{"schema_version":1,"title":"E4jvikwp VikBooking Hotel Booking Engine & PMS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in E4jvikwp VikBooking Hotel Booking Engine & PMS: 0 in the last 7 days and 6 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-15401, was published on 24 July 2026.","url":"https://junglewise.ai/threats/technologies/vikbooking-hotel-booking-engine-pms","json_url":"https://junglewise.ai/threats/technologies/vikbooking-hotel-booking-engine-pms.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/vikbooking-hotel-booking-engine-pms","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":7,"all_time":9,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":6,"last_365_days":9},"latest":[{"cve":"CVE-2026-15401","cvss":7.2,"slug":"cve-2026-15401-vikbooking-hotel-booking-engine-pms-stored-xss-in-vbfx-parameter","title":"VikBooking Hotel Booking Engine & PMS Stored XSS in vbfX parameter","severity":"high","exploited":false,"published_at":"2026-07-24T10:16:31.41+00:00","url":"https://junglewise.ai/threats/cve-2026-15401-vikbooking-hotel-booking-engine-pms-stored-xss-in-vbfx-parameter"},{"cve":"CVE-2026-15346","cvss":6.1,"slug":"cve-2026-15346-e4jvikwp-vikbooking-hotel-booking-engine-pms-reflected-xss","title":"e4jvikwp VikBooking Hotel Booking Engine & PMS Reflected XSS","severity":"medium","exploited":false,"published_at":"2026-07-24T09:16:23.953+00:00","url":"https://junglewise.ai/threats/cve-2026-15346-e4jvikwp-vikbooking-hotel-booking-engine-pms-reflected-xss"},{"cve":"CVE-2026-6820","cvss":7.2,"slug":"cve-2026-6820-vikbooking-hotel-booking-engine-pms-stored-xss-in-email-parameter","title":"VikBooking Hotel Booking Engine & PMS Stored XSS in email parameter","severity":"high","exploited":false,"published_at":"2026-07-08T13:16:57.78+00:00","url":"https://junglewise.ai/threats/cve-2026-6820-vikbooking-hotel-booking-engine-pms-stored-xss-in-email-parameter"},{"cve":"CVE-2026-6818","cvss":7.2,"slug":"cve-2026-6818-vikbooking-hotel-booking-engine-pms-stored-xss-in-special-requests","title":"VikBooking Hotel Booking Engine & PMS Stored XSS in special_requests","severity":"high","exploited":false,"published_at":"2026-07-08T12:17:21.017+00:00","url":"https://junglewise.ai/threats/cve-2026-6818-vikbooking-hotel-booking-engine-pms-stored-xss-in-special-requests"},{"cve":"CVE-2026-57723","cvss":7.4,"slug":"cve-2026-57723-e4jvikwp-vikbooking-hotel-booking-engine-csrf-to-file-deletion","title":"e4jvikwp VikBooking Hotel Booking Engine CSRF to file deletion","severity":"high","exploited":false,"published_at":"2026-07-01T18:16:35.36+00:00","url":"https://junglewise.ai/threats/cve-2026-57723-e4jvikwp-vikbooking-hotel-booking-engine-csrf-to-file-deletion"},{"cve":"CVE-2026-12754","cvss":6.1,"slug":"cve-2026-12754-e4jvikwp-vikbooking-hotel-booking-engine-reflected-xss-in","title":"e4jvikwp VikBooking Hotel Booking Engine reflected XSS in layoutstyle","severity":"medium","exploited":false,"published_at":"2026-07-01T10:16:26.79+00:00","url":"https://junglewise.ai/threats/cve-2026-12754-e4jvikwp-vikbooking-hotel-booking-engine-reflected-xss-in"},{"cve":"CVE-2026-42683","cvss":7.1,"slug":"cve-2026-42683-e4jvikwp-vikbooking-hotel-booking-engine-dom-based-xss","title":"e4jvikwp VikBooking Hotel Booking Engine DOM-based XSS","severity":"high","exploited":false,"published_at":"2026-06-01T15:16:36.127+00:00","url":"https://junglewise.ai/threats/cve-2026-42683-e4jvikwp-vikbooking-hotel-booking-engine-dom-based-xss"},{"cve":"CVE-2026-42762","cvss":7.1,"slug":"cve-2026-42762-e4jvikwp-vikbooking-hotel-booking-engine-dom-xss","title":"e4jvikwp VikBooking Hotel Booking Engine DOM XSS","severity":"high","exploited":false,"published_at":"2026-05-27T11:16:22.897+00:00","url":"https://junglewise.ai/threats/cve-2026-42762-e4jvikwp-vikbooking-hotel-booking-engine-dom-xss"},{"cve":"CVE-2026-42737","cvss":8.6,"slug":"cve-2026-42737-e4jvikwp-vikbooking-arbitrary-file-deletion-via-path-traversal","title":"e4jvikwp VikBooking arbitrary file deletion via path traversal","severity":"high","exploited":false,"published_at":"2026-05-27T11:16:20.35+00:00","url":"https://junglewise.ai/threats/cve-2026-42737-e4jvikwp-vikbooking-arbitrary-file-deletion-via-path-traversal"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"E4jvikwp