Digitaldruid

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 30
    Known Exploited: 0
    9
    Critical Level Threats
    6
    High Level Threats
    14
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-55816

    HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.

    Last Modified: Dec 15, 2025
    Published: Dec 11, 2025

    CVE-2025-44203

    In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL error messages disclose the administrator username, password hash, and salt. The same race leaves the setup partially initialized, so the administrator can no longer log in with the credentials set during installation, resulting in a denial of service that requires reinstallation to recover. Remote exploitation additionally requires the installation to allow non-localhost access. The vulnerability was fixed in version 3.0.8.

    Last Modified: Jul 09, 2026
    Published: Jun 20, 2025

    CVE-2023-43378

    A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the commento1_1 parameter.

    Last Modified: Jun 23, 2025
    Published: Apr 22, 2025

    CVE-2025-25748

    A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is an id_sessione CSRF token.

    Last Modified: Jan 29, 2026
    Published: Mar 11, 2025

    CVE-2025-25747

    Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint

    Last Modified: May 28, 2025
    Published: Mar 11, 2025
    Items Per Page
    Digitaldruid Vulnerabilities & Security CVEs | CVE-DB