Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Online Scheduling and Appointment Booking System – Bookly — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Online Scheduling and Appointment Booking System – Bookly, with AI-generated Chinese analysis, references, and POCs.

Vendor: ladela

CVE ID Title CVSS Severity Published
CVE-2026-12626 Online Scheduling and Appointment Booking System <= 28.2 - Authenticated (Custom+) PHP Object Injection via 'value' Parameter CWE-502 7.2 High 2026-10-10
CVE-2026-103365 Online Scheduling and Appointment Booking System <= 28.4 - Unauthenticated Sensitive Information Exposure in 'phone' Parameter to bookly_render_details CWE-200 5.3 Medium 2026-10-10
CVE-2026-104898 Online Scheduling and Appointment Booking System <= 28.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Privilege Escalation via 'id' and 'wp_user_id' Parameters via Query String / JSON Body CWE-639 6.8 Medium 2026-10-10
CVE-2026-93399 Online Scheduling and Appointment Booking System <= 28.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Booking Token Disclosure and Deletion via 'order_id' Parameter CWE-639 9.1 Critical 2026-09-25
CVE-2026-92799 Online Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Juggling via json_data CWE-285 5.3 Medium 2026-09-25
CVE-2026-89063 Online Scheduling and Appointment Booking System <= 28.1 - Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' Parameter CWE-639 7.5 High 2026-09-16
CVE-2026-2520 Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update CWE-862 5.4 Medium 2026-09-08
CVE-2026-13424 Online Scheduling and Appointment Booking System <= 27.7 - Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action CWE-79 7.2 High 2026-08-16
CVE-2026-12905 Online Scheduling and Appointment Booking System – Bookly <= 27.7 - Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' Parameter CWE-639 4.3 Medium 2026-08-16
CVE-2026-14516 Online Scheduling and Appointment Booking System <= 27.5 - Unauthenticated SQL Injection CWE-89 7.5 High 2026-07-28
CVE-2026-5513 Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie CWE-79 7.2 High 2026-06-13
CVE-2026-2519 Online Scheduling and Appointment Booking System – Bookly <= 27.0 - Unauthenticated Price Manipulation via 'tips' CWE-472 5.3 Medium 2026-04-09
CVE-2024-5584 WordPress Online Booking and Scheduling Plugin – Bookly <= 23.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Color Profile Parameter CWE-79 6.4 Medium 2024-06-11

All 13 known CVE vulnerabilities affecting Online Scheduling and Appointment Booking System – Bookly with full Chinese analysis, references, and POCs where available.