Hostel
This hub aggregates every CVE we track for Hostel, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
13
CVEs tracked
0
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM9HIGH4
Monthly trend
0
0
0
0
0
1
2
0
0
2
0
0
0
0
2
0
0
0
1
0
0
1
0
0
2024-102026-09
Latest CVEs
The 13 most recently published vulnerabilities affecting Hostel.
- CVE-2026-3907Hostel <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wphostel-book' Shortcode6.4
- CVE-2026-1838Hostel <= 1.1.6 - Reflected Cross-Site Scripting via 'shortcode_id' Parameter6.1
- CVE-2023-32120WordPress Hostel plugin <= 1.1.5.1 - Cross Site Scripting (XSS)5.9
- CVE-2025-66119WordPress Hostel plugin <= 1.1.5.9 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2025-6236Hostel < 1.1.5.9 - Admin+ Stored XSS4.8
- CVE-2025-6234Hostel < 1.1.5.8 - Reflected XSS6.1
- CVE-2025-39566WordPress Hostel plugin <= 1.1.5.6 - SQL Injection Vulnerability7.6
- CVE-2025-30848WordPress Hostel plugin <= 1.1.5 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2025-31102WordPress Hostel plugin <= 1.1.5.5 - Reflected Cross Site Scripting (XSS) vulnerability7.1
- CVE-2024-3753Hostel < 1.1.5.3 - Reflected XSS5.9
- CVE-2024-4314hostel <= 1.1.5.3 - Cross-Site Request Forgery4.3
- CVE-2023-0545Hostel < 1.1.5.2 - Admin+ Stored XSS4.8
- CVE-2019-12345XSS exists in the Kiboko Hostel plugin before 1.1.4 for WordPress.6.1
Product normalization is registry-driven with AI assist and human review. How it works