Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Dismissed suggestions

These automatic suggestions were dismissed after initial triaging.

to select a suggestion for revision.

View:
Compact
Detailed
Dismissed
(no matching packages found)
Permalink CVE-2026-15054
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Bit Form < 3.1.2 - Unauthenticated Inactive Form Submission

The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries to, and fire the configured workflows (such as email notifications) of forms the site owner has deactivated or unpublished.

References

Affected products

Bit Form
  • <3.1.2
Dismissed
(no matching packages found)
Permalink CVE-2026-66415
8.4 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): High (H)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): High (H)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Leantime Server-Side Request Forgery and Local File Inclusion in Blueprints::import()

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path validation. Attackers can submit crafted filenames containing URL wrappers or path traversal sequences through the JSON-RPC API endpoint to access cloud metadata services or read arbitrary files from the server filesystem.

Affected products

Leantime
  • <3.6.2
Dismissed
(no matching packages found)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Apache JSPWiki: UserManager does not sanity-check user database at startup

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.

Affected products

Apache JSPWiki
  • <2.12.4
Dismissed
(no matching packages found)
Permalink CVE-2026-11782
5.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Arbitrary User Wallet & Points Manipulation via IDOR

The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily modify or corrupt (including driving it negative) the stored wallet balance and loyalty points of any user. Modifying the wallet balance additionally requires the companion Wallet System for WooCommerce Points and Rewards for WooCommerce WordPress plugin before 2.10.1 to be active.

References

Affected products

Points and Rewards for WooCommerce
  • <2.10.1
Dismissed
(no matching packages found)
Permalink CVE-2026-67530
6.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
WACRM: SSRF via the automation `send_webhook` action

WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/automations/engine.ts and its validation in src/lib/automations/validate.ts allowed an authenticated user with automation privileges to submit an arbitrary webhook URL that the server fetched without the existing isDeliverableUrl SSRF guard in src/lib/webhooks/ssrf.ts, allowing requests to private, loopback, link-local, or cloud metadata addresses such as the cloud metadata endpoint at 169.254.169.254. This vulnerability is fixed with commit 23838a9959550e975d732ae08a44a3a2f0cc084b.

Affected products

wacrm
  • ==<= 0.7.0
Dismissed
(no matching packages found)
Permalink CVE-2025-36374
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
IBM DataPower Gateway affected by XML external entity injection

IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerability to expose sensitive information or consume memory resources.

References

Affected products

DataPower Gateway 10.5.0
  • =<10.5.0.21
DataPower Gateway 10.6.0
  • =<10.6.0.9
DataPower Gateway 10.6CD
  • =<10.6.6
Dismissed
(no matching packages found)
Permalink CVE-2026-13178
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation

The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked as paid without completing any payment.

References

Affected products

Eventin
  • <4.1.16
Dismissed
(max. allowed matches exceeded)
Permalink CVE-2026-58043
7.5 HIGH
  • CVSS version (CVSS): 3.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
A flaw in Node.js Permission Model enforcement can over-grant filesystem …

A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.

Affected products

node
  • =<22.23.1
  • =<24.18.0
  • =<26.5.0
Dismissed
(no matching packages found)
Permalink CVE-2026-13584
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocol

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET, Liner Track System MTR-S series Linear track control module, Inverter FR-A800/F800/E800 Series, Industrial Robot CR800-D series controller Network Base Card, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module, CC-Link IE TSN-AnyWireASLINK bridge module, Energy Measuring Unit CC-Link IE TSN Communication Unit, Industrial Computer MELIPC series, GOT3000 Series, CC-Link IE TSN Communication Unit, Motion Control Software, CC-Link IE TSN Communication Software for Windows, Analysis Support Software MELSOFT VIMA, Master/Local module Designated communication LSI DeviceKit, Master/Local module Designated communication LSI, Remote Station Communication LSI with GbE-PHY, CC-Link IE TSN Master/Local module Designated communication LSI SDK, and Remote station software development kit allows an attacker with access to a CC-Link IE TSN network to tamper with communication data (control input/output values) by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.

