VYPR

Bookly

by WordPress

Source repositories

CVEs (15)

  • CVE-2023-26526HigMay 17, 2024
    risk 0.50cvss 7.7epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Nota-Info Bookly allows Path Traversal, Manipulating Web Input to File System Calls.This issue affects Bookly: from n/a through 21.7.1.

  • CVE-2026-42667HigJun 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.

  • CVE-2026-13424HigAug 16, 2026
    risk 0.47cvss 7.2epss 0.00

    The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action in all versions up to, and including, 27.7 due to insufficient input sanitization and output escaping.…

  • CVE-2023-1172HigMar 17, 2023
    risk 0.47cvss 7.2epss 0.00

    The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

  • CVE-2026-32540HigMar 25, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bookly Bookly bookly-responsive-appointment-booking-tool allows Reflected XSS.This issue affects Bookly: from n/a through <= 26.7.

  • CVE-2024-5584MedJun 11, 2024
    risk 0.42cvss 6.4epss 0.00

    The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Color Profile parameter in all versions up to, and including, 23.2 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-5513HigJun 13, 2026
    risk 0.40cvss 7.2epss 0.00

    The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This…

  • CVE-2018-6891MedFeb 11, 2018
    risk 0.40cvss 6.1epss 0.01

    Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.

  • CVE-2026-2520MedSep 8, 2026
    risk 0.28cvss 5.4epss 0.00

    The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'updateAddon' function in all versions up to, and including, 27.2. This makes it possible for…

  • CVE-2026-12905MedAug 16, 2026
    risk 0.28cvss 4.3epss 0.00

    The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 27.7 via the appointment() method of the Mobile Staff Cabinet API (resource=appointment, action=bookly_mobile_staff_cabinet) in…

  • CVE-2026-2519MedApr 9, 2026
    risk 0.27cvss 5.3epss 0.00

    The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied input without server-side validation…

  • CVE-2023-1159MedJun 2, 2023
    risk 0.26cvss 4.0epss 0.00

    The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative privileges to…

  • CVE-2026-14516HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions up to, and including, 27.5 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2026-61949CriJul 23, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Bookly <= 27.7 versions.

  • CVE-2026-61944HigJul 23, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.