4, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-37331MEDIUM Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade License and viewing it, ID Cards a | Oct 4, 2021 | 5.3 | 19 | NO | NO |
CVE-2020-25444MEDIUM Cross Site Scripting (XSS) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 via the (1) "About Yourself” section under the “My Profile” page, " (2) “Hotel | Jul 14, 2021 | 5.4 | 19 | NO | NO |
CVE-2020-27379MEDIUM Cross Site Request Forgery (CSRF) vulnerability in Booking Core - Ultimate Booking System Booking Core 1.7.0 . The CSRF token is not being validated when the request is sent as a G | Jul 14, 2021 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bookingcore.
Media articles that mention a CVE ID that affects a product developed by Bookingcore — matched by CVE ID, not by vendor name.