HotelDruid vulnerabilities
CVEs whose affected-version data names the HotelDruid package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2023-34854Medium· 6.6HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.
▾ Sunlitdigitaldruid · HotelDruidEPSS 0.23%via NVD
CVE-2025-44203High· 7.5PoCIn HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking
In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a…
▾ Midnightdigitaldruid · hoteldruidEPSS 0.57%via NVD