Extension WordPress
Vulnérabilités Online Scheduling and Appointment Booking System – Bookly
Cette page rassemble les failles publiées pour Online Scheduling and Appointment Booking System – Bookly, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Online Scheduling and Appointment Booking System – Bookly
14 fiches
Online Scheduling and Appointment Booking System – Bookly <= 27.7 – Unauthenticated Stored Cross-Site Scripting
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 27.7 due to insufficient input sanitization and output escaping. This makes it possible for…
*-27.7
27.8
16/07/2026
Online Scheduling and Appointment Booking System – Bookly <= 27.7 – Unauthenticated SQL Injection
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 27.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-27.7
27.8
16/07/2026
Online Scheduling and Appointment Booking System – Bookly <= 27.2 – Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This…
*-27.2
27.3
13/06/2026
Online Scheduling and Appointment Booking System – Bookly <= 27.4 – Unauthenticated Information Exposure
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 27.4. This makes it possible for unauthenticated attackers to extract sensitive user or…
*-27.4
27.5
10/05/2026
Online Scheduling and Appointment Booking System – Bookly <= 27.0 – Unauthenticated Price Manipulation via 'tips'
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied…
*-27.0
27.1
08/04/2026
Online Scheduling and Appointment Booking System – Bookly <= 26.7 – Reflected Cross-Site Scripting
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 26.7 due to insufficient input sanitization and output escaping. This makes it possible for…
*-26.7
26.8
20/03/2026
WordPress Online Booking and Scheduling Plugin – Bookly <= 23.2 – Authenticated (Subscriber+) Stored Cross-Site Scripting via Color Profile Parameter
The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Color Profile parameter in all versions up to, and including, 23.2 due to insufficient input sanitization and output…
*-23.2
23.3
10/06/2024
WordPress Online Booking and Scheduling Plugin – Bookly <= 22.4.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 22.4.1 due to insufficient input sanitization and output escaping. This…
*-22.4.1
22.5
06/11/2023
Bookly <= 22.3.1 – Authenticated(Administrator+) SQL Injection
The Bookly plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 22.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
*-22.3.1
22.4
25/09/2023
Bookly <= 21.7 – Authenticated (Admin+) Stored Cross-Site Scripting
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative…
21.7
21.8
01/06/2023
Bookly <= 21.7.1 – Arbitrary File Deletion
The Bookly plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 21.7.1. This makes it possible for authenticated attackers with staff-level access to delete arbitrary files on the affected site's server which…
*-21.7.1
21.8
11/05/2023
Bookly <= 21.5 – Unauthenticated Stored Cross-Site Scripting via Name
The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
21.5
21.5.1
17/03/2023
Bookly <= 20.3 – Staff Member Stored Cross-Site Scripting
The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name field before outputting it back in a page, which could lead to a Stored Cross-Site Scripting issue
*-20.3
20.3.1
08/11/2021
WordPress Online Booking and Scheduling Plugin – Bookly <= 14.5 – Cross-Site Scripting
The Online Booking and Scheduling plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 14.5. This is due to insufficient input sanitization and output escaping on the name parameter of a booking submission…
*-14.5
14.6
10/02/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.