Extension WordPress

Vulnérabilités Online Scheduling and Appointment Booking System – Bookly

Cette page rassemble les failles publiées pour Online Scheduling and Appointment Booking System – Bookly, leurs plages de versions affectées et les correctifs signalés dans la base locale.

14Vulnérabilités
0Critiques
14Avec correctif
8,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Online Scheduling and Appointment Booking System – Bookly

14 fiches

CVE-2026-61944 Élevée · 7,2
Online Scheduling and Appointment Booking System – Bookly

Online Scheduling and Appointment Booking System – Bookly <= 27.7 – Unauthenticated Stored Cross-Site Scripting

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 27.7 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-27.7

Correctif

27.8

Publication

16/07/2026

CVE-2026-61949 Élevée · 7,5
Online Scheduling and Appointment Booking System – Bookly

Online Scheduling and Appointment Booking System – Bookly <= 27.7 – Unauthenticated SQL Injection

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 27.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

Versions affectées

*-27.7

Correctif

27.8

Publication

16/07/2026

CVE-2026-5513 Élevée · 7,2
Online Scheduling and Appointment Booking System – Bookly

Online Scheduling and Appointment Booking System – Bookly <= 27.2 – Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-27.2

Correctif

27.3

Publication

13/06/2026

CVE-2026-42667 Moyenne · 5,3
Online Scheduling and Appointment Booking System – Bookly

Online Scheduling and Appointment Booking System – Bookly <= 27.4 – Unauthenticated Information Exposure

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 27.4. This makes it possible for unauthenticated attackers to extract sensitive user or…

Versions affectées

*-27.4

Correctif

27.5

Publication

10/05/2026

CVE-2026-2519 Moyenne · 5,3
Online Scheduling and Appointment Booking System – Bookly

Online Scheduling and Appointment Booking System – Bookly <= 27.0 – Unauthenticated Price Manipulation via 'tips'

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation via the 'tips' parameter in all versions up to, and including, 27.0. This is due to the plugin trusting a user-supplied…

Versions affectées

*-27.0

Correctif

27.1

Publication

08/04/2026

CVE-2026-32540 Moyenne · 6,1
Online Scheduling and Appointment Booking System – Bookly

Online Scheduling and Appointment Booking System – Bookly <= 26.7 – Reflected Cross-Site Scripting

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 26.7 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-26.7

Correctif

26.8

Publication

20/03/2026

CVE-2024-5584 Moyenne · 6,4
Online Scheduling and Appointment Booking System – Bookly

WordPress Online Booking and Scheduling Plugin – Bookly <= 23.2 – Authenticated (Subscriber+) Stored Cross-Site Scripting via Color Profile Parameter

The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Color Profile parameter in all versions up to, and including, 23.2 due to insufficient input sanitization and output…

Versions affectées

*-23.2

Correctif

23.3

Publication

10/06/2024

CVE-2023-5209 Moyenne · 4,4
Online Scheduling and Appointment Booking System – Bookly

WordPress Online Booking and Scheduling Plugin – Bookly <= 22.4.1 – Authenticated (Admin+) Stored Cross-Site Scripting

The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 22.4.1 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-22.4.1

Correctif

22.5

Publication

06/11/2023

CVE-2023-1159 Moyenne · 4,0
Online Scheduling and Appointment Booking System – Bookly

Bookly <= 21.7 – Authenticated (Admin+) Stored Cross-Site Scripting

The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative…

Versions affectées

21.7

Correctif

21.8

Publication

01/06/2023

CVE-2023-1172 Élevée · 7,2
Online Scheduling and Appointment Booking System – Bookly

Bookly <= 21.5 – Unauthenticated Stored Cross-Site Scripting via Name

The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the full name value in versions up to, and including, 21.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

21.5

Correctif

21.5.1

Publication

17/03/2023

CVE-2018-6891 Élevée · 7,2
Online Scheduling and Appointment Booking System – Bookly

WordPress Online Booking and Scheduling Plugin – Bookly <= 14.5 – Cross-Site Scripting

The Online Booking and Scheduling plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 14.5. This is due to insufficient input sanitization and output escaping on the name parameter of a booking submission…

Versions affectées

*-14.5

Correctif

14.6

Publication

10/02/2018

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités