SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-61949

CRITICAL · CVSS 9.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

An unauthenticated SQL injection vulnerability in Bookly versions up to 27.7 allows attackers to execute arbitrary SQL queries, potentially leading to unauthorized access to sensitive data and complete database compromise. Organizations using affected versions should prioritize patching this critical vulnerability to mitigate the risk of data breaches and maintain the integrity of their systems. Immediate action is essential for any entity relying on Bookly for managing bookings or customer data.

CVE
CVE-2026-61949
Severity
CRITICAL
CVSS
9.3
EPSS
0.28%

Original NVD Description

Unauthenticated SQL Injection in Bookly <= 27.7 versions.