Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-55816
HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.
Hoteldruid
after 3.0.7
HIGH 7.5
CVE-2025-44203
In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database …
Hoteldruid
Mitigation only
MEDIUM 6.1
CVE-2023-43378
A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injec…
Hoteldruid
No fix yet
HIGH 7.3
CVE-2025-25748
A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user p…
Hoteldruid
Mitigation only
HIGH 7.1
CVE-2025-25749
An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.
Hoteldruid
after 3.0.7
MEDIUM 5.4
CVE-2025-25747
Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information v…
Hoteldruid
No fix yet
HIGH 7.5
CVE-2024-23091
Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.
Hoteldruid
1.3.2+
MEDIUM 6.1
CVE-2023-47164
Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and earlier allows a remote unauthenticated attacker to execute an arbitrary script on the web…
Hoteldruid
after 3.0.5
CRITICAL 9.8
CVE-2023-43373
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.
Hoteldruid
No fix yet
CRITICAL 9.8
CVE-2023-43374
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php.
Hoteldruid
No fix yet
CRITICAL 9.8
CVE-2023-43375
Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giorn…
Hoteldruid
Mitigation only
MEDIUM 5.4
CVE-2023-43376
A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML …
Hoteldruid
No fix yet
MEDIUM 5.4
CVE-2023-43377
A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scr…
Hoteldruid
No fix yet
CRITICAL 9.8
CVE-2023-43371
Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php.
Hoteldruid
No fix yet
HIGH 8.8
CVE-2023-33817
hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability.
Hoteldruid
No fix yet
MEDIUM 5.4
CVE-2023-34537
A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command on affected webpage's parameter to trick use…
Hoteldruid
No fix yet
MEDIUM 5.4
CVE-2023-29839
A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands…
Hoteldruid
No fix yet
CRITICAL 9.8
CVE-2021-42949EPSS 6%
The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to by…
Hoteldruid
Mitigation only
MEDIUM 6.1
CVE-2022-26564
HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 parameter in creaprezzi.php.
Hoteldruid
No fix yet
HIGH 8.8
CVE-2022-22909EPSS 45%
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payloa…
Hoteldruid
No fix yet
MEDIUM 6.1
CVE-2021-38559
DigitalDruid HotelDruid 3.0.2 has an XSS vulnerability in prenota.php affecting the fineperiodo1 parameter.
Hoteldruid
No fix yet
CRITICAL 9.8
CVE-2021-37832
A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application database. A malicious attacker can …
Hoteldruid
No fix yet
MEDIUM 6.1
CVE-2021-37833
A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid application that allows for arbitra…
Hoteldruid
No fix yet
MEDIUM 6.5
CVE-2019-9085
Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via the n_file parameter to visuali…
Hoteldruid
2.3.1+
CRITICAL 9.8
CVE-2019-9087
HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter.
Hoteldruid
2.3.1+
CRITICAL 9.8
CVE-2019-9086
HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter.
Hoteldruid
2.3.1+
MEDIUM 6.1
CVE-2019-8937EPSS 11%
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabella3.php, personalizza.php, an…
Hoteldruid
No fix yet
CRITICAL 9.8
CVE-2018-1000871
HotelDruid HotelDruid 2.3.0 version 2.3.0 and earlier contains a SQL Injection vulnerability in "id_utente_mod" parameter in gestione_utenti.php file…
Hoteldruid
after 2.3.0