Saasproject operates a booking package application oriented toward web-facing customer interactions, with the durable signal centered on application-layer input-handling and data-exposure issues, principally cross-site scripting and sensitive-information disclosure. Treat this as a compact vendor profile rather than a broad trend line; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Saasproject over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40774HIGH Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions. | Jun 15, 2026 | 7.5 | 26 | NO | NO |
CVE-2024-30516HIGH Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects B | Jan 5, 2026 | 7.5 | 24 | NO | NO |
CVE-2021-20840MEDIUM Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions prior to 1.5.11 allows a remote attacker to inject an arbitrary script via unsp | Nov 24, 2021 | 6.1 | 22 | NO | NO |
CVE-2023-39918MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SAASPROJECT Booking Package Booking Package plugin <= 1.6.01 versions. | Sep 4, 2023 | 6.1 | 19 | NO | NO |
CVE-2022-0709HIGH The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response | Apr 4, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Saasproject.
Media articles that mention a CVE ID that affects a product developed by Saasproject — matched by CVE ID, not by vendor name.