Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Salonbookingsystem

First CVE: Jul 12, 2021Active for: 5 yearsTotal CVEs: 22
24.9
VTI Score
Low

Salonbookingsystem develops a focused web-based booking platform for salon and service-industry operations that, despite a narrow product scope, has accumulated a substantial vulnerability history reflecting the challenges of building secure web applications. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and center on application-layer deficiencies: cross-site scripting, missing authorization controls, cross-site request forgery, and path-traversal issues that are characteristic of web-input handling and access-control shortcomings in customer-facing applications. These weakness classes recur across the vendor's booking system and represent durable structural risks in how user input is validated, how access permissions are enforced, and how file resources are restricted. Defenders operating or supporting salon and service businesses using this platform should prioritize patching and assess whether the application sits in scope for customer data handling; current severity, exploitation activity, and advisory counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
4.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Salonbookingsystem over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 12, 2021
5 years ago
Most Recent CVE
May 15, 2025
439 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-3229CRITICAL
The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SLN_Action_Ajax_ImportAssistants function along wit
Jun 19, 20249.829NONO
CVE-2024-4442CRITICAL
The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 9.8. This is due to the plugin not properly validating
May 21, 20249.129NONO
CVE-2024-37231CRITICAL
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salon Booking System Salon booking system allows File Manipulation.This issue affect
Jun 24, 20249.125NONO
CVE-2024-30510CRITICAL
Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5.
Mar 29, 20249.825NONO
CVE-2022-0920HIGH
The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings a
Apr 11, 20227.525NONO
CVE-2024-47316HIGH
Authorization Bypass Through User-Controlled Key vulnerability in Dimitri Grassi Salon booking system salon-booking-system.This issue affects Salon booking system: from n/a through
Oct 5, 20248.824NONO
CVE-2025-32220HIGH
Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue a
Apr 4, 20258.823NONO
CVE-2023-48319HIGH
Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6.
May 17, 20247.222NONO
CVE-2022-43487MEDIUM
Cross-site scripting vulnerability in Salon booking system versions prior to 7.9 allows a remote unauthenticated attacker to inject an arbitrary script.
Dec 5, 20226.122NONO
CVE-2025-31560HIGH
Incorrect Privilege Assignment vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Privilege Escalation.This issue affects Salon booking system: from n
Apr 1, 20257.221NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
55%
27%
18%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (54.5%)
Unknown0 (0.0%)
Required10 (45.5%)
Privileges Required
Low4 (18.2%)
High5 (22.7%)
None13 (59.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Salonbookingsystem.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Salonbookingsystem — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Salonbookingsystem's Products

View all 4 CNAs →

Top CWEs