Salonbookingsystem develops a focused web-based booking platform for salon and service-industry operations that, despite a narrow product scope, has accumulated a substantial vulnerability history reflecting the challenges of building secure web applications. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and center on application-layer deficiencies: cross-site scripting, missing authorization controls, cross-site request forgery, and path-traversal issues that are characteristic of web-input handling and access-control shortcomings in customer-facing applications. These weakness classes recur across the vendor's booking system and represent durable structural risks in how user input is validated, how access permissions are enforced, and how file resources are restricted. Defenders operating or supporting salon and service businesses using this platform should prioritize patching and assess whether the application sits in scope for customer data handling; current severity, exploitation activity, and advisory counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Salonbookingsystem over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3229CRITICAL The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_ImportAssistants function along wit | Jun 19, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-4442CRITICAL The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 9.8. This is due to the plugin not properly validating | May 21, 2024 | 9.1 | 29 | NO | NO |
CVE-2024-37231CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salon Booking System Salon booking system allows File Manipulation.This issue affect | Jun 24, 2024 | 9.1 | 25 | NO | NO |
CVE-2024-30510CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5. | Mar 29, 2024 | 9.8 | 25 | NO | NO |
CVE-2022-0920HIGH The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings a | Apr 11, 2022 | 7.5 | 25 | NO | NO |
CVE-2024-47316HIGH Authorization Bypass Through User-Controlled Key vulnerability in Dimitri Grassi Salon booking system salon-booking-system.This issue affects Salon booking system: from n/a through | Oct 5, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-32220HIGH Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a | Apr 4, 2025 | 8.8 | 23 | NO | NO |
CVE-2023-48319HIGH Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6. | May 17, 2024 | 7.2 | 22 | NO | NO |
CVE-2022-43487MEDIUM Cross-site scripting vulnerability in Salon booking system versions prior to 7.9 allows a remote unauthenticated attacker to inject an arbitrary script. | Dec 5, 2022 | 6.1 | 22 | NO | NO |
CVE-2025-31560HIGH Incorrect Privilege Assignment vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Privilege Escalation.This issue affects Salon booking system: from n | Apr 1, 2025 | 7.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Salonbookingsystem.
Media articles that mention a CVE ID that affects a product developed by Salonbookingsystem — matched by CVE ID, not by vendor name.