Affected products

Motion module RD78G4
  • ==all versions
Motion module RD78G8
  • ==all versions
Motion module RD78G16
  • ==all versions
Motion module RD78G64
  • ==all versions
Motion module RD78GHV
  • ==all versions
Motion module RD78GHW
  • ==all versions
Tension meter LM7-1LG
  • ==all versions
Tension meter LM7-2LG
  • ==all versions
Motion module FX5-40SSC-G
  • ==all versions
Motion module FX5-80SSC-G
  • ==all versions
FPGA module NZ2GN2S-D41D01
  • ==all versions
FPGA module NZ2GN2S-D41P01
  • ==all versions
GOT3000 Series GT3708-XRBA
  • ==all versions
GOT3000 Series GT3708-XRBD
  • ==all versions
GOT3000 Series GT3710-XRBA
  • ==all versions
GOT3000 Series GT3710-XRBD
  • ==all versions
GOT3000 Series GT3712-XRBA
  • ==all versions
GOT3000 Series GT3712-XRBD
  • ==all versions
GOT3000 Series GT3715-XRBA
  • ==all versions
GOT3000 Series GT3715-XRBD
  • ==all versions
FPGA module NZ2GN2S-D41PD02
  • ==all versions
GOT3000 Series GT3712-WXCBD
  • ==all versions
GOT3000 Series GT3715-FHCBD
  • ==all versions
AC Servo MELSERVO-J5 MR-J5-G
  • ==all versions
AC Servo MELSERVO-J5 MR-J5W-G
  • ==all versions
Motion Control Software SWM-G
  • ==all versions
AC Servo MELSERVO-J5 MR-J5D-G4
  • ==all versions
AC Servo MELSERVO-J5 MR-MD333G
  • ==all versions
AC Servo MELSERVO-JET MR-JET-G
  • ==all versions
Motion Control Board MR-EM441G
  • ==all versions
AC Servo MELSERVO-J5 MR-J5-G-HS
  • ==all versions
AC Servo MELSERVO-J5 MR-J5-G-LL
  • ==all versions
AC Servo MELSERVO-J5 MR-J5-G-RJ
  • ==all versions
Master/local module RJ71GN11-SX
  • ==all versions
Master/local module RJ71GN11-T2
  • ==all versions
Master/local module FX5-CCLGN-MS
  • ==all versions
Master/local module RJ71GN11-EIP
  • ==all versions
Motion Control Software SWM-G-N1
  • ==all versions
AC Servo MELSERVO-JET MR-JET-G4-HS
  • ==all versions
Block-type remote module NZ2GN2B1-16D
  • ==all versions
Block-type remote module NZ2GN2B1-16T
  • ==all versions
Block-type remote module NZ2GN2B1-32D
  • ==all versions
Block-type remote module NZ2GN2B1-32T
  • ==all versions
Block-type remote module NZ2GN2S1-16D
  • ==all versions
Block-type remote module NZ2GN2S1-16T
  • ==all versions
Block-type remote module NZ2GN2S1-32D
  • ==all versions
Block-type remote module NZ2GN2S1-32T
  • ==all versions
Block-type remote module NZ2GNCE3-32D
  • ==all versions
Block-type remote module NZ2GNCF1-32D
  • ==all versions
Block-type remote module NZ2GNCF1-32T
  • ==all versions
Block-type remote module NZ2GN12A2-16T
  • ==all versions
Block-type remote module NZ2GN12A4-16D
  • ==all versions
Block-type remote module NZ2GN2B1-16TE
  • ==all versions
Block-type remote module NZ2GN2B1-32DT
  • ==all versions
Block-type remote module NZ2GN2B1-32TE
  • ==all versions
Block-type remote module NZ2GN2S1-16TE
  • ==all versions
Block-type remote module NZ2GN2S1-32DT
  • ==all versions
Block-type remote module NZ2GN2S1-32TE
  • ==all versions
Block-type remote module NZ2GNCE3-32DT
  • ==all versions
Block-type remote module NZ2GN12A2-16TE
  • ==all versions
Block-type remote module NZ2GN12A4-16DE
  • ==all versions
Block-type remote module NZ2GN2B1-32DTE
  • ==all versions
Block-type remote module NZ2GN2S1-32DTE
  • ==all versions
Block-type remote module NZ2GN12A42-16DT
  • ==all versions
CC-Link IE TSN expansion unit FCU8-EX569
  • ==all versions
Block-type remote module NZ2GN12A42-16DTE
  • ==all versions
MELSEC MX Controller MX-R model MXR300-16
  • ==all versions
MELSEC MX Controller MX-R model MXR300-32
  • ==all versions
MELSEC MX Controller MX-R model MXR300-64
  • ==all versions
CC-Link IE TSN compatible coupler NZ2FT-GN
  • ==all versions
CC-Link IE TSN interface board NZ81GN11-SX
  • ==all versions
CC-Link IE TSN interface board NZ81GN11-T2
  • ==all versions
