Products: 1
Vulnerabilities: 5
Known Exploited: 0
0
Critical Level Threats
3
High Level Threats
2
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-13424
Online Scheduling and Appointment Booking System <= 27.7 - Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action
Last Modified: Aug 17, 2026
Published: Aug 16, 2026
CVE-2026-12905
Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' Parameter
Last Modified: Aug 17, 2026
Published: Aug 16, 2026
CVE-2026-14516
Online Scheduling and Appointment Booking System <= 27.5 - Unauthenticated SQL Injection
Last Modified: Jul 28, 2026
Published: Jul 28, 2026
CVE-2026-5513
Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie
Last Modified: Jun 15, 2026
Published: Jun 13, 2026
CVE-2026-2519
Online Scheduling and Appointment Booking System – Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips'
Last Modified: Apr 24, 2026
Published: Apr 09, 2026
Items Per Page
