bookly-responsive-appointment-booking-tool vulnerabilities
CVEs whose affected-version data names the bookly-responsive-appointment-booking-tool package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-96347Medium· 6.5Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.
Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.
▾ SunlitBookly · bookly-responsive-appointment-booking-toolvia NVD
CVE-2026-96348High· 7.5Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
Unauthenticated Broken Access Control in Bookly <= 28.2 versions.
▾ TwilightBookly · bookly-responsive-appointment-booking-toolvia NVD