VikBooking Hotel Booking Engine & PMS","slug":"vikbooking-hotel-booking-engine-pms","vendor":{"name":"E4jvikwp","slug":"e4jvikwp","url":"https://junglewise.ai/threats/vendors/e4jvikwp"},"aliases":[],"category":"cms-plugin","homepage":"https://e4j.com/joomla-extensions/vik-booking-hotel-booking-engine-pms.html","repo_url":"https://github.com/e4j/VikBooking-for-WordPress","description":"VikBooking is a WordPress plugin designed for hotel reservations and property management.","url":"https://junglewise.ai/threats/technologies/vikbooking-hotel-booking-engine-pms"},"most_severe":[{"cve":"CVE-2026-42737","cvss":8.6,"slug":"cve-2026-42737-e4jvikwp-vikbooking-arbitrary-file-deletion-via-path-traversal","title":"e4jvikwp VikBooking arbitrary file deletion via path traversal","severity":"high","exploited":false,"published_at":"2026-05-27T11:16:20.35+00:00","url":"https://junglewise.ai/threats/cve-2026-42737-e4jvikwp-vikbooking-arbitrary-file-deletion-via-path-traversal"},{"cve":"CVE-2026-57723","cvss":7.4,"slug":"cve-2026-57723-e4jvikwp-vikbooking-hotel-booking-engine-csrf-to-file-deletion","title":"e4jvikwp VikBooking Hotel Booking Engine CSRF to file deletion","severity":"high","exploited":false,"published_at":"2026-07-01T18:16:35.36+00:00","url":"https://junglewise.ai/threats/cve-2026-57723-e4jvikwp-vikbooking-hotel-booking-engine-csrf-to-file-deletion"},{"cve":"CVE-2026-15401","cvss":7.2,"slug":"cve-2026-15401-vikbooking-hotel-booking-engine-pms-stored-xss-in-vbfx-parameter","title":"VikBooking Hotel Booking Engine & PMS Stored XSS in vbfX parameter","severity":"high","exploited":false,"published_at":"2026-07-24T10:16:31.41+00:00","url":"https://junglewise.ai/threats/cve-2026-15401-vikbooking-hotel-booking-engine-pms-stored-xss-in-vbfx-parameter"},{"cve":"CVE-2026-6820","cvss":7.2,"slug":"cve-2026-6820-vikbooking-hotel-booking-engine-pms-stored-xss-in-email-parameter","title":"VikBooking Hotel Booking Engine & PMS Stored XSS in email parameter","severity":"high","exploited":false,"published_at":"2026-07-08T13:16:57.78+00:00","url":"https://junglewise.ai/threats/cve-2026-6820-vikbooking-hotel-booking-engine-pms-stored-xss-in-email-parameter"},{"cve":"CVE-2026-6818","cvss":7.2,"slug":"cve-2026-6818-vikbooking-hotel-booking-engine-pms-stored-xss-in-special-requests","title":"VikBooking Hotel Booking Engine & PMS Stored XSS in special_requests","severity":"high","exploited":false,"published_at":"2026-07-08T12:17:21.017+00:00","url":"https://junglewise.ai/threats/cve-2026-6818-vikbooking-hotel-booking-engine-pms-stored-xss-in-special-requests"},{"cve":"CVE-2026-42683","cvss":7.1,"slug":"cve-2026-42683-e4jvikwp-vikbooking-hotel-booking-engine-dom-based-xss","title":"e4jvikwp VikBooking Hotel Booking Engine DOM-based XSS","severity":"high","exploited":false,"published_at":"2026-06-01T15:16:36.127+00:00","url":"https://junglewise.ai/threats/cve-2026-42683-e4jvikwp-vikbooking-hotel-booking-engine-dom-based-xss"},{"cve":"CVE-2026-42762","cvss":7.1,"slug":"cve-2026-42762-e4jvikwp-vikbooking-hotel-booking-engine-dom-xss","title":"e4jvikwp VikBooking Hotel Booking Engine DOM XSS","severity":"high","exploited":false,"published_at":"2026-05-27T11:16:22.897+00:00","url":"https://junglewise.ai/threats/cve-2026-42762-e4jvikwp-vikbooking-hotel-booking-engine-dom-xss"},{"cve":"CVE-2026-15346","cvss":6.1,"slug":"cve-2026-15346-e4jvikwp-vikbooking-hotel-booking-engine-pms-reflected-xss","title":"e4jvikwp VikBooking Hotel Booking Engine & PMS Reflected XSS","severity":"medium","exploited":false,"published_at":"2026-07-24T09:16:23.953+00:00","url":"https://junglewise.ai/threats/cve-2026-15346-e4jvikwp-vikbooking-hotel-booking-engine-pms-reflected-xss"},{"cve":"CVE-2026-12754","cvss":6.1,"slug":"cve-2026-12754-e4jvikwp-vikbooking-hotel-booking-engine-reflected-xss-in","title":"e4jvikwp VikBooking Hotel Booking Engine reflected XSS in layoutstyle","severity":"medium","exploited":false,"published_at":"2026-07-01T10:16:26.79+00:00","url":"https://junglewise.ai/threats/cve-2026-12754-e4jvikwp-vikbooking-hotel-booking-engine-reflected-xss-in"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}