Known Vulnerabilities for Bookly by Ladela
Listed below are 1 of the newest known vulnerabilities associated with "Bookly" by "Ladela".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61949 json | Unauthenticated SQL Injection in Bookly <= 27.7 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-61944 json | Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-42667 json | Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-5513 json | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scrip... | Not Provided | 2026-06-13 | 2026-06-15 |
| CVE-2018-6891 json | Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js. | 6.1 - MEDIUM | 2018-02-11 | 2022-11-14 |