L
Üretici güvenlik profili
latepoint
Ürün portföyü, yama kanıtları ve sömürü sinyalleri tek güvenlik karnesinde
Veriler CVE Programı, NVD, CISA KEV ve üretici güvenlik bültenlerinden birleştirilir.
Toplam CVE9
Kritik1
CISA KEV0
Public exploit0
Yama oranı%0
Ort. CVSS6.2
12 aylık açık hızı
0
0
0
0
0
0
0
0
0
1
2
6
CVE KEV
CVE önem dağılımı
9toplam CVE
Kritik1 (11%)
Yüksek2 (22%)
Orta6 (67%)
Yama ve sömürü görünümü
%0
Doğrulanmış yama
%0
CISA KEV
%0
Public exploit
0Yama var
0Kısmi
0Geçici çözüm
0Üretici: yama yok
9Bilinmiyor
Son güvenlik açıkları
7.5
CVE-2026-96662
Appointment Booking Plugin <= 5.7.2 - Unauthenticated SQL Injection via 'booking[service_id]' Parameter
L
Yama durumu bilinmiyorEPSS %0
8.8
CVE-2026-104766
Appointment Booking Plugin <= 5.7.3 - Authenticated (Custom+) Privilege Escalation to 'settings[default_wp_role_for_customer]' Parameter
L
Yama durumu bilinmiyorEPSS %0
4.3
CVE-2026-91050
Appointment Booking Plugin <= 5.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Unauthorized Booking Creation and Sensitive Information Disclosure via 'params[presets][order_item_id]' Parameter
L
Yama durumu bilinmiyorEPSS %0
5.4
CVE-2026-17538
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress <= 5.6.9 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Customer PII Modification
L
Yama durumu bilinmiyorEPSS %0
5.3
CVE-2026-94432
Appointment Booking Plugin <= 5.7.1 - Insecure Direct Object Reference to Unauthenticated Unauthorized Transaction Intent Creation/Modification and Invoice Enumeration via 'invoice_id' Parameter
L
Yama durumu bilinmiyorEPSS %0
9.1
CVE-2026-92966
Appointment Booking Plugin <= 5.7.0 - Unauthenticated Arbitrary Shortcode Execution via First/Last Name Field
L
Yama durumu bilinmiyorEPSS %0
4.3
CVE-2026-13471
LatePoint <= 5.6.3 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Booking Deletion and Customer/Booking Data Disclosure via Abilities REST API (list-bookings, list-customers, delete-booking)
L
Yama durumu bilinmiyorEPSS %0
4.3
CVE-2026-18441
LatePoint - Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Disclosure via 'customer[id]' Parameter
L
Yama durumu bilinmiyorEPSS %0
6.4
CVE-2026-5391
LatePoint <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
L
Yama durumu bilinmiyorEPSS %0