Service Finder Bookings

Service Finder Bookings has 9 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; 5 are fixed and 4 remain unpatched as of September 2026. Their average CVSS score is 8.9, and the most serious one scores 9.8 out of 10. Severity breakdown: 5 critical and 3 high. 2025 was the busiest year with 7 disclosures.

The most common weakness is Authorization Bypass Through User-Controlled Key, behind 4 of the records (44%). Other recurring categories include Incorrect Privilege Assignment, Authentication Bypass Using An Alternate Path Or Channel.

5 of the records (56%) have a vendor fix, while 4 remain unpatched. The oldest unresolved one dates back to 2025.

6 independent researchers contributed these findings, most of them (3) reported by Foxyyy.

Strategic Overview

Avg CVSSHigh
8.9/ 10
Patch Coverage56%
Open

4

Fixed

5

Get automatic notifications for all Service Finder Bookings vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2025-5948

Service Finder Bookings <= 6.0 - Unauthenticated Privilege Escalation via claim_business

Read the full analysis

Vulnerability Records

9 records
2026-08-13 00:00CVE-2026-28159
4.3
Medium
Jamaal ahmedNo
2026-08-13 00:00CVE-2026-28161
8.8
High
Jamaal ahmedNo
2025-10-31 18:15CVE-2025-6574
8.8
High
Thái AnYes
2025-10-31 16:21CVE-2025-5949
8.8
High
FoxyyyYes
2025-09-18 16:31CVE-2025-5948
9.8
Critical
FoxyyyNo
2025-07-31 14:59CVE-2025-5947
9.8
Critical
FoxyyyYes
2025-07-04 00:00CVE-2025-23970
9.8
Critical
BondsNo
2025-04-24 00:00CVE-2025-2470
9.8
Critical
Alyudin NafiieYes
2025-03-18 00:00CVE-2024-13442
9.8
Critical
TonnYes
Showing 1–9 of 9 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C