目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-13395— Bookly < 27.8 staff_id 未认证 SQL 注入漏洞

AI Predicted 9.8 Difficulty: Trivial EPSS 0.34% · P26

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
UnknownOnline Scheduling and Appointment Booking System< 27.8affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-13395の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Bookly < 27.8 - Unauthenticated SQL Injection via staff_id
ソース: CVE Program / CVE List V5
脆弱性説明
The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
UnknownOnline Scheduling and Appointment Booking System 0 ~ 27.8 -

II. CVE-2026-13395の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-13395のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-13395 厂商安全公告 (1)

Same Patch Batch · Unknown · 2026-07-30 · 36 CVEs total

CVE-2026-13143WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN
CVE-2026-15257RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modificatio
CVE-2026-15240Customer Switching for WooCommerce < 2.1.3 - Customer+ Privilege Escalation to Administrat
CVE-2026-15382Ultimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom Icon Font Dele
CVE-2026-11870Hide My WP Ghost < 7.0.05 - IP Address Spoofing via Trusted Proxy Headers Leading to Prote
CVE-2026-11867Frontend Admin by DynamiApps < 3.29.7 - Subscriber+ Taxonomy Term Creation/Modification/De
CVE-2026-11881Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field
CVE-2026-11782Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Arbitrary User Wallet & Poin
CVE-2026-12500WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update
CVE-2026-15255RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR
CVE-2026-13145WP Travel < 11.8.1 - Subscriber+ Booking PII Disclosure via IDOR
CVE-2026-13344Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table
CVE-2026-13330Animation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG Upload
CVE-2026-13345Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce
CVE-2026-13178Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation
CVE-2026-14310Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection
CVE-2026-14239Tourmaster < 5.4.8 - Stored XSS via CSRF
CVE-2026-14305WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likes
CVE-2026-15235Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX
CVE-2026-14188Easy Appointments <= 3.12.26 - Contributor+ Customer Data Disclosure

Showing 20 of 36 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-13395へのコメント

まだコメントはありません


コメントを残す