Industrial Computer MELIPC series MI2332-W
  • ==all versions
Industrial Computer MELIPC series MI2532-W
  • ==all versions
Inverter FR-A800/F800/E800 Series FR-A8NCG
  • ==all versions
MELSEC MX Controller MX-R model MXR500-128
  • ==all versions
MELSEC MX Controller MX-R model MXR500-256
  • ==all versions
Inverter FR-A800/F800/E800 Series FR-E800-E
  • ==all versions
Inverter FR-A800/F800/E800 Series FR-A800-GN
  • ==all versions
Inverter FR-A800/F800/E800 Series FR-A8NCG-S
  • ==all versions
MELSEC MX Controller MX-F model MXF100-8-N32
  • ==all versions
MELSEC MX Controller MX-F model MXF100-8-P32
  • ==all versions
Analog-Digital converter module NZ2GN2B-60AD4
  • ==all versions
Analog-Digital converter module NZ2GN2S-60AD4
  • ==all versions
Digital-Analog converter module NZ2GN2B-60DA4
  • ==all versions
Digital-Analog converter module NZ2GN2S-60DA4
  • ==all versions
Inverter FR-A800/F800/E800 Series FR-E800-SCE
  • ==all versions
MELSEC MX Controller MX-F model MXF100-16-N32
  • ==all versions
MELSEC MX Controller MX-F model MXF100-16-P32
  • ==all versions
CC-Link IE TSN Communication Unit GT25-J71GN13-T2
  • ==all versions
Analysis Support Software MELSOFT VIMA SW1DNN-VIMA-M
  • ==all versions
CC-Link IE TSN-AnyWireASLINK bridge module NZ2AW1GNAL
  • ==all versions
Remote station software development kit SW1DNC-GNSDK1S-M
  • ==all versions
Remote station software development kit SW1DNC-GNSDK2S-M
  • ==all versions
Block-type remote module with safety functions NZ2GNSS2-8D
  • ==all versions
Block-type remote module with safety functions NZ2GNSS2-8TE
  • ==all versions
Remote Station Communication LSI with GbE-PHY NZ2GACP620-60
  • ==all versions
Remote Station Communication LSI with GbE-PHY NZ2GACP621-90
  • ==all versions
Block-type remote module with safety functions NZ2GNSS2-8D-K
  • ==all versions
Remote Station Communication LSI with GbE-PHY NZ2GACP620-300
  • ==all versions
Remote Station Communication LSI with GbE-PHY NZ2GACP621-720
  • ==all versions
Block-type remote module with safety functions NZ2GNSS2-16DTE
  • ==all versions
Block-type remote module with safety functions NZ2GNSS2-8TE-K
  • ==all versions
Block-type remote module with safety functions NZ2GNS12A2-14DT
  • ==all versions
Master/Local module Designated communication LSI NZ2GACP610-60
  • ==all versions
Block-type remote module with safety functions NZ2GNS12A2-16DTE
  • ==all versions
Block-type remote module with safety functions NZ2GNSS2-16DTE-K
  • ==all versions
CC-Link IE TSN-CC-Link IE Field Network bridge module NZ2GN-GFB
  • ==all versions
CC-Link IE TSN Communication Software for Windows SW1DND-CCIETCT-M
  • ==all versions
Energy Measuring Unit CC-Link IE TSN Communication Unit EMU4-CM-TSN
  • ==all versions
Liner Track System MTR-S series Linear track control module MTR-SCU00-4G
  • ==all versions
Liner Track System MTR-S series Linear track control module MTR-SCU00-PG
  • ==all versions
Industrial Robot CR800-D series controller Network Base Card 2F-DQ535-TSN
  • ==all versions
Master/Local module Designated communication LSI DeviceKit NZ2KT-NPETNG51
  • ==all versions
CC-Link IE TSN Master/Local module Designated communication LSI SDK SW1DNN-GN610SRC-M
  • ==all versions
Dismissed
(no matching packages found)
Permalink CVE-2026-13395
8.6 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
created 1 month ago Activity log
  • Created & dismissed (no matching packages found) suggestion
Bookly < 27.8 - Unauthenticated SQL Injection via staff_id

The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from its unauthenticated front-end booking requests before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data such as password hashes from the database.

References

Affected products

Online Scheduling and Appointment Booking System
  • <